SSCP Risk Identification, Monitoring, and Analysis Practice Question
A security team is building a continuous monitoring program for a regulated environment. The compliance manager wants assurance that monitoring data is trustworthy and that deviations are detected promptly. Which THREE activities should be included in the monitoring program? (Choose three.)
⚠ Common exam trap
The trap here is equating continuous monitoring with frequent one-time assessments such as penetration tests, or with simply storing data, rather than with ongoing review, measurement, and program improvement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Collecting and reviewing audit logs from critical systems on a defined schedule.
Continuous monitoring depends on three reinforcing activities: scheduled collection and review of audit logs, defined metrics with escalation thresholds, and recurring evaluation of the program itself. Together they provide detection, measurable response criteria, and a feedback loop that keeps coverage current. Penetration testing is periodic validation rather than continuous monitoring, and indefinite archiving without analysis adds no detection capability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Collecting and reviewing audit logs from critical systems on a defined schedule.
Why this is correct
Scheduled collection and review of audit logs from critical systems is a core continuous monitoring activity because it provides evidence that controls are operating and reveals deviations such as failed logins, privilege changes, and configuration edits. Without a defined review cadence, logs accumulate unread and incidents go unnoticed. This activity directly supports both security detection and compliance evidence requirements.
- ✓
Reviewing the monitoring program's own controls and making improvements on a recurring cycle.
Why this is correct
A monitoring program must itself be monitored. Recurring review of its scope, coverage, and effectiveness ensures that new systems are onboarded, stale rules are retired, and gaps are corrected. This feedback loop is what keeps the program trustworthy over time and is expected in mature continuous monitoring frameworks, since an unexamined program silently degrades as the environment changes.
- ✗
Archiving all monitoring data indefinitely without any review or analysis.
Why it's wrong here
Retention without review produces cost and liability without security value. Data must be analyzed and acted upon to detect deviations; indefinite archiving alone does nothing to identify incidents or demonstrate control effectiveness. Retention periods should be driven by legal, regulatory, and investigative needs, and the retained data should feed an active review process rather than sit unexamined.
- ✓
Establishing metrics and reporting thresholds that trigger escalation when exceeded.
Why this is correct
Metrics and thresholds convert raw monitoring data into actionable signals. Defining what constitutes a deviation, and what happens when it occurs, ensures the program detects problems promptly instead of relying on ad hoc observation. Escalation criteria are what make monitoring continuous and repeatable, and they provide auditors with a documented basis for how exceptions are handled.
- ✗
Performing a full penetration test of every system on a weekly basis.
Why it's wrong here
Weekly penetration testing of every system is neither practical nor a continuous monitoring activity. Penetration tests are point-in-time assessments that validate controls and uncover exploitable paths, and they are typically scoped and scheduled periodically. Substituting frequent pen tests for ongoing log review and metrics would consume enormous resources while still missing day-to-day deviations between tests.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.