Courseiva
easyMultiple ChoiceObjective-mapped

SSCP Practice Question: A financial services company has recently…

A financial services company has recently deployed a new customer-facing web application on port 443. The application is essential for client transactions. Within the first week, the security team's monitoring system detected thousands of failed login attempts originating from a wide range of IP addresses across multiple countries. The attempts are using common usernames and passwords, indicating a coordinated brute-force attack. The company's perimeter firewall is configured with a default allow rule for inbound TCP traffic on port 443 to the web server's public IP address. The company operates with a small IT team and has a limited security budget. The web application is custom-developed and cannot be modified quickly. The security analyst must recommend a solution to mitigate the attack while maintaining availability for legitimate users. Which of the following is the most effective first step?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Deploy a Web Application Firewall (WAF) configured with rate limiting and CAPTCHA challenges

Deploying a Web Application Firewall (WAF) with rate limiting and CAPTCHA is the most effective solution because it can identify and block malicious traffic patterns without requiring application changes. It operates at the application layer and can enforce policies such as rate limiting per IP, geolocation blocking, and CAPTCHA challenges, which directly mitigate brute-force attacks while minimizing impact on legitimate users. Other options are less effective: IP blacklisting is reactive and cannot handle distributed attacks; changing ports only provides obscurity; enabling SSH does not address the web application attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement IP blacklisting by manually adding offending IP addresses to the firewall's deny list

    Why it's wrong here

    IP blacklisting is reactive and cannot keep up with a large distributed attack. It also risks blocking legitimate users that share IP ranges with attackers, and requires constant manual updates.

  • Change the web server port from 443 to a non-standard high port

    Why it's wrong here

    Changing the port is a form of security through obscurity. Attackers can easily scan for open ports, so this provides no real protection and may cause connectivity issues for some users.

  • Deploy a Web Application Firewall (WAF) configured with rate limiting and CAPTCHA challenges

    Why this is correct

    A WAF can automatically detect and mitigate brute-force patterns by rate-limiting requests from suspicious IPs, presenting CAPTCHAs to verify human users, and applying other application-layer controls without modifying the application.

  • Enable SSH access to the web server for administrative purposes

    Why it's wrong here

    Enabling SSH does not mitigate the brute-force attack on the web application. It adds an additional attack surface and is unrelated to the issue.

About these practice questions

Courseiva writes every SSCP question from scratch — 920 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.