Courseiva

SSCP Systems and Application Security Practice Question

A security operations center (SOC) is investigating a suspected supply chain attack where a trusted software update was modified to include a backdoor. The update was delivered via the vendor's official update server over HTTPS. Which of the following controls, if implemented by the organization, would have BEST prevented the installation of the backdoored update?

⚠ Common exam trap

The trap here is assuming that HTTPS and TLS pinning guarantee the integrity of the update content, when they only secure the transport, not the package itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Code signing verification of the update package before installation.

Code signing verification is the key control to ensure the integrity and authenticity of software updates. If the update was modified after signing, the signature check fails, and the installation is blocked. Other controls like network segmentation or TLS pinning do not protect against a compromised update server or a malicious insider at the vendor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    TLS certificate pinning for the update server connection.

    Why it's wrong here

    TLS certificate pinning ensures the connection is to the legitimate update server, preventing man-in-the-middle attacks. However, in this scenario, the update was delivered from the official server, so the TLS connection was valid. The attacker compromised the update at the source. Pinning does not verify the integrity of the update package itself.

  • ✗

    Network segmentation between the update server and critical systems.

    Why it's wrong here

    Network segmentation can limit lateral movement after a compromise, but it does not prevent the initial installation of a malicious update. The update is delivered over HTTPS from the official server, so segmentation would not block the download or execution. It fails to address the integrity of the update itself.

  • ✓

    Code signing verification of the update package before installation.

    Why this is correct

    Code signing verification checks that the update package was signed by the vendor's private key and has not been altered. If the attacker modified the update, the signature would not match, and the installation would be blocked. This directly prevents the backdoored update from being installed, assuming the vendor's private key was not compromised. It is the most effective control for this scenario.

  • ✗

    Endpoint detection and response (EDR) with behavioral monitoring.

    Why it's wrong here

    EDR may detect the backdoor's behavior after installation, but it does not prevent the installation. The backdoor could be stealthy and evade detection. While EDR is valuable, it is a detective control, not a preventive one for this specific threat. The question asks for the best control to prevent installation.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.