Courseiva
easyMultiple Choice

SSCP Practice Question: A small company with 50 employees uses a local…

A small company with 50 employees uses a local file server for sharing documents. Each employee has a username and password for authentication. The company wants to implement an additional layer of security to protect sensitive data without incurring high costs. They are considering using smart cards or biometric scanners. However, the budget is limited, and employees often work remotely. Which of the following is the most cost-effective and practical approach to strengthen authentication?

⚠ Common exam trap

The trap is that candidates might think increasing password complexity is sufficient for 'additional layer of security', but the question asks for strengthening authentication, which implies MFA; also, they might overlook the remote work aspect, making hardware tokens less practical.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a one-time password (OTP) system via a mobile app.

A one-time password (OTP) system via a mobile app is the most cost-effective and practical approach because it adds a second factor (something the user has) without requiring additional hardware. It works remotely since employees can use their smartphones, and it is low-cost compared to smart cards or biometric scanners. It is also more secure than just increasing password complexity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement a one-time password (OTP) system via a mobile app.

    Why this is correct

    OTP via a mobile app delivers a second factor without issuing physical tokens or biometric hardware, so no per-user device cost arises. It works wherever employees have their phones, satisfying the remote-working constraint, and the app itself is typically free, meeting the limited budget.

  • ✗

    Increase password complexity requirements and enforce periodic changes.

    Why it's wrong here

    Password complexity and rotation add no second authentication factor, so a stolen password still grants access, and frequent changes encourage weaker reuse. It is tempting because it is free and needs no hardware. It would suit environments where MFA is genuinely unavailable, not one seeking an additional layer.

  • ✗

    Issue USB tokens to all employees.

    Why it's wrong here

    USB tokens still require a reader or driver per endpoint and can be lost or shared, so remote staff on personal machines face friction and replacement costs. They suit environments needing portable cryptographic key storage for PKI or FIDO authentication, not a low-cost second factor across 50 distributed users.

  • ✗

    Use Windows Hello facial recognition on company laptops.

    Why it's wrong here

    Windows Hello facial recognition needs infrared-capable hardware and Windows 10/11 enrolment, which company laptops may lack, and it does not cover the local file server login for remote staff. It fits organisations issuing modern managed laptops where passwordless sign-in to Microsoft Entra ID is the goal.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.