Courseiva

SSCP Security Operations and Administration Practice Question

A security administrator is reviewing an incident response plan and finds that the team has no agreed way to classify how severe a detected event is before deciding whether to escalate. Which artifact should be created to standardize this decision?

⚠ Common exam trap

Many candidates confuse documents that govern vendor or legal relationships with the operational standard needed to classify incident severity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An incident severity matrix that maps impact and scope to response tiers.

Consistent incident triage depends on predefined criteria that translate technical indicators and business impact into response tiers. A severity matrix supplies those criteria, so different analysts reach the same escalation decision. It also enables meaningful metrics, since severity levels become comparable across incidents and reporting periods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A vulnerability management scanning schedule.

    Why it's wrong here

    A scanning schedule governs when systems are assessed for weaknesses; it does not classify the severity of detected security events. Scanning feeds the vulnerability process, not incident triage. Creating a schedule would not give responders the shared decision criteria they lack, so it fails to address the scenario's actual gap.

  • ✗

    A memorandum of understanding with the legal department.

    Why it's wrong here

    An MOU records an agreement between parties, often about cooperation or data sharing, but it contains no operational criteria for rating incidents. It would not help an analyst decide whether an event is critical or low. The stated problem is inconsistent severity judgment, which requires a classification standard rather than an interdepartmental agreement.

  • ✗

    A service level agreement with the managed security service provider.

    Why it's wrong here

    An SLA defines contractual response times and responsibilities, but it does not tell internal responders how to judge the severity of an event. Without a classification scheme, the SLA targets cannot be applied consistently. The scenario asks for a way to categorize events, so a contract document addresses a different governance need and leaves the triage gap open.

  • ✓

    An incident severity matrix that maps impact and scope to response tiers.

    Why this is correct

    A severity matrix defines levels such as low, medium, high, and critical based on factors like business impact, data sensitivity, and number of affected systems. It gives responders a consistent, repeatable way to decide escalation and notification. Because the gap is inconsistent triage, a documented classification scheme directly resolves the problem and supports metrics reporting.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.