156-110 Sample Questions & Answers
Free Security Principles Associate (CCSPA) practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.
Launch the full 156-110 simulator →Showing 6 of 12 free samples.
- Question 1
Which type of access management uses information about job duties and positions, to indicate subjects' clearance levels?
Show answer & explanation
Correct answer: B
Role-based access control (RBAC) uses job duties and organizational positions to determine subjects' clearance levels and access permissions, mapping users to predefined roles that reflect their responsibilities within the organization. This approach streamlines access management by grouping permissions based on functional requirements rather than individual user attributes. Discretionary access control allows owners to set permissions, mandatory access control uses security labels and classifications, nondiscretionary access control is system-enforced, and hybrid approaches combine multiple models but don't specifically use job position information as the primary determinant.
- Question 2
A(n) __________ is a one-way mathematical function that maps variable values into smaller values of a fixed length.
Show answer & explanation
Correct answer: D
A hash function is a one-way mathematical function that takes variable-length input data and produces a fixed-length output value (hash or digest), commonly used for data integrity verification, digital signatures, and password storage in security systems. The one-way property means it's computationally infeasible to reverse the process and derive the original input from the hash value. Symmetric keys are used for encryption/decryption, algorithms are broader computational procedures, backdoors are unauthorized access methods, and integrity is a security principle that hash functions help achieve rather than being the function itself.
- Question 3
INFOSEC professionals are concerned about providing due care and due diligence. With whom should they consult, when protecting information assets?
Show answer & explanation
Correct answer: E
INFOSEC professionals must consult with their organization's legal experts when implementing due care and due diligence measures because legal requirements vary by jurisdiction, industry regulations, and organizational context, and legal counsel ensures compliance with applicable laws and standards. Due diligence requires demonstrating reasonable care in protecting information assets, which has specific legal implications and liability considerations. Law enforcement, senior management, IETF officials, and other INFOSEC professionals provide valuable input but cannot provide the authoritative legal guidance necessary for proper due care implementation.
- Question 4
Which of the following is the BEST method for managing users in an enterprise?
Show answer & explanation
Correct answer: D
Placing users in a centralized Lightweight Directory Access Protocol (LDAP) directory provides the best enterprise user management by creating a single, standardized repository for user accounts, credentials, and attributes that can be accessed by multiple systems and applications. LDAP enables centralized administration, consistent user policies, and simplified authentication across the enterprise. Spreadsheets lack security and scalability, centralized access control is a concept rather than implementation method, Kerberos is an authentication protocol but not a user management system, and DNS resolves domain names rather than managing user accounts.
- Question 5
A(n) _________ is an abstract machine, which mediates all access subjects have to objects.
Show answer & explanation
Correct answer: B
A reference monitor is an abstract machine concept in computer security that mediates all access attempts by subjects (users, processes) to objects (files, resources), ensuring that security policies are enforced for every access request. The reference monitor validates permissions, logs access attempts, and prevents unauthorized access according to defined security policies. Access Control Lists (ACLs) are implementation mechanisms, state machines are computational models, Trusted Computing Base (TCB) is the security-critical hardware/software components, and routers are network devices that don't provide comprehensive access mediation.
- Question 6
Why should the number of services on a server be limited to required services?
Show answer & explanation
Correct answer: A
Every open service on a server represents a potential vulnerability because each service provides an attack vector that could be exploited by malicious actors, expanding the attack surface and increasing security risks. Following the security principle of minimal exposure, servers should only run services essential for their intended function to reduce the number of potential entry points for attackers. The incorrect options present false information: closed systems don't require special connectivity services, extra services decrease rather than increase efficiency due to resource consumption, services are not inherently secure and require proper configuration and maintenance, and additional services definitely do not improve security.
Ready for the real thing?
The full 156-110 simulator has every exam-style question, timed mode, and instant scoring.