SSCP • Practice Test 40
Free SSCP practice test — 15 questions with explanations. Set 40. No signup required.
An organization uses a SIEM to correlate events. The SIEM receives Windows Security Event ID 4625 (failed login) and 4776 (credential validation). An analyst wants to detect a brute-force attack against a service account. Which correlation rule is most effective?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.