Courseiva

SSCP Systems and Application Security Practice Question

A software vendor ships a Java-based payment service to a customer's data center. The customer's security team requires that the application run with only the minimum privileges necessary and cannot be trusted to restrict itself. Which mechanism should the security team use to enforce these restrictions on the JVM?

⚠ Common exam trap

The trap here is assuming that signing an application's code automatically restricts what it can do, when signing addresses authenticity rather than runtime privilege.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Java security policy files configured with a SecurityManager

Java's SecurityManager works with a policy file that enumerates granted permissions, so code is denied anything not explicitly allowed. This lets the security team enforce least privilege from outside the application, which matches the requirement that the application itself not be trusted to limit its own access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Java security policy files configured with a SecurityManager

    Why this is correct

    A Java security policy file lists the exact permissions granted to code, and the SecurityManager enforces them at runtime by checking each sensitive operation against the policy. This gives the security team an external, declarative way to restrict the application to only the privileges it needs, independent of how the application is written.

  • ✗

    Running the JVM as a Windows service under Local System

    Why it's wrong here

    Running as Local System grants the JVM the highest local privilege level, which is the opposite of least privilege. If the application is compromised, the attacker inherits those broad rights. A restricted service account plus a Java security policy would be required to actually constrain the application.

  • ✗

    Enabling verbose garbage collection logging

    Why it's wrong here

    GC logging is a diagnostic feature that records memory management activity for troubleshooting performance. It has no security function and does not restrict code behavior, file access, or network operations. It would not satisfy a requirement to enforce least privilege on the application.

  • ✗

    Code signing the JAR with a trusted certificate

    Why it's wrong here

    Signing a JAR only proves the code's origin and integrity; it does not limit which files, sockets, or system properties the code can access. A signed application can still request any permission the JVM grants by default. Signing is useful for trust and tamper detection, but it does not enforce least privilege here.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.