<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Incorrect answers i the SSCP Quizlet in Exam Preparation</title>
    <link>https://community.isc2.org/t5/Exam-Preparation/Incorrect-answers-i-the-SSCP-Quizlet/m-p/64513#M4110</link>
    <description>&lt;P&gt;I took the quiz and for number 3, I don't believe that it is a well written question as it is open ended and could have multiple partially correct answers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on the actual question (9) I can see why you might pick C.&amp;nbsp; Personally have an issue with this question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There are four common risk mitigation strategies. Typically the most common include&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;avoidance, reduction, transference, and acceptance&lt;/STRONG&gt;&lt;SPAN&gt;. There are others (risk sharing, risk buffering, etc.)&amp;nbsp; The question actually lists transference, acceptance and avoidance as distractors&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I believe the question needs to be reviewed and maybe rewritten.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;mhoo&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;d&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Nov 2023 22:27:09 GMT</pubDate>
    <dc:creator>dcontesti</dc:creator>
    <dc:date>2023-11-13T22:27:09Z</dc:date>
    <item>
      <title>Incorrect answers i the SSCP Quizlet</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Incorrect-answers-i-the-SSCP-Quizlet/m-p/64489#M4108</link>
      <description>&lt;P&gt;Hello.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV&gt;I just took the SSCP readiness quiz found in the link below. Of the ten questions, two of them were marked as "incorrect". There's no feedback on the quizlet, so I'd like your feedback since I think the answer from ISC2 in the Quizlet is incorrect in both instances.&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Question 3 describes an integrity requirement: you prevent fraud by assuring the integrity of the data, which is why I answered b). ISC2 tells me this is incorrect and that the correct answer is d), which is the definition of Availability; I don't think data availability prevents fraud, although ensuring only valid users have access goes some way, if you cannot assure the integrity, then valid users can still conduct fraud by covering their tracks.&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;On question 9, they ask, "What other form of Risk Management will also be included?" I answered c) because Risk Capture is what you do immediately after risk identification. You identify a risk, then capture it in the risk register, so it comes before Risk Mitigation and is always included in the Risk Mitigation process. "Risk acceptance" according to CISSP OSG (Page 67) "...is the result, after a cost/benefit analysis shows that countermeasure costs [i.e. Mitigations] outweigh the possible costs of loss due to a risk." In other words, Risk Acceptance is what you do if you don't want to do Risk Mitigation.&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Who is wrong here? Me or ISC2? If it's me, please explain. Thank you&amp;nbsp;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;Quizlet can be found here&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;A class="" href="https://l.facebook.com/l.php?u=https%3A%2F%2Fcloud.connect.isc2.org%2Fsscp-quiz%3Ffbclid%3DIwAR0G7ZMSBuKeMxEGQHHpo-GqiJ9o0JoIyrlw0yfTgBcnQtq5XBJDCwdHvy0&amp;amp;h=AT2-KWwxt4uM3-_7By4HK2LfEuuNxmyk_ws6rhjMCTCxiSZMZonCwowESNUIqLcUzcxEdo0a7WQy9bRptiKGcEOOJqI_uj7NAXrTebFdY2JVWMKRMmooM7zyTO6AQo0QnJvC&amp;amp;__tn__=-UK-R&amp;amp;c[0]=AT0tzxyPpxvCAgQlMhLKYn-CwvG0oHHNyE3bn0eIhMoc2Qt59QZlNuHUxBIxMv-ypIDMXKa3snZlnVWyEr529gcaJV3tMQaK6SYU1Y-Uc9zJ5_6t0MKIY-6oJwokBRb0Y_B9owsQOqn1R3mEBsFHcnspT8JhTIUu-VOyO3U" target="_blank" rel="nofollow noopener noreferrer"&gt;https://cloud.connect.isc2.org/sscp-quiz&lt;/A&gt;&lt;/SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-11-13 130441.png" style="width: 999px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/7915i11547474DBEF4DDD/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-11-13 130441.png" alt="Screenshot 2023-11-13 130441.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-11-13 130648.png" style="width: 999px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/7916iB3A0F7DF632C13E3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-11-13 130648.png" alt="Screenshot 2023-11-13 130648.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 13 Nov 2023 13:23:03 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Incorrect-answers-i-the-SSCP-Quizlet/m-p/64489#M4108</guid>
      <dc:creator>JonP</dc:creator>
      <dc:date>2023-11-13T13:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect answers i the SSCP Quizlet</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Incorrect-answers-i-the-SSCP-Quizlet/m-p/64494#M4109</link>
      <description>I guess the first question is talking about authorisation as well as availability- I assume the author may clumsily be hinting about confidentiality - data theft from improper access would also be fraudulent, it’s a poorly written question by the looks I’d fall on integrity however.&lt;BR /&gt;&lt;BR /&gt;Second one I’d fall down more on the authors side - after the risk is mitigated with a compensating control residual risk would need to be accepted. Putting it in the risk register would be something you’d do for any risk you hadn’t got down to zero.&lt;BR /&gt;&lt;BR /&gt;Just quick thoughts.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 13 Nov 2023 14:03:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Incorrect-answers-i-the-SSCP-Quizlet/m-p/64494#M4109</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2023-11-13T14:03:59Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect answers i the SSCP Quizlet</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Incorrect-answers-i-the-SSCP-Quizlet/m-p/64513#M4110</link>
      <description>&lt;P&gt;I took the quiz and for number 3, I don't believe that it is a well written question as it is open ended and could have multiple partially correct answers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on the actual question (9) I can see why you might pick C.&amp;nbsp; Personally have an issue with this question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There are four common risk mitigation strategies. Typically the most common include&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;avoidance, reduction, transference, and acceptance&lt;/STRONG&gt;&lt;SPAN&gt;. There are others (risk sharing, risk buffering, etc.)&amp;nbsp; The question actually lists transference, acceptance and avoidance as distractors&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I believe the question needs to be reviewed and maybe rewritten.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;mhoo&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;d&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 22:27:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Incorrect-answers-i-the-SSCP-Quizlet/m-p/64513#M4110</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2023-11-13T22:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect answers i the SSCP Quizlet</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Incorrect-answers-i-the-SSCP-Quizlet/m-p/64528#M4112</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/797288093"&gt;@Early_Adopter&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I think in the first one we need to revert to the syllabus.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If, as you assume, it's a clumsy reference to access controls, then there are two points to be made:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- First, access controls as described in the answer, only addresses threats from external actors, not insider threats.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Second, the response I made is the definition of Integrity (According to the exam itself, in another question it asked what the definition of integrity was, I answered this, and the answer was marked correct.) So if I revert to ISC2's definition of Integrity,&amp;nbsp;according to ISC2's CISSP Exam Study Guide, 9th edition, page 6&lt;/P&gt;&lt;P&gt;"Integrity can be examined from 3 perspectives:&lt;BR /&gt;1 - Preventing unauthorised subjects from making changes.&lt;BR /&gt;2 - Preventing authorised subjects from making unauthorised changes.&lt;BR /&gt;3 - Maintaining internal and external consistency of objects so that their data is a correct and true reflection of the real world and any relationship with any other object is valid, consistent and verifiable"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we consider perspective 1, this matches with the authorisation requirement in answer c) given by ISC2 as the correct answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we consider perspective 2, this surpasses the answer given by ISC2 by adding additional controls on authorised users, therefore b) is the better answer because it includes any controls in answer c) and additional controls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did some research after posting this, and I agree with your conclusion about the Risk Management question, especially since "Risk capture" is not a recognised Risk Management process.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 13:42:43 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Incorrect-answers-i-the-SSCP-Quizlet/m-p/64528#M4112</guid>
      <dc:creator>JonP</dc:creator>
      <dc:date>2023-11-14T13:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect answers i the SSCP Quizlet</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Incorrect-answers-i-the-SSCP-Quizlet/m-p/64529#M4113</link>
      <description>Hey Jon,&lt;BR /&gt;&lt;BR /&gt;We’re in concurrence on the first one - I’d almost certainly answer integrity as the best fit as the question is written - though I’d disagree on your first assumption in that you can easily have a population of authorised and non- authorised users. We could add R, W, M to what our authorised users could do - then we’re into fraud by improper modification(W,M) vs fraud by theft(R) - (I steal your info and use to to pretext) though we’re assuming “availability to authorised users” means authorised users only do correct things intentionally- any user monitoring system is going to keep an accountable record of what users did and there will be some verification of the users work. Horrible question, and I think we’re being over-generous to it to it…&lt;BR /&gt;&lt;BR /&gt;“Now I’ve caught you … you Risk you!!!” &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;</description>
      <pubDate>Tue, 14 Nov 2023 14:00:17 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Incorrect-answers-i-the-SSCP-Quizlet/m-p/64529#M4113</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2023-11-14T14:00:17Z</dc:date>
    </item>
  </channel>
</rss>

