SSCP Security Operations and Administration Practice Question
A security administrator is reviewing audit logs and discovers that a user account with administrative privileges was used to access a file server outside of normal business hours. The administrator needs to determine whether this access was authorized. Which of the following should the administrator do FIRST?
⚠ Common exam trap
The trap here is jumping to containment or notification before verifying whether the activity was legitimate; always gather context first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the change management records and on-call schedule for that time period
The first step in investigating suspicious access is to gather context from non-intrusive sources such as change management and on-call schedules. This helps determine if the access was authorized without disrupting operations or alerting a potential insider. Disabling accounts, contacting users, or escalating externally should come after initial verification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Escalate the incident to law enforcement as a potential breach
Why it's wrong here
Escalating to law enforcement is premature without evidence of a crime. It can waste resources and damage the organization's reputation if the access was legitimate. The administrator should first perform internal verification through logs and records to determine whether the activity was authorized.
- ✓
Review the change management records and on-call schedule for that time period
Why this is correct
Checking change management records and on-call schedules provides context to determine if the access was planned or expected. This is a non-intrusive first step that can quickly validate or refute the need for further investigation. It preserves evidence and avoids disrupting operations prematurely.
- ✗
Contact the user to ask whether they performed the access
Why it's wrong here
Contacting the user can be part of the investigation, but it should not be the first step because it may alert a malicious insider or the user may not respond promptly. The administrator should first review available evidence such as change tickets, schedules, and additional logs to establish context.
- ✗
Disable the administrative account immediately to prevent further access
Why it's wrong here
Disabling the account may stop a potential threat, but it could also disrupt legitimate business if the access was authorized. The first step should be to gather information to determine whether the activity is malicious. Disabling without investigation can destroy evidence and cause unnecessary downtime.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.