Be able to select the best operational control for a scenario and justify it using risk: severity, active exploitation, and asset criticality. The single most important thing is prioritizing remediation by real business impact, not raw CVSS score alone.
Start practicing
Security Operations and Administration — choose a session length
Free · No account required
Domain overview
Security Operations and Administration covers the day-to-day controls that keep systems trustworthy: asset inventory, configuration and change management, patch management, security awareness, physical/environmental controls, and incident response support. Questions are scenario-based, asking you to pick the best administrative or operational action, recognize process gaps, and apply risk-based prioritization rather than recite definitions.
Exam objectives
Using a hardened baseline and configuration monitoring to detect drift, as with SIEM alerts on changed server settings.
Prioritizing patching by combining CVSS severity, active exploitation (KEV), and asset criticality/business impact.
Identifying patch management audit gaps such as no inventory, no testing, no rollback, or no verification of deployment.
Applying administrative controls: least privilege, separation of duties, security awareness training, and formal change management.
Treating CVSS score alone as the priority; a 9.8 on a low-criticality, non-exploited host may rank below an exploited medium-severity issue on a critical system.
Confusing configuration management with patch management: baselines and drift detection are not the same as deploying missing software updates.
Assuming a patch is complete once deployed; verification, testing, and rollback planning are required to close the process gap.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company wants to ensure that employees understand the proper use of corporate email and internet. Which policy should they implement?
2During a security audit, it is found that several employees have written their passwords on sticky notes attached to their monitors. Which policy is being violated?
3A security awareness training program is being developed. Which topic is most important to include to reduce the risk of credential theft?
4A security metric shows that patch compliance is at 85%. The goal is 95%. Which action should be taken first?
5A change request to update a critical database server has been approved by the Change Advisory Board (CAB). During testing, a major compatibility issue is discovered. What is the best course of action?
6A security administrator needs to ensure that all servers are configured with a hardened baseline. Which tool is best suited to detect deviations from the baseline configuration?
7A company wants to track all hardware assets including serial numbers and locations. What is the primary repository for this information?
8An organization uses a mantrap at its main entrance. An employee badges in, enters the first door, but then the second door fails to open. What should the employee do?
9Which backup type copies all data that has changed since the last full backup, regardless of subsequent backups?
10A critical vulnerability with a CVSS score of 9.8 is discovered in a web server that cannot be patched due to vendor dependency. What is the best compensating control?
11Which of the following is a key principle of the 3-2-1 backup rule?
12A security administrator receives an alert from the SIEM indicating a configuration change on a critical server. The change was not part of any approved change request. What should be the first step?
13A company is implementing a new access control system for its data center. Which physical security control is best for preventing tailgating?
14A patch management process is being audited. Which finding indicates a critical gap in the process?
15A security administrator is selecting security metrics for the organization. Which TWO metrics are most useful for measuring the effectiveness of patching? (Select TWO)
16A company is implementing a change management process. Which THREE elements are essential for every change request? (Select THREE)
17An organization is enhancing its backup strategy. According to the 3-2-1 rule, which THREE characteristics must the backup strategy include? (Select THREE)
18A security administrator is designing physical security for a high-security area. Which TWO controls are most effective for preventing unauthorized entry? (Select TWO)
19During a change management process, the Change Advisory Board (CAB) has approved a change to update a critical database server. After implementation, a rollback is necessary due to unforeseen performance issues. What should the change manager do next?
20Which of the following backup methods copies all data that has changed since the last full backup, regardless of any intermediate backups?
21A company is implementing a new patch management process. After scanning for missing patches, the team must prioritize which patches to apply first. Which combination of factors is most critical for prioritization?
22Which of the following is the primary purpose of a configuration management database (CMDB)?
23An organization wants to ensure that all new servers are deployed with a hardened baseline configuration. Which of the following is the most effective control to enforce this?
24A security metric tracking the percentage of systems with critical patches applied within 48 hours is an example of which type of metric?
25Which of the following is the correct order of steps in the change management process?
26A security administrator needs to dispose of hard drives that contain sensitive data. Which method provides the highest assurance that data cannot be recovered?
27An organization's security policy requires that all portable media containing sensitive data be encrypted. Which type of control does this requirement represent?
28A company's backup strategy uses a full backup on Sundays and differential backups on other days. On Thursday, the storage system fails. How many backups are required to restore the data?
29A security administrator is implementing physical security for a data center. Which THREE of the following controls should be included to provide layered security?
30Which THREE of the following are examples of security awareness training topics?
31An organization is implementing a software inventory management process. Which TWO of the following should be tracked for each software asset?
32Which TWO of the following are valid reasons to deny a change request during the CAB approval process?
33A security administrator is implementing a policy that requires all employees to use a password manager and enable multi-factor authentication. This policy is BEST described as a:
34A company has a backup policy that performs a full backup every Sunday and incremental backups on other days. On Wednesday, a server fails. How many backup sets are needed to restore the server to its state on Tuesday night?
35Which of the following is the PRIMARY purpose of implementing a clean desk policy?
36An organization wants to ensure that servers are configured securely before deployment. They plan to use a hardened operating system image and regularly scan for deviations using SCAP. Which concept does this represent?
37Which of the following physical security controls is designed to prevent tailgating by requiring two doors to be interlocked?
38A company uses a backup strategy that backs up all data every Sunday and backs up only data that has changed since the last full backup on other days. This is an example of which backup type?
39A vulnerability scan identifies a critical vulnerability on a web server with a CVSS score of 9.8. The server hosts a public-facing application. However, the patch would require a reboot that would cause downtime during business hours. What should the security administrator do FIRST?
40An employee is leaving the company. As part of the offboarding process, which action should be taken regarding the hardware assigned to the employee?
41Which of the following is the BEST definition of Recovery Point Objective (RPO)?
42A security administrator is reviewing log files and notices that a user logged in at 3:00 AM from an IP address in a foreign country. The user's manager confirms the user is not authorized for remote access. Which type of policy has likely been violated?
43During a post-implementation review of a change, it is discovered that the change introduced a configuration deviation from the baseline. The deviation was not detected during testing. What is the BEST way to prevent this in the future?
44An organization wants to ensure that sensitive data on laptops is protected in case of loss or theft. Which control is MOST effective?
45Which THREE of the following are valid steps in the change management process? (Select THREE)
46Which TWO of the following are examples of physical security controls? (Select TWO)
47Which THREE of the following are critical elements of a patch management policy? (Select THREE)
48Which TWO of the following are key components of a configuration management database (CMDB)? (Select TWO)
49A security awareness training program aims to reduce successful phishing attacks. Which metric is most appropriate for measuring the effectiveness of this training?
50What is the primary purpose of a baseline configuration in configuration management?
51An organization uses a SIEM to alert when a server's configuration changes from its hardened baseline. This is an example of:
52Which backup type copies all data that has changed since the last full backup, regardless of any incremental backups?
53An organization needs to recover data from a backup after a ransomware attack. The backup was taken 12 hours ago, and the RPO is 4 hours. What is the impact?
54A security administrator is prioritizing patches for a vulnerability with a CVSS score of 9.8 that is being actively exploited in the wild. The affected server has a low criticality classification. What should the administrator do?
55Which physical security control is designed to prevent tailgating by allowing only one person to enter at a time?
56An organization's backup policy states: 'Maintain three copies of data on two different media types, with one copy stored offsite.' This is known as:
57After a patch is deployed to a critical server, the system becomes unstable. The change management plan includes a rollback procedure. What should be done FIRST?
58Which TWO controls are examples of physical security controls that can help prevent unauthorized access to a data center? (Select TWO.)
59A security administrator is implementing the 3-2-1 backup rule. Which THREE actions are required to comply with this rule? (Select THREE.)
60A security administrator at a financial services firm is reviewing the organization's data retention practices. The legal team has mandated that certain transaction records be kept for exactly seven years and then destroyed. The administrator must ensure records are deleted automatically after seven years. Which of the following should be implemented to enforce this requirement?
61A security administrator at a healthcare company must ensure that audit logs from a critical patient-record system are retained for seven years and cannot be altered even by system administrators. Which solution BEST meets these requirements?
62A security administrator is implementing a new access control system. The organization wants to ensure that users are granted only the permissions necessary to perform their job functions and nothing more. Which principle is being applied?
63A security administrator is conducting a risk assessment for a new cloud-based application. The administrator needs to identify TWO factors that are most important when determining the appropriate security controls for the application. (Choose two.)
64A security administrator is reviewing the organization's data retention policy. The policy states that customer financial records must be kept for seven years, but the IT team currently archives them indefinitely. Which action should the administrator take to align data handling with the policy while preserving records for legal discovery?
65A security administrator is configuring a new web server and wants to ensure that the server's operating system and applications are hardened according to organizational standards. Which of the following should the administrator apply to enforce the desired security settings?
66A payroll administrator at a healthcare company resigns. On her last day, the security team must ensure she can no longer access the HR payroll application, but her mailbox must remain active for 30 days so her manager can review pending correspondence. Which access management action BEST meets these requirements?
67A security administrator is reviewing audit logs and discovers that a user account with administrative privileges was used to access a file server outside of normal business hours. The administrator needs to determine whether this access was authorized. Which of the following should the administrator do FIRST?
68A security administrator is reviewing an incident response plan and finds that the team has no agreed way to classify how severe a detected event is before deciding whether to escalate. Which artifact should be created to standardize this decision?
69A security administrator needs to ensure that only authorized devices can connect to the corporate wireless network. Which of the following should be implemented to meet this requirement?
70A security administrator is implementing a new system that will process credit card payments. The organization must comply with PCI DSS. Which of the following controls is specifically required by PCI DSS to protect stored cardholder data?
71A security administrator is implementing a defense-in-depth strategy for a new data center. Which of the following BEST describes the role of security awareness training within this strategy?
72A financial services firm must demonstrate to auditors that access to its core banking platform follows least privilege and is reviewed regularly. Which TWO practices BEST support this objective? (Choose two.)
73A security administrator needs to ensure that a terminated employee loses access to all systems immediately upon departure. Which action best accomplishes this?
74A security administrator is implementing a solution to detect unauthorized changes to critical system files on a server. Which of the following technologies is BEST suited for this purpose?
75A security administrator is drafting a data handling standard for a retail company that processes payment cards. The standard must state how long transaction records may be retained and how they must be destroyed. Which source should PRIMARILY drive these retention and destruction requirements?
76A security administrator must verify that a third-party service provider meets the organization's security requirements before signing a contract. The provider will process regulated customer data. Which action provides the most reliable assurance?
77A healthcare organization's security team is reviewing a third-party cloud provider that will store electronic protected health information. The provider's SOC 2 Type II report is two years old, and the provider has since migrated to a new data center. Which action should the security administrator take FIRST to determine whether the provider still meets the organization's security requirements?
78A security administrator is reviewing the organization's account management process. The policy states that user accounts must be reviewed at least quarterly to ensure that only authorized individuals retain access. During an audit, it is discovered that several former employees still have active accounts. Which of the following is the MOST appropriate action to address this finding?
79A security administrator is reviewing the organization's backup strategy for a database server that must meet a recovery point objective (RPO) of 15 minutes. The server currently uses a full backup every Sunday and differential backups every night. The administrator finds that the current strategy cannot meet the RPO. Which backup method should the administrator implement to meet the RPO while minimizing backup storage consumption?
80A financial services firm is implementing role-based access control for its trading platform. An auditor finds that several traders can approve their own trades in addition to executing them. Which principle is being violated, and which control should the security administrator implement to remediate the finding?
81A security administrator is implementing a new file integrity monitoring (FIM) solution on critical servers. The administrator needs to ensure that the solution can detect unauthorized changes to system binaries and configuration files. Which of the following should the administrator configure to establish a trusted baseline for the FIM solution?
82A security administrator is tasked with implementing a formal process for managing user access rights. The organization requires that access be granted based on job roles and that users receive only the permissions necessary to perform their duties. Which of the following should the administrator implement?
83A security administrator is reviewing the organization's account management procedures. The administrator discovers that user accounts for terminated employees remain active for up to 30 days after departure. Which account management control should the administrator implement to address this risk?
84A security administrator is reviewing the organization's incident response plan. The plan must include procedures for handling security incidents. Which of the following are appropriate steps to include in the incident response process? (Choose two.)
85A security administrator is reviewing the organization's security awareness training program. The administrator wants to measure whether employees can recognize and report phishing emails. Which metric BEST measures the effectiveness of the training?
86A security administrator is tasked with implementing a defense-in-depth strategy for the organization's data center. The administrator wants to ensure that physical access to servers is restricted to authorized personnel only. Which of the following controls should be implemented to achieve this?
87A security administrator is implementing a mandatory vacation policy for employees in sensitive roles. The administrator needs to ensure that the policy supports the detection of fraudulent activities. Which control should be implemented alongside mandatory vacations to maximize its effectiveness?
88A security administrator is implementing a data loss prevention strategy for a company that handles credit card data. The administrator must ensure the organization meets PCI DSS requirements for protecting stored cardholder data. Which TWO practices should the administrator implement? (Choose two.)
89A security administrator is implementing a security awareness training program. The administrator wants to measure the effectiveness of the training in reducing phishing susceptibility. Which of the following metrics would be MOST indicative of the training's success?
90A security administrator is reviewing the account lifecycle process for a large retail company. An employee in the accounting department has been promoted to a role in the same department that requires access to the payroll system, while the employee's previous duties no longer require access to the accounts payable system. Which action should the administrator take to ensure least privilege is maintained?
91A security administrator is implementing a formal data retention and destruction program for a financial services firm. The firm stores customer records, transaction logs, and email archives on a variety of media, including solid-state drives, magnetic tapes, and cloud object storage. Which TWO practices should the administrator include to ensure data is destroyed in a manner that is both effective and auditable? (Choose two.)
92A security administrator is reviewing the organization's awareness program after a recent phishing campaign. Several employees clicked the link, and one entered credentials on the fake page. The administrator wants to reduce the likelihood of credential theft in future campaigns. Which control should the administrator implement to best address this risk?
93A security administrator at a software company is reviewing the organization's security assessment strategy. The administrator must select an assessment method that evaluates the effectiveness of implemented controls through direct observation and testing, rather than relying on interviews or documentation review alone. Which assessment method should the administrator choose?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to select the best operational control for a scenario and justify it using risk: severity, active exploitation, and asset criticality. The single most important thing is prioritizing remediation by real business impact, not raw CVSS score alone.
The Courseiva SSCP question bank contains 93 questions in the Security Operations and Administration domain, covering the 16% of the exam attributed to this domain in the official ISC2 blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security Operations and Administration domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included