ISC2 · Free Practice Questions · Last reviewed May 2026
42real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
15% of exam · 6 sample questions below
A security analyst is reviewing logs and notices multiple failed login attempts for a user account, followed by a successful login from an unfamiliar IP address at 3:00 AM. Which type of risk is most directly indicated by this scenario?
Environmental risk
Human intentional risk
Repeated failed logins followed by a successful login from an unfamiliar IP at 3:00 AM indicates deliberate credential attack or account compromise. A person intentionally attempted unauthorised access, which is human intentional risk rather than accidental or environmental risk.
Human accidental risk
Technical risk
An organization calculates the SLE for a server as $5,000 and the ARO as 0.2. What is the ALE?
$5,000
$10,000
$25,000
$1,000
Multiplying the single loss expectancy of $5,000 by the annualised rate of occurrence of 0.2 yields an annualised loss expectancy of $1,000. This satisfies the stem's requirement to derive the expected yearly financial loss from the two supplied quantitative risk values.
During a vulnerability scan, a security analyst discovers that several workstations are missing critical security patches. The organization decides to implement a compensating control by restricting network access to these workstations until patches are applied. Which risk response strategy is being used?
Avoidance
Mitigation
Mitigation reduces risk likelihood or impact through controls, and restricting network access to unpatched workstations does exactly that by shrinking their exposure while patching is pending. It satisfies the stem's compensating-control constraint, since the underlying vulnerability remains until patches are applied, but the residual risk is lowered.
Transfer
Acceptance
Which type of IDS uses a baseline of normal behavior to detect anomalies?
Host-based IDS (HIDS)
Anomaly-based IDS
Anomaly-based IDS builds a statistical or behavioural baseline of normal activity, then flags deviations from it as potential intrusions. This directly satisfies the stem's requirement for a baseline of normal behaviour, unlike signature-based detection, which matches known attack patterns rather than profiling legitimate traffic.
Network-based IDS (NIDS)
Signature-based IDS
An organization uses User Behavior Analytics (UBA) to detect insider threats. Which of the following activities would most likely trigger an alert for a compromised account?
User receives a large number of emails
User logs in from a recognized corporate device
User attempts to access a database at 2:00 AM, which is outside their normal pattern
UBA baselines each user's normal behaviour, so a 2:00 AM database access falling outside that learned pattern deviates from the established profile. This temporal anomaly is exactly the behavioural signal UBA is designed to flag for a potentially compromised account.
User accesses the same files as usual during business hours
Which of the following is a vulnerability source explicitly based on publicly known flaws?
Configuration weaknesses
Hardware failure
CVEs
CVEs are identifiers assigned to publicly disclosed flaws in specific products, so they directly satisfy the stem's requirement for a vulnerability source based on publicly known issues. Unlike proprietary or internal findings, each CVE entry is catalogued and openly accessible, letting analysts correlate exposures against vendor advisories.
Design flaws
Want more Risk Identification, Monitoring, and Analysis practice?
Practice this domainA security administrator is implementing an access control model that assigns permissions based on the clearance of the subject and the classification of the object. Which model is being implemented?
Role-Based Access Control (RBAC)
Discretionary Access Control (DAC)
Attribute-Based Access Control (ABAC)
Mandatory Access Control (MAC)
Mandatory Access Control enforces access decisions through system-assigned labels: each subject holds a clearance and each object a classification, and the operating system compares these to grant or deny access. Because users cannot alter labels or delegate permissions, this satisfies the stem's requirement that permissions derive from clearance and classification rather than owner discretion.
Which access control model enforces the principle of least privilege by granting permissions based on job functions and requires separation of duties?
Attribute-Based Access Control (ABAC)
Role-Based Access Control (RBAC)
RBAC assigns permissions to roles defined by job function rather than to individuals, so users receive only the access their duties require. Roles can also be structured to enforce separation of duties, satisfying both least privilege and the split-responsibility constraint in the stem.
Mandatory Access Control (MAC)
Discretionary Access Control (DAC)
An organization requires users to authenticate using a password and a one-time code from a mobile app. Which authentication method is being used?
Time-based One-Time Password (TOTP)
TOTP generates a code from a shared secret and the current time, so the mobile app produces a fresh one-time code every 30 seconds. Combined with the password, this delivers the two distinct factors the stem requires, satisfying the multi-factor authentication constraint.
Smart card
Hardware token
Biometrics
A company is implementing a Single Sign-On (SSO) solution that uses XML-based assertions to exchange authentication and authorization data between an identity provider and a service provider. Which protocol is being used?
Kerberos
SAML
SAML exchanges authentication and authorisation data as XML assertions between an identity provider and a service provider, exactly the flow described. Its assertion-based, XML-encoded token format is the defining characteristic distinguishing it from other SSO protocols.
OAuth 2.0
OpenID Connect
An organization wants to ensure that privileged accounts are used only when needed and that all activities are recorded. Which Privileged Access Management (PAM) control should be implemented?
Password vaulting
Role-based access control
Multi-factor authentication
Just-in-Time (JIT) provisioning with session recording
Just-in-Time provisioning grants privileged rights only for the required window, then revokes them, satisfying the 'only when needed' constraint. Session recording captures all privileged activity for audit, meeting the recording requirement. Standing admin rights would fail both conditions.
A security analyst is evaluating a biometric system. The system currently has a high number of false rejections. Which metric is most directly related to this issue?
False Acceptance Rate (FAR)
Equal Error Rate (EER)
Crossover Error Rate (CER)
False Rejection Rate (FRR)
False Rejection Rate measures the proportion of legitimate users incorrectly denied access, which is exactly the high false-rejection symptom described. It is the biometric accuracy metric tied to Type I errors, unlike False Acceptance Rate, which covers impostors wrongly admitted.
Want more Access Controls practice?
Practice this domain14% of exam · 6 sample questions below
During which phase of the NIST SP 800-61 incident response lifecycle are incident response plan updates and lessons learned typically documented?
Preparation
Containment, Eradication, and Recovery
Detection and Analysis
Post-Incident Activity
Post-Incident Activity is where the NIST SP 800-61 lifecycle captures lessons learned and revises the incident response plan. This phase explicitly covers reviewing what happened and feeding improvements back into the plan, satisfying the stem's requirement.
A security analyst receives a chain of custody form for a hard drive that was seized from a suspected insider threat. The form shows that the drive was handled by three individuals over two days. Which of the following is the PRIMARY reason for maintaining a chain of custody?
To prove that the evidence has not been tampered with and is admissible in legal proceedings
The chain of custody documents every person who handled the drive and when, proving the evidence remained unaltered since seizure. This continuity is what allows the drive to be admitted in legal proceedings against the insider threat suspect.
To determine the cost of the forensic investigation
To ensure the hard drive is stored in a secure location
To track the productivity of forensic analysts
During incident response, a team needs to isolate an infected workstation that is part of a critical manufacturing network. Which containment method is MOST appropriate to minimize disruption while preventing the spread of malware?
Place the workstation into a quarantine VLAN via switch configuration
A quarantine VLAN isolates the workstation at the switch port while leaving the manufacturing network's routing and production traffic intact. This contains malware spread with minimal disruption, unlike disabling the switch port or powering off, which would halt critical operations.
Apply a host-based firewall rule to block all inbound traffic
Physically unplug the network cable
Disable the user's Active Directory account
After a ransomware incident, an organization decides to restore data from backups. The RPO (Recovery Point Objective) is 4 hours. What does this RPO indicate?
Backups must be taken at least every 4 hours to ensure data loss does not exceed 4 hours
RPO defines the maximum tolerable data loss measured in time, so a four-hour RPO means backups must run at least every four hours; otherwise a failure could destroy more than four hours of transactions, breaching the objective.
The organization can tolerate 4 hours of downtime
The system must be restored within 4 hours of the incident
The recovery process will take a maximum of 4 hours
Which DR testing type involves running recovery systems in parallel with production systems to verify functionality without impacting live operations?
Full interruption test
Simulation test
Parallel test
A parallel test runs recovery systems alongside production, processing the same transactions in parallel, so functionality is verified without disrupting live operations. This directly satisfies the stem's constraint of validating recovery capability while leaving production systems untouched.
Tabletop exercise
During the eradication phase of a malware incident, a security analyst removes malicious files and cleans registry persistence. What is the MOST critical additional step to prevent reinfection through the same vector?
Patching the vulnerability that was exploited
Patching the exploited vulnerability closes the original entry vector, so the attacker cannot reinfect the host through the same flaw. Removing files and registry persistence alone leaves that vector open, allowing immediate recompromise during or after eradication.
Running a full antivirus scan
Resetting all user passwords
Reimaging the system with a clean OS
Want more Incident Response and Recovery practice?
Practice this domain15% of exam · 6 sample questions below
During a security assessment, it is discovered that a Linux server has unnecessary services running, including Telnet and FTP. The server is also missing critical security patches. Which of the following is the MOST effective approach to harden this server according to industry best practices?
Move the server to a more secure network segment and implement network access controls.
Enable SELinux and configure a host-based firewall using iptables.
Install a host-based intrusion detection system (HIDS) to monitor for attacks.
Disable Telnet and FTP services, and apply all critical security patches.
Disabling Telnet and FTP removes insecure cleartext protocols, while patching closes known vulnerabilities. Together they eliminate both the exposed attack surface and the exploitable flaws, satisfying the hardening requirement more completely than either measure alone.
An organization wants to prevent unauthorized applications from running on Windows workstations. Which Windows feature should be used to enforce application whitelisting?
User Account Control (UAC)
Windows Firewall with Advanced Security
Windows Defender Application Control (WDAC)
WDAC enforces application whitelisting by validating executables against code-integrity policies at the kernel level, blocking anything unsigned or untrusted. This directly satisfies the requirement to prevent unauthorised applications from running on Windows workstations, unlike AppLocker's weaker user-mode enforcement.
Windows Defender Antivirus
A cloud security team is deploying a new web application on an IaaS platform. According to the shared responsibility model, which of the following security tasks is the customer responsible for?
Network infrastructure security such as DDoS protection at the provider edge
Hypervisor security and vulnerability management
Patching the guest operating system and web server software
In IaaS, the provider secures the physical hosts, network and hypervisor only. The customer retains control of everything above the hypervisor, so patching the guest OS and web server software falls to them. This satisfies the shared responsibility split for IaaS workloads.
Physical security of the data center hosting the servers
A company uses multiple virtual machines on a single hypervisor. To prevent a VM from escaping its virtualized environment and compromising the hypervisor, which of the following should be implemented?
Use a separate network for VM management traffic
Apply hypervisor security patches and disable unnecessary VM guest tools
Patching the hypervisor closes known privilege-escalation vulnerabilities that permit VM escape, while removing unnecessary guest tools shrinks the guest-to-host attack surface, such as shared folders and clipboard channels. Together these directly satisfy the stem's requirement to stop a VM compromising the hypervisor.
Deploy a host-based firewall on each VM
Enable VM snapshots to restore in case of compromise
In Linux, which command is used to change file permissions to restrict access so that only the owner can read and write, and the group and others have no access?
chmod 600 file.txt
chmod 600 file.txt sets the permission bits to rw-------, giving the owner read and write while group and others receive none. The octal 6 encodes read (4) plus write (2) for the owner, and the two trailing zeros deny all group and other access, satisfying the stem's restriction requirement.
chown 600 file.txt
umask 077 file.txt
setfacl -m u::rw file.txt
An application security team is reviewing code for vulnerabilities. They find that user input is directly concatenated into an SQL query without sanitization. This is an example of which OWASP Top 10 vulnerability?
Injection
Direct concatenation of unsanitised input into an SQL query is classic SQL injection, which falls under the OWASP Top 10 Injection category. The stem's defining constraint — untrusted input reaching an interpreter without sanitisation — is precisely the mechanism Injection describes, making it the accurate classification.
Cross-Site Scripting (XSS)
Security Misconfiguration
Broken Access Control
Want more Systems and Application Security practice?
Practice this domain16% of exam · 6 sample questions below
A company wants to ensure that employees understand the proper use of corporate email and internet. Which policy should they implement?
Data Handling Policy
Remote Access Policy
Acceptable Use Policy
An Acceptable Use Policy defines permitted employee behaviour for corporate email and internet resources, directly addressing the stated need. It specifies what staff may and may not do with these assets, unlike password or access policies that govern credentials.
Password Policy
During a security audit, it is found that several employees have written their passwords on sticky notes attached to their monitors. Which policy is being violated?
Social Media Policy
Clean Desk Policy
A Clean Desk Policy requires sensitive information, including written credentials, to be secured or removed when workspaces are unattended. Sticky notes exposing passwords on monitors directly breach that requirement, since the policy explicitly covers physical artefacts left in plain view.
Data Handling Policy
Password Policy
A security awareness training program is being developed. Which topic is most important to include to reduce the risk of credential theft?
Proper use of social media
Physical security procedures
Recognizing phishing attempts
Phishing is the leading vector for stolen credentials, tricking users into surrendering passwords on fraudulent pages. Training staff to recognise suspicious senders, links and urgent requests directly reduces that risk, addressing the credential-theft constraint more effectively than general policy or password topics.
Data backup procedures
A security metric shows that patch compliance is at 85%. The goal is 95%. Which action should be taken first?
Increase the frequency of vulnerability scans
Disable automatic updates to prevent issues
Prioritize patching based on vulnerability criticality
Prioritising by vulnerability criticality directs remediation toward the highest-risk exposures first, satisfying the stem's requirement to close the 10% compliance gap efficiently. Rather than chasing every missing patch equally, risk-based sequencing reduces exploitable attack surface fastest when resources cannot immediately achieve full coverage.
Exclude non-critical systems from patching
A change request to update a critical database server has been approved by the Change Advisory Board (CAB). During testing, a major compatibility issue is discovered. What is the best course of action?
Report the issue to the CAB and request a revised change
The CAB owns change approval, so a discovered compatibility issue invalidates the approved change and must be escalated for reassessment. Proceeding without reapproval bypasses change control; reporting back and requesting a revised change preserves governance and satisfies the stem's testing constraint.
Reject the change request and close it permanently
Implement the change but have a rollback plan ready
Proceed with the change and resolve the issue after implementation
A security administrator needs to ensure that all servers are configured with a hardened baseline. Which tool is best suited to detect deviations from the baseline configuration?
Vulnerability scanner
Asset management database
SCAP scanner
An SCAP scanner evaluates system configurations against standardised checklists such as DISA STIG or CIS benchmarks, reporting deviations from the hardened baseline. This satisfies the requirement to detect configuration drift, which signature-based vulnerability scanners alone would not reliably identify.
SIEM
Want more Security Operations and Administration practice?
Practice this domain16% of exam · 6 sample questions below
Which protocol and port combination is commonly used for secure remote administration of a server?
HTTPS on TCP 443
Telnet on TCP 23
RDP on TCP 3389
SSH on TCP 22
SSH on TCP 22 encrypts the entire remote administration session, including credentials and commands, satisfying the requirement for secure remote server management. Unlike Telnet on port 23, which transmits data in cleartext, SSH provides confidentiality and integrity through cryptographic tunnelling, making it the standard choice for hardened administrative access.
A security analyst notices an unusual number of ARP replies on the network where one MAC address is claiming to be multiple IP addresses. Which type of attack is most likely occurring?
ARP spoofing
ARP spoofing involves an attacker sending forged ARP replies that bind one MAC address to multiple IP addresses, poisoning neighbours' ARP caches so traffic is redirected to the attacker. This matches the observed pattern of conflicting ARP mappings.
SYN flood
DNS poisoning
DHCP starvation
A company wants to deploy a firewall that can track the state of active connections and make decisions based on the context of traffic flows. Which firewall type should they choose?
Stateless packet filter
Stateful firewall
A stateful firewall maintains a connection state table, tracking each flow's context so return traffic and established sessions are evaluated against recorded states rather than static rules alone. This satisfies the requirement to make decisions based on the context of active traffic flows.
Application proxy firewall
Next-generation firewall
Which protocol is used for secure web browsing and operates on TCP port 443?
HTTPS
HTTPS wraps HTTP inside TLS, encrypting web traffic and authenticating the server, and by convention listens on TCP port 443. That combination delivers the confidentiality and integrity required for secure browsing over the specified port.
HTTP
SSH
FTP
An organization wants to ensure that only authorized devices can connect to the corporate wired network. Which technology should they implement to enforce this?
Network Access Control (NAC) with 802.1X
802.1X port-based authentication requires a supplicant to authenticate against a RADIUS server before the switch port grants access, and NAC enforces the resulting policy. Together they ensure only authorised, compliant devices can connect to the wired network.
VLAN segmentation
MAC address filtering
Firewall rules
A network administrator wants to block all inbound traffic except for web and email services. Which firewall rule configuration would achieve this?
Default-deny with allow rules for HTTP, HTTPS, and SMTP
Default-deny drops all inbound packets unless a rule explicitly permits them, so only HTTP, HTTPS and SMTP traffic reaches the internal network. This satisfies the requirement to block everything else, since any protocol without a matching allow rule is discarded at the perimeter.
Stateful inspection without default policy
Stateless packet filtering with a rule per service
Default-allow with deny rules for unwanted services
Want more Network and Communications Security practice?
Practice this domainA security analyst is recommending a symmetric encryption algorithm for a new application that requires both confidentiality and authentication. Which algorithm and mode combination should they select?
3DES-CBC
AES-ECB
RC4
AES-GCM
AES-GCM is a block cipher in Galois/Counter Mode, providing authenticated encryption: confidentiality plus an authentication tag verifying integrity and origin. This satisfies the stem's dual requirement for confidentiality and authentication in one symmetric primitive, unlike CBC or CTR, which lack built-in authentication.
An organization is implementing a digital signature solution to ensure non-repudiation of documents. Which combination of keys is used during the signing process?
Recipient's public key to sign, recipient's private key to verify
Sender's private key to sign, sender's public key to verify
Non-repudiation requires the signer to use their private key, which only they hold, and verifiers to use the corresponding public key. This asymmetric pairing proves origin and prevents the sender denying authorship of the signed document.
Sender's public key to sign, recipient's private key to verify
A shared symmetric key for both signing and verification
A company is deploying a VPN using IPsec. They want to ensure that even if the private key of the server is compromised, past session keys cannot be derived. Which key exchange method should they use?
Pre-shared key (PSK)
RSA key exchange
Ephemeral Diffie-Hellman (DHE or ECDHE)
Ephemeral Diffie-Hellman generates a fresh key pair per session, so the derived shared secret is never transmitted and cannot be recovered from the server's long-term private key. This satisfies the forward secrecy constraint: compromise of that key leaves previously negotiated session keys underivable.
Diffie-Hellman with static keys
Which of the following hash algorithms is considered cryptographically broken and should be avoided due to collision attacks?
SHA-3
SHA-256
MD5
MD5 produces a 128-bit digest and is vulnerable to practical collision attacks, so distinct inputs can yield identical hashes. This breaks integrity guarantees, making it unsuitable where collision resistance is required, unlike SHA-256 or SHA-3.
HMAC-SHA256
An organization uses a PKI with a root CA that issues certificates to intermediate CAs, which then issue end-entity certificates. A client receives an end-entity certificate signed by an intermediate CA. During validation, which certificates are required to build the chain of trust?
Only the root CA certificate
End-entity certificate, intermediate CA certificate, and root CA certificate
Validation requires the full chain from the end-entity certificate up through the issuing intermediate CA to the trusted root CA, because each signature must be verified against its issuer's public key until a trust anchor is reached.
Only the end-entity certificate and the root CA certificate
Only the end-entity certificate and the intermediate CA certificate
A security engineer needs to choose an asymmetric algorithm for a system with limited computational resources, such as an IoT device. The algorithm must provide equivalent security to RSA 2048-bit while using smaller key sizes. Which algorithm should they choose?
RSA with 2048-bit keys
Elliptic Curve Cryptography (ECC) with 256-bit keys
ECC achieves equivalent security with far smaller keys because its security rests on the elliptic curve discrete logarithm problem, which resists known sub-exponential attacks. A 256-bit ECC key matches RSA 2048-bit strength, satisfying the IoT constraint of limited computational resources and smaller key sizes.
Diffie-Hellman with 2048-bit keys
3DES with 168-bit keys
Want more Cryptography practice?
Practice this domainThe SSCP exam has 125 questions and must be completed in 180 minutes. The passing score is 700/1000.
Multiple-choice questions on access controls, security operations, risk, cryptography, network security, and incident response.
The exam covers 7 domains: Risk Identification, Monitoring, and Analysis, Access Controls, Incident Response and Recovery, Systems and Application Security, Security Operations and Administration, Network and Communications Security, Cryptography. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official ISC2 SSCP exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.