Courseiva

SSCP Security Operations and Administration Practice Question

A security administrator needs to ensure that all servers are configured with a hardened baseline. Which tool is best suited to detect deviations from the baseline configuration?

⚠ Common exam trap

Candidates often confuse a vulnerability scanner (which finds weaknesses) with a configuration compliance scanner (which checks for policy drift), but the question specifically asks for detecting deviations from a baseline, not vulnerabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SCAP scanner

SCAP (Security Content Automation Protocol) scanners are specifically designed to automate the verification of system configurations against a defined baseline, such as a hardened image or a security policy. They use standardized checklists (e.g., XCCDF, OVAL) to detect deviations, making them the ideal tool for this task. Unlike vulnerability scanners, SCAP scanners focus on configuration compliance rather than known vulnerabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Vulnerability scanner

    Why it's wrong here

    A vulnerability scanner identifies known software flaws and missing patches, not configuration settings deviating from a defined hardening baseline. It suits periodic exposure discovery. Detecting drift from a baseline requires a configuration compliance or SCAP benchmark assessment tool.

  • ✗

    Asset management database

    Why it's wrong here

    An asset management database records inventory attributes such as ownership, location and lifecycle status; it holds no configuration state, so it cannot compare running settings against a hardened baseline. It is tempting because it catalogues every server, but it would be correct for tracking assets and their metadata, not for detecting configuration drift.

  • ✓

    SCAP scanner

    Why this is correct

    An SCAP scanner evaluates system configurations against standardised checklists such as DISA STIG or CIS benchmarks, reporting deviations from the hardened baseline. This satisfies the requirement to detect configuration drift, which signature-based vulnerability scanners alone would not reliably identify.

  • ✗

    SIEM

    Why it's wrong here

    A SIEM correlates log events for threat detection and alerting, not configuration drift; it lacks the desired-state comparison that a hardened baseline requires. It is tempting because SIEMs ingest server telemetry, but they would be correct for detecting suspicious activity or security incidents rather than flagging deviations from a configuration baseline.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.