SSCP Systems and Application Security Practice Question
A security administrator is implementing application whitelisting on a fleet of Linux servers that run a fixed set of approved binaries. The administrator wants to ensure only authorized executables can run, while still allowing legitimate administrative scripts. Which TWO of the following approaches BEST support this goal? (Choose two.)
⚠ Common exam trap
The trap here is selecting detective or hardening measures that reduce risk but do not actually block execution of unauthorized binaries, which is what whitelisting requires.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use an integrity measurement and attestation mechanism that records hashes of approved binaries and blocks execution of unlisted files.
Effective application whitelisting on Linux relies on preventive controls that stop unapproved executables before they run. Integrity measurement with attestation and mandatory access control profiles both enforce an allowlist at execution time, while still permitting approved administrative scripts when properly configured. Detection and hardening measures are useful complements but do not by themselves guarantee that only authorized binaries execute.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable a host-based intrusion detection system that alerts on execution of unknown binaries.
Why it's wrong here
A host-based intrusion detection system is a detective control that generates alerts after execution occurs. It does not block unauthorized binaries, so the attacker's code still runs. While valuable for visibility, it does not satisfy the requirement to ensure only authorized executables can run, making it insufficient as a whitelisting approach.
- ✗
Mount the application directories as read-only and restrict write access to root only.
Why it's wrong here
Read-only mounts and restrictive permissions reduce the chance of tampering with approved binaries, but they do not prevent an attacker from executing an unauthorized binary placed elsewhere, such as in a temporary directory. This is a hardening measure that complements whitelisting rather than a whitelisting enforcement mechanism itself, so it does not fully meet the stated goal.
- ✓
Use an integrity measurement and attestation mechanism that records hashes of approved binaries and blocks execution of unlisted files.
Why this is correct
Integrity measurement with attestation verifies that only binaries matching approved hashes execute, which directly enforces whitelisting. It also provides evidence that the system has not been tampered with. This approach supports the requirement to allow approved binaries while blocking unauthorized executables, and it can be integrated with boot-time verification for stronger assurance.
- ✓
Deploy mandatory access control policy that confines each service to a profile permitting only its required executables.
Why this is correct
Mandatory access control profiles restrict processes to a defined set of allowed executables and operations, which effectively enforces whitelisting per service. Even if an attacker drops a malicious binary, the confined process cannot execute it if the profile disallows it. This directly supports the goal while still permitting legitimate administrative scripts when the profile is written to include them.
- ✗
Configure a cron job that periodically compares running processes against a known-good list and kills anomalies.
Why it's wrong here
Periodic comparison is reactive and leaves a window during which unauthorized processes run and potentially complete their objectives. It also risks killing legitimate processes if the baseline is incomplete. This is not a reliable enforcement mechanism for application whitelisting and does not provide the preventive control the administrator needs.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.