SSCP - Systems Security Certified Practitioner Practice Test
SSCP - Systems Security Certified Practitioner के लिए अपना आत्मविश्वास बढ़ाएँ। अवधारणाओं का अभ्यास करें, उत्तरों को समझें और हर सवाल के साथ अपना ज्ञान मज़बूत करें।
एक नमूना सवाल आज़माएँपरीक्षा का परिचय और विवरण
The Systems Security Certified Practitioner (SSCP) certification is a globally recognized credential offered by (ISC)² that validates a candidate's technical and operational proficiency in implementing, monitoring, and administering IT security infrastructure. Unlike management-focused certifications, the SSCP is designed for hands-on security practitioners-including security analysts, system engineers, network administrators, and security consultants-who are responsible for the day-to-day operation of security controls. The exam covers seven domains aligned with the (ISC)² Common Body of Knowledge (CBK): Access Controls, Cryptography, Incident Response and Recovery, Network and Communications Security, Risk Identification Monitoring and Analysis, Security Operations and Administration, and Systems and Application Security. Earning the SSCP demonstrates that you possess the technical skills to protect organizational assets, respond to security incidents, and ensure compliance with security policies. For employers, the SSCP is a trusted benchmark that reduces hiring risk and confirms a candidate's ability to perform critical security functions. For professionals, this certification opens doors to roles such as Security Administrator, Network Security Engineer, and SOC Analyst, and is often a stepping stone toward advanced certifications like the CISSP. With the global cybersecurity workforce shortage, holding an SSCP credential signals that you are part of a qualified, vetted community committed to industry best practices and ethical conduct.
नमूना प्रश्न
अभ्यास कैसे काम करता है, यह जानने के लिए एक उत्तर चुनें और व्याख्या देखें।
Place the following steps of the incident response process, as defined by NIST SP 800-61, in their CORRECT chronological order. 1. Containment, Eradication, and Recovery 2. Preparation 3. Post-Incident Activity 4. Detection and Analysis
सही क्रम निम्नलिखित है जो NIST कंप्यूटर सुरक्षा घटना प्रबंधन मार्गदर्शिका (SP 800-61) द्वारा परिभाषित घटना प्रतिक्रिया प्रक्रिया के चरणों को दर्शाता है:
सही क्रम निम्नलिखित है जो NIST कंप्यूटर सुरक्षा घटना प्रबंधन मार्गदर्शिका (SP 800-61) द्वारा परिभाषित घटना प्रतिक्रिया प्रक्रिया के चरणों को दर्शाता है:
- सजगता (Step 2), जिसमें घटना के पहले ही होने से पहले नीतियों, प्रक्रियाओं, टीमों और उपकरणों का निर्माण शामिल है। इसके बाद है व्याख्या और पता लगाना (Step 4), जहां संभावित घटनाओं की पहचान और जांच की जाती है ताकि उन्हें पुष्टि किया जा सके। एक बार पुष्टि हो जाने के बाद, सीमित करना, नष्ट करना, और पुनर्स्थापना चरण (Step 1) का पालन किया जाता है ताकि नुकसान को सीमित किया जा सके, खतरे को हटाया जा सके और प्रणालियों को पुनर्स्थापित किया जा सके। अंतिम चरण है घटना के बाद की गतिविधि (Step 3), जिसमें सबक सीखना, रिपोर्टिंग, और योजनाओं को अद्यतन करना शामिल है। 'PCER' (सजगता, सीमित करना, नष्ट करना, और पुनर्स्थापना) अक्षरों को याद रखना गलत है; सही प्रवाह सजगता -> व्याख्या/पता लगाना -> सीमित करना/नष्ट करना/पुनर्स्थापना -> घटना के बाद की गतिविधि है।
In the context of identity and access management, what does the principle of 'least privilege' primarily enforce?
श्रेणी के नामांकन और पहुंच प्रबंधन के संदर्भ में, 'कम से कम अधिकार' के सिद्धांत का मुख्य रूप से क्या प्रभावी होता है, इसका विवरण निम्नलिखित है:
कम से कम अधिकार एक मूलभूत सुरक्षा अवधारणा है जो उपयोगकर्ताओं, कार्यक्रमों या प्रक्रियाओं को उनके अधिकृत कार्यों को पूरा करने के लिए आवश्यक न्यूनतम स्तर की पहुंच (अनुमतियां, अधिकार, अधिकार) प्रदान करती है - और अधिक नहीं। यह दुर्घटनाओं, त्रुटियों या अनधिकृत उपयोगकर्ता क्रेडेंशियल्स के दुरुपयोग के संभावित नुकसान को सीमित करता है। यह पहुंच नियंत्रण रणनीतियों का एक मूलभूत घटक है। विकल्प बी सत्र समयबद्धता का वर्णन करता है, जो एक संबंधित लेकिन विशिष्ट नियंत्रण है। विकल्प सी समय पर पहुंच रद्दीकरण का एक हिस्सा वर्णित करता है, जो अक्सर प्रोविजनिंग सिस्टम द्वारा समर्थित होता है। विकल्प डी मल्टी-फैक्टर ऑथेंटिकेशन (एमएफए) का वर्णन करता है, जो पोस्ट-ऑथेंटिकेशन के बाद प्रदान किए गए पहुंच के स्तर को मजबूत करता है लेकिन सीधे परिभाषित नहीं करता है। कम से कम अधिकार का उद्देश्य किसी भी दिए गए खाते के 'हटारा सतह' या 'विस्फोट का क्षेत्रफल' को कम करना है।
Attackers on a user VLAN send forged ARP replies after obtaining an IP address from DHCP. The switch can build a trusted binding table from DHCP assignments. Which controls should be paired?
Secure Web Application Deployment A company is deploying a new customer-facing web application. The architecture includes a web server, an application server, and a database server, each on a separate host. The security team mandates that all communication between these tiers must be protected against eavesdropping and tampering.
Which of the following represents the MOST secure and practical network segmentation design to support this requirement?
विवरण: सुरक्षित वेब अनुप्रयोग प्रेषण
एक कंपनी एक नया ग्राहक-मुख्य वेब अनुप्रयोग प्रेषित कर रही है। वास्तुकला में एक वेब सर्वर, एक अनुप्रयोग सर्वर, और एक डेटाबेस सर्वर शामिल हैं, जिनमें प्रत्येक एक अलग होस्ट पर है। सुरक्षा टीम द्वारा मांग की गई है कि इन तीरों के बीच की सभी संचार को चोरी और हेरफेर के खिलाफ सुरक्षित किया जाए।
एक बहु-तीर सेगमेंटेशन मॉडल (वेब तीर, अनुप्रयोग/व्यवसायिक तर्क तीर, डेटा तीर) पूर्णतः सुरक्षित है। वेब सर्वर, जो सबसे अधिक उजागर है, डीएमजेड में रहता है। अनुप्रयोग सर्वर, जो सीधे इंटरनेट तक पहुंच योग्य नहीं होना चाहिए, एक अलग, अधिक सुरक्षित क्षेत्र (कभी-कभी 'मिडलवेयर' या 'अनुप्रयोग' डीएमजेड कहा जाता है) में रखा जाता है। डेटाबेस सर्वर, जो सबसे संवेदनशील डेटा रखता है, सबसे विश्वसनीय आंतरिक नेटवर्क सेगमेंट पर रखा जाता है। प्रत्येक क्षेत्र के बीच फ़ायरवॉल सख्त नियमों को लागू करते हैं (उदाहरण के लिए, डीएमजेड केवल विशिष्ट पोर्ट पर ऐप ज़ोन से बात कर सकता है, ऐप ज़ोन विशिष्ट पोर्ट पर डीबी से बात कर सकता है)। यह एक तीर को प्रभावित होने पर लेटरल गतिविधि को सीमित करता है। विकल्प बी आम है लेकिन कम सुरक्षित है क्योंकि यह ऐप और डीबी को एक साथ समूहित करता है। विकल्प ए कोई सेगमेंटेशन प्रदान नहीं करता है। विकल्प डी को यदि रिवर्स प्रॉक्सी हैक हो जाता है तो आंतरिक नेटवर्क को अनावश्यक रूप से उजागर करता है।
An endpoint fails posture checks because EDR is disabled and critical patches are missing. The access switch should allow remediation services but block normal production access. Which network control supports this?
करियर के अवसर और वेतन
जब तक लोकल रेंज न दिखे, ये US मार्केट के आंकड़े हैं।