Sample questions
Systems Security Certified Practitioner SSCP practice questions
Refer to the exhibit. A security analyst observes this event on a workstation. What is the MOST likely explanation?
A company has segmented its network into VLANs for different departments: HR, Finance, and IT. The router interconnecting the VLANs has ACLs configured to block traffic from HR to…
Which TWO of the following are key components of a Business Impact Analysis (BIA)?
An organization uses role-based access control (RBAC). An employee transfers from the Sales department to the Marketing department. What is the most secure way to update the employ…
A cloud application uses OAuth 2.0 to authorize a third-party app to access user data. What is the primary purpose of the access token issued by the authorization server?
Which of the following is a key advantage of using a behavior-based detection approach in a User and Entity Behavior Analytics (UEBA) system?
Risk Identification, Monitoring, and AnalysismediumSee the answer and why each option is right or wrong →During a security assessment, an analyst finds that multiple snapshots of a critical virtual machine are stored on the hypervisor host. Some snapshots are several months old. Which…
Which TWO are valid reasons to revoke a user's access? (Choose two.)
Which of the following is the primary purpose of a risk register?
A vulnerability scanner identifies a high-severity vulnerability in a web server that is exposed to the internet. According to common remediation SLAs, what is the typical timefram…
Risk Identification, Monitoring, and AnalysiseasySee the answer and why each option is right or wrong →A company uses a backup strategy that backs up all data every Sunday and backs up only data that has changed since the last full backup on other days. This is an example of which b…
A security analyst needs to verify that a downloaded file has not been tampered with. The publisher provides a SHA-256 hash. Which property of the hash function is being relied upo…
A financial services firm with 500 servers and 2000 workstations uses an internal public key infrastructure (PKI) for authentication and secure communication. The root CA certifica…
Which TWO of the following are key components of a configuration management database (CMDB)? (Select TWO)
During an incident response, a forensic analyst captures a memory dump from a compromised server. Which of the following is the MOST important step to ensure the integrity of the e…
Which TWO actions are part of the containment phase of incident response?
A company uses a SIEM to monitor security events. Recently, they are experiencing false positives from a new IDS rule. Which approach would best reduce false positives while mainta…
Which federated identity protocol uses XML-based assertions and provides single sign-on across different security domains?
A security architect is designing an access control system for a healthcare application that requires fine-grained access decisions based on user role, location, time of day, and p…
A patch management process is being audited. Which finding indicates a critical gap in the process?
Which of the following best describes the purpose of a Hardware Security Module (HSM) in key management?
A security administrator is designing physical security for a high-security area. Which TWO controls are most effective for preventing unauthorized entry? (Select TWO)
Which of the following is the PRIMARY purpose of establishing a chain of custody when handling digital evidence?
Drag and drop the steps for conducting a security incident response under the NIST framework into the correct order.