Systems Security Certified Practitioner – SSCP – Question0386

Which of the following is not a form of passive attack?

A.
Scavenging
B. Data diddling
C. Shoulder surfing
D. Sniffing

Correct Answer: B

Explanation:

Data diddling involves alteration of existing data and is extremely common. It is one of the easiest types of crimes to prevent by using access and accounting controls, supervision, auditing, separation of duties, and authorization limits. It is a form of active attack. All other choices are examples of passive attacks, only affecting confidentiality. Source: HARRIS, Shon, All-In-One CISSP Certification Exam Guide, McGraw-Hill/Osborne, 2002, Chapter 10: Law, Investigation, and Ethics (page 645).