Courseiva

SSCP Security Operations and Administration Practice Question

A security administrator is implementing a defense-in-depth strategy for a new data center. Which of the following BEST describes the role of security awareness training within this strategy?

⚠ Common exam trap

It's easy for candidates to confuse administrative controls like training with technical controls like encryption or malware blocking; training changes user behavior, not system behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It reduces the likelihood of successful social engineering attacks by educating users.

Security awareness training is an administrative control that educates users on recognizing and avoiding social engineering attacks, thereby reducing the likelihood of successful phishing or pretexting attempts. It complements technical controls like firewalls and antivirus, forming a layer of defense that addresses the human element.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It enforces mandatory vacation policies to detect fraud.

    Why it's wrong here

    Mandatory vacation policies are a separate administrative control used to detect fraud by requiring employees to take time off so their duties can be reviewed. Security awareness training does not enforce vacations. The two are distinct and serve different purposes.

  • ✗

    It encrypts sensitive data at rest and in transit.

    Why it's wrong here

    Encryption is a technical control that protects data confidentiality. Security awareness training does not perform encryption. While training might cover the importance of encryption, it does not implement it. This option confuses an administrative control with a technical one.

  • ✓

    It reduces the likelihood of successful social engineering attacks by educating users.

    Why this is correct

    Security awareness training educates users about phishing, pretexting, and other social engineering tactics, making them less likely to fall victim. This directly reduces the risk of human-based attacks, which are a common initial access vector. It is a key administrative control in defense-in-depth.

  • ✗

    It provides a technical control that blocks malware from executing on endpoints.

    Why it's wrong here

    Security awareness training is an administrative control, not a technical control. It does not block malware; that is the role of antivirus or endpoint detection and response tools. Training educates users to recognize threats, but it cannot directly prevent execution of malicious code.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.