SSCP Systems and Application Security Practice Question
A cloud security team is using Cloud Security Posture Management (CSPM) to identify misconfigurations. Which of the following scenarios is MOST likely to be detected by CSPM?
⚠ Common exam trap
SSCP often tests whether candidates can distinguish CSPM (configuration/posture) from runtime monitoring, APM, and UEBA tools — the key is whether the issue is a static misconfiguration versus a behavioral or performance anomaly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A cloud storage bucket is configured with public read access
CSPM tools continuously scan cloud configurations against security benchmarks (CIS, NIST, PCI-DSS) and detect misconfigurations like publicly accessible storage buckets, overly permissive IAM policies, unencrypted volumes, and disabled logging. A publicly readable S3 bucket is a textbook CSPM finding.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An application running on a cloud VM has a memory leak causing performance degradation
Why it's wrong here
A memory leak is a runtime application defect, surfaced by APM or host monitoring, not by comparing resource configuration against a secure baseline. It is tempting because CSPM inventories cloud VMs and reports on them, but it assesses settings such as exposed ports or missing patches, not process memory behaviour.
- ✓
A cloud storage bucket is configured with public read access
Why this is correct
CSPM evaluates cloud resource configurations against security baselines and benchmarks. A storage bucket set to public read access is a classic configuration drift that CSPM detects and flags, since it inspects control-plane settings rather than runtime traffic or application behaviour.
- ✗
A cloud-based database is experiencing slow query response times
Why it's wrong here
Slow query response times are a performance metric, detected by database monitoring or APM tooling rather than configuration assessment. It is tempting because CSPM dashboards display cloud resource health data, yet query latency reflects workload and tuning, not a deviation from a secure configuration baseline.
- ✗
An employee's credentials were used from an unusual geographic location
Why it's wrong here
Credential use from an unusual location is behavioural anomaly detection, which belongs to UEBA or SIEM analytics, not posture scanning. It is tempting because CSPM platforms often surface identity findings alongside configuration ones, and unusual geolocation would legitimately be flagged by a UEBA tool monitoring sign-in patterns.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.