easyMultiple Choice
SSCP Practice Question: A company has 200 employees using a Windows…
A company has 200 employees using a Windows Active Directory environment. The security administrator receives multiple alerts that user accounts are being locked out every 15 minutes. The help desk confirms that users who report the issue are able to log in successfully after unlocking their accounts, but they get locked out again shortly after. The administrator checks the domain controller security logs and sees many failed logon attempts with a specific service account name 'svc_backup' from multiple workstations. The svc_backup account is used for a backup application that runs scheduled tasks. What should the administrator do to resolve the issue?
⚠ Common exam trap
SSCP often tests whether candidates chase the symptom (lockouts) rather than the root cause (stale cached credential), so the trap is selecting a mitigation that weakens policy or disables the account instead of fixing the credential.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the password for svc_backup and update the backup application with the new password
Changing the password for svc_backup and updating the backup application with the new password is correct because the symptom pattern — repeated lockouts every 15 minutes from multiple workstations with failed logons for a single service account — is the classic signature of a stale cached credential. The backup application (or a scheduled task) is still presenting the old password, and each retry trips the domain account lockout threshold. Updating the credential in the application (and any dependent scheduled tasks/services) stops the failed attempts at the source.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the svc_backup account until the backup vendor releases a patch
Why it's wrong here
Disabling svc_backup halts the scheduled backup application entirely, breaking a business-critical job rather than fixing the stale cached credentials causing the lockouts. It is tempting as an immediate containment step, and disabling an account would be correct if it were confirmed compromised or no longer required.
- ✓
Change the password for svc_backup and update the backup application with the new password
Why this is correct
The svc_backup account's stored password no longer matches the domain, so the backup application's scheduled tasks repeatedly authenticate with stale credentials, triggering lockouts. Updating the password and reconfiguring the application restores successful authentication and stops the failed logon attempts.
- ✗
Create a new service account with a different name and grant it the same permissions
Why it's wrong here
Renaming the service account does not remove the stale cached credentials on each workstation, so the failed logons simply target the new name. It is tempting because it appears to invalidate the offending identity, but creating a fresh account is the right move only when the original is irrecoverably compromised.
- ✗
Increase the account lockout threshold to prevent lockouts
Why it's wrong here
Raising the lockout threshold leaves the stale svc_backup credentials still hammering every workstation, so the failed authentications continue and the underlying cause persists. It is tempting as a quick way to stop help-desk tickets, but lockout policy tuning is the correct choice only when legitimate users genuinely mistype passwords repeatedly.
Visual reference
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.