SSCP Security Operations and Administration Practice Question
A security metric shows that patch compliance is at 85%. The goal is 95%. Which action should be taken first?
⚠ Common exam trap
The trap is choosing 'increase scanning frequency' because it sounds proactive, when the metric measures patching — candidates must distinguish detection activities from remediation activities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prioritize patching based on vulnerability criticality
When patch compliance is below target, the first step is to prioritize patching based on vulnerability criticality so that the most exploitable and highest-impact systems are remediated first. This maximizes risk reduction per unit of effort and directly addresses the gap between 85% and 95% by focusing resources where they matter most. Simply scanning more or excluding systems does not improve compliance meaningfully.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the frequency of vulnerability scans
Why it's wrong here
Scanning more often re-measures the same 85% compliance and produces additional findings without remediating a single missing patch. It is tempting because vulnerability scanning identifies which systems are unpatched, and it would be correct for establishing or refreshing the baseline inventory before remediation priorities are assigned.
- ✗
Disable automatic updates to prevent issues
Why it's wrong here
Disabling automatic updates removes the primary mechanism that installs patches, driving compliance below 85% rather than toward 95%. It is tempting because uncontrolled updates can destabilise production systems, and a staged or maintenance-window deployment would be correct for managing that risk while still meeting the compliance target.
- ✓
Prioritize patching based on vulnerability criticality
Why this is correct
Prioritising by vulnerability criticality directs remediation toward the highest-risk exposures first, satisfying the stem's requirement to close the 10% compliance gap efficiently. Rather than chasing every missing patch equally, risk-based sequencing reduces exploitable attack surface fastest when resources cannot immediately achieve full coverage.
- ✗
Exclude non-critical systems from patching
Why it's wrong here
Excluding systems from the compliance calculation inflates the percentage without remediating a single host, so the 95% target becomes meaningless. It tempts because scoping metrics to critical assets is legitimate when non-critical systems genuinely pose no risk, but here the gap reflects unpatched systems, not inappropriate scope.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.