Courseiva

SSCP Systems and Application Security Practice Question

A system administrator is hardening a Linux server. After installing the OS, which of the following steps should be taken to ensure that only authorized users can execute commands with elevated privileges?

⚠ Common exam trap

The trap is confusing logging or authentication controls with authorization — candidates may pick auditd or PAM because they sound security-related, but only sudoers governs who may execute commands with elevated privileges.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Edit the /etc/sudoers file to restrict sudo access

The /etc/sudoers file defines which users and groups may run which commands with elevated privileges via sudo. Restricting sudo access by editing this file (preferably with visudo) ensures that only authorized users can execute commands as root or another privileged account. This directly satisfies the requirement to control who can execute commands with elevated privileges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Edit the /etc/sudoers file to restrict sudo access

    Why this is correct

    Editing /etc/sudoers defines exactly which users or groups may run which commands via sudo, satisfying the requirement that only authorised accounts gain elevated execution. This replaces blanket root access with granular, auditable privilege delegation, so unauthorised users cannot escalate.

  • ✗

    Enable auditd to log all commands

    Why it's wrong here

    Auditd records executed commands for later review; it is detective logging and changes no permission, so unauthorised users still gain elevated privileges. It is tempting because audit trails are a genuine hardening control, and it would be correct when the requirement is monitoring or forensic evidence rather than preventing privilege escalation.

  • ✗

    Configure PAM to enforce password complexity

    Why it's wrong here

    PAM password complexity governs authentication strength at login, not which accounts may execute privileged commands once authenticated. It is tempting because PAM modules such as pam_wheel.so do restrict su access, so PAM would be the right choice when the requirement is limiting who can authenticate to a privileged account.

  • ✗

    Set the setuid bit on critical binaries

    Why it's wrong here

    The setuid bit makes a binary run as its owner regardless of who executes it, granting privilege to every user rather than restricting it to authorised ones. It is tempting because setuid is genuinely used for controlled elevation, and it would be correct for a specific vetted binary needing a defined privilege, not general hardening.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.