Courseiva
easyMultiple Choice

SSCP Practice Question: A security analyst notices repeated failed login…

A security analyst notices repeated failed login attempts from a single IP address on the VPN gateway. The analyst adjusts the threshold for account lockout and enables geo-ip blocking. This activity is part of which risk management process?

⚠ Common exam trap

Watch out — candidates often confuse 'monitoring' (ongoing observation and adjustment) with 'risk assessment' (quantitative/qualitative analysis), because adjusting thresholds feels like evaluating risk, but the question explicitly describes a reactive, operational action rather than a formal assessment process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk monitoring

The analyst is actively monitoring the VPN gateway for security events (failed logins) and then adjusting controls (lockout threshold, geo-IP blocking) in response to observed threats. This continuous observation and adjustment is the essence of risk monitoring, which is the ongoing process of tracking identified risks and evaluating the effectiveness of controls. The actions taken are not about identifying new risks, assessing their likelihood/impact, or formally reporting them, but rather about reacting to real-time data to maintain an acceptable risk posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk identification

    Why it's wrong here

    Adjusting lockout thresholds and enabling geo-IP blocking are reactive controls applied after detecting an attack, which is risk mitigation, not identification. Identification is tempting because the analyst did discover the failed logins, but that discovery is monitoring; the configuration changes themselves reduce likelihood, placing the activity in the mitigation process.

  • ✗

    Risk assessment

    Why it's wrong here

    Risk assessment identifies, analyses and evaluates risks; the analyst is instead executing controls in response to an observed event. Assessment would be correct when scoring likelihood and impact to prioritise risks, whereas adjusting lockout thresholds and geo-blocking implements the treatment itself.

  • ✗

    Risk reporting

    Why it's wrong here

    Risk reporting communicates risk status, metrics and treatment progress to stakeholders; the analyst is performing hands-on control implementation, not documenting or escalating findings. Reporting would be correct when producing dashboards or briefings that inform management decisions about the VPN brute-force exposure.

  • ✓

    Risk monitoring

    Why this is correct

    Risk monitoring involves continuously tracking identified risks and evaluating control effectiveness. Adjusting the lockout threshold and enabling geo-ip blocking in response to observed failed logins treats the VPN gateway as an ongoing monitored risk, refining controls rather than performing initial assessment or identification.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.