Courseiva

Systems Security Certified Practitioner SSCP (SSCP) — Questions 1–75

971 questions total · 13pages · All types, answers revealed

Page 1 of 13

Page 2
1
MCQeasy

An organization wants to prevent unauthorized devices from connecting to its wired network. Which security control should be implemented?

A.Port security with sticky MAC
B.MAC address filtering
C.VLAN segmentation
D.IEEE 802.1X port-based authentication
AnswerD

IEEE 802.1X enforces port-based authentication at the switch, requiring devices to authenticate via a supplicant, authenticator and RADIUS server before any traffic passes. This directly satisfies the stem's constraint of blocking unauthorised devices from the wired network, since unauthenticated ports remain closed.

Why this answer

IEEE 802.1X port-based authentication is the correct control because it authenticates each device at the network edge before granting access to the wired LAN. It uses an authentication server (e.g., RADIUS) to verify credentials or certificates, effectively preventing unauthorized devices from connecting. Unlike MAC-based controls, 802.1X provides dynamic, per-session authentication that cannot be easily spoofed.

Exam trap

ISC2 often tests the misconception that MAC-based controls (port security or MAC filtering) provide strong authentication, when in fact they are easily bypassed by MAC spoofing, whereas 802.1X uses cryptographic credentials or certificates for true device authentication.

How to eliminate wrong answers

Option A is wrong because port security with sticky MAC only learns and limits MAC addresses on a switch port, but it does not authenticate the device; an attacker can spoof a learned MAC address to bypass the control. Option B is wrong because MAC address filtering is a static, easily spoofed control that only checks the source MAC at Layer 2, offering no authentication or encryption. Option C is wrong because VLAN segmentation separates traffic logically but does not prevent unauthorized devices from physically connecting to the network; it only limits their broadcast domain.

2
MCQhard

An organization has implemented a SIEM solution and wants to reduce false positives. Which of the following is the most effective approach?

A.Tune correlation rules to exclude known benign activities
B.Increase the number of log sources feeding the SIEM
C.Raise the threshold for each correlation rule to reduce alerts
D.Assign more analysts to manually review all alerts
AnswerA

Tuning correlation rules to exclude known benign activity reduces alerts triggered by legitimate behaviour, directly cutting false positives while preserving detection of genuine threats. Raising severity thresholds or disabling rules would suppress true positives, so rule tuning is the targeted approach the stem requires.

Why this answer

The most effective way to reduce false positives in a SIEM is to tune correlation rules so they exclude known benign activities. False positives occur when rules trigger on legitimate behavior; by refining rule logic (whitelisting trusted IPs, excluding scheduled tasks, adjusting thresholds based on baselines), analysts reduce noise without losing detection of real threats. This is the standard SIEM tuning approach.

Exam trap

SSCP often tests the difference between reducing false positives (tuning rules) and reducing alert volume (raising thresholds) — candidates pick threshold-raising because it sounds efficient, but it introduces false negatives and is not the most effective approach.

How to eliminate wrong answers

Option B is wrong because adding more log sources increases data volume and typically increases false positives, not reduces them — more sources mean more events that may match rules. Option C is wrong because raising thresholds reduces alerts but also risks missing real threats (false negatives), and it is a blunt approach rather than targeted tuning. Option D is wrong because assigning more analysts to manually review alerts does not reduce false positives — it only increases the cost of handling them; the alerts are still false positives.

3
MCQhard

During a forensic investigation, you find that the attacker used a legitimate Windows tool to exfiltrate data. Which tool is commonly abused for this purpose?

A.Telnet
B.Netcat
C.PowerShell
D.FTP
AnswerC

PowerShell provides native scripting, remote execution and file-transfer capabilities built into Windows, letting attackers blend malicious commands with legitimate administrative activity. Its trusted status and logging gaps make it a common living-off-the-land tool for data exfiltration.

Why this answer

PowerShell is a legitimate Windows administrative tool that attackers commonly abuse for data exfiltration because it provides native access to network protocols (e.g., HTTP, HTTPS, FTP, SMB) and can download/upload files directly from the command line without additional binaries. Its deep integration with the Windows operating system allows scripts to run in memory, bypassing traditional file-based detection mechanisms, making it a favored tool for post-exploitation data theft.

Exam trap

The trap here is that candidates often associate Netcat (a classic hacking tool) with data exfiltration, but the question specifically requires a 'legitimate Windows tool,' and PowerShell is the correct answer because it is built-in and widely abused, whereas Netcat is not native to Windows.

How to eliminate wrong answers

Option A is wrong because Telnet is an unencrypted remote terminal protocol (RFC 854) that lacks native file transfer capabilities; while it can be used to send data manually, it is not commonly abused for automated or stealthy exfiltration due to its lack of encryption and limited scripting support. Option B is wrong because Netcat is a third-party network utility (not a legitimate Windows built-in tool) that can be used for data exfiltration, but the question specifies a 'legitimate Windows tool,' and Netcat is not included by default in Windows. Option D is wrong because FTP is a file transfer protocol that can be used for exfiltration, but the built-in Windows FTP client (ftp.exe) is deprecated and less commonly abused compared to PowerShell, which offers more flexibility and is present on all modern Windows systems.

4
MCQmedium

An incident responder needs to create a forensic image of a suspect hard drive. What is the correct procedure to ensure evidence integrity?

A.Use a write blocker, create a bit-for-bit image, and compute SHA-256 hash before and after imaging.
B.Boot the suspect system and use imaging software to copy data.
C.Remove the drive and place it in anti-static bag, then ship to lab.
D.Connect the drive directly to forensic workstation, copy all files, and compute MD5 hash of copy.
AnswerA

A write blocker prevents any modification to the source drive, bit-for-bit imaging captures an exact replica including slack space, and SHA-256 hashes computed before and after verify the image matches the original, satisfying the evidence-integrity requirement.

Why this answer

Forensic imaging requires a write blocker to prevent any modification to the original evidence, a bit-for-bit (sector-level) copy to capture all data including slack space and deleted files, and cryptographic hashing (SHA-256) both before and after imaging to verify that the image is an exact, unaltered duplicate of the source. This process ensures the integrity and admissibility of digital evidence in legal proceedings.

Exam trap

The trap here is that candidates may think booting the system or simply copying files is sufficient, but the SSCP exam emphasizes that any write activity to the original evidence breaks the chain of custody and invalidates the forensic integrity.

How to eliminate wrong answers

Option B is wrong because booting the suspect system alters the system state (e.g., writes temporary files, updates logs, changes timestamps), which modifies evidence and violates forensic best practices. Option C is wrong because simply placing the drive in an anti-static bag and shipping it does not create a forensic image; imaging must be performed to preserve the data, and the procedure omits write-blocking and hashing. Option D is wrong because connecting the drive directly without a write blocker risks accidental writes to the source, and copying files (rather than creating a bit-for-bit image) loses metadata, slack space, and deleted data; MD5 is also less collision-resistant than SHA-256 for modern forensic standards.

5
Multi-Selectmedium

A security team is implementing a PKI for a large enterprise. Which TWO of the following are commonly used methods for certificate revocation checking? (Select TWO.)

Select 2 answers
A.Certificate Signing Request (CSR)
B.Online Certificate Status Protocol (OCSP)
C.Certificate Revocation List (CRL)
D.Key Escrow
E.Digital Signature Algorithm (DSA)
AnswersB, C

OCSP queries a responder for the real-time revocation status of a specific certificate, returning good, revoked or unknown. This satisfies the enterprise PKI requirement for a commonly used revocation checking method, offering lower latency than downloading a full list.

Why this answer

Option B, Online Certificate Status Protocol (OCSP), is correct because it is a standard protocol defined in RFC 6960 that allows a client to query a dedicated OCSP responder in real time to determine whether a specific certificate has been revoked, returning a status of good, revoked, or unknown. Option C, Certificate Revocation List (CRL), is correct because it is a signed list published by the Certificate Authority (typically distributed via HTTP, LDAP, or FTP at the CDP extension URL) that enumerates the serial numbers of certificates that have been revoked before their expiration date. The remaining options are not revocation-checking methods: a Certificate Signing Request (A) is a message sent to a CA to request issuance of a certificate, Key Escrow (D) is the practice of storing private keys with a third party for recovery purposes, and the Digital Signature Algorithm (E) is a signing algorithm used to create and verify digital signatures, not to check revocation status.

Exam trap

The trap is confusing certificate lifecycle elements like CSR or key escrow with revocation checking mechanisms, or picking cryptographic algorithms like DSA that are unrelated to revocation.

6
MCQmedium

A security administrator discovers that a web application is vulnerable to SQL injection. Which of the following is the most effective mitigation to implement at the application layer?

A.Implement input validation using a blacklist of SQL keywords.
B.Encrypt the database connection using TLS.
C.Use parameterized queries or prepared statements.
D.Encode all output sent to the browser.
E.Deploy a web application firewall (WAF) in front of the server.
AnswerC

Parameterised queries separate SQL code from user-supplied data, so input is treated as a value rather than executable syntax. This eliminates the injection vector at the application layer, satisfying the requirement for the most effective mitigation rather than input filtering or WAF rules.

Why this answer

(parameterized queries or prepared statements) is the most effective mitigation at the application layer because it ensures user input is treated as data, not executable SQL code, thus preventing SQL injection. Option A (input validation via blacklist) can be bypassed by attackers using encoding or alternative characters. Option B (encrypting the database connection with TLS) protects data in transit but does not prevent SQL injection.

Option D (output encoding) addresses cross-site scripting (XSS), not SQL injection. Option E (deploying a WAF) operates at the network layer and can be circumvented; it is not an application-layer control.

7
MCQeasy

Which protocol is used to automatically assign IP addresses to devices on a network?

A.ARP
B.DNS
C.ICMP
D.DHCP
AnswerD

DHCP uses the DORA exchange (Discover, Offer, Request, Acknowledge) to lease IP addresses, subnet masks, gateways and DNS settings to clients automatically, removing manual static configuration. DNS resolves names and ARP maps IPs to MAC addresses; neither assigns addresses.

Why this answer

DHCP (Dynamic Host Configuration Protocol) is the correct answer because it is specifically designed to automatically assign IP addresses and other network configuration parameters (such as subnet mask, default gateway, and DNS servers) to devices on a network. This eliminates the need for manual IP configuration and reduces the risk of address conflicts.

Exam trap

The trap here is that candidates often confuse ARP's role in network communication (mapping IP to MAC) with IP address assignment, but ARP has no mechanism for leasing or configuring IP addresses.

How to eliminate wrong answers

Option A (ARP) is wrong because ARP (Address Resolution Protocol) is used to map a known IP address to a MAC address on a local network, not to assign IP addresses. Option B (DNS) is wrong because DNS (Domain Name System) translates domain names to IP addresses, not assign them. Option C (ICMP) is wrong because ICMP (Internet Control Message Protocol) is used for error reporting and diagnostic functions (e.g., ping), not for IP address assignment.

8
MCQeasy

A security analyst is reviewing a proposed solution that uses a stream cipher to encrypt real-time voice traffic. Which property of stream ciphers makes them well suited for this scenario?

A.They require a unique public/private key pair for every call.
B.They encrypt data one bit or byte at a time, avoiding the need to pad to a block boundary.
C.They provide built-in non-repudiation for each voice packet.
D.They automatically compress voice data before encryption.
AnswerB

Stream ciphers generate a keystream and combine it with plaintext one unit at a time, so they do not require padding and can handle continuous data streams. This is advantageous for real-time voice, where traffic is generated continuously and buffering to fill a block could introduce latency. The absence of padding also avoids ciphertext expansion.

Why this answer

Stream ciphers operate on small units of data, such as bits or bytes, and do not require padding to a block boundary. This makes them efficient for continuous, low-latency traffic like real-time voice, where waiting for a full block would add delay. They are symmetric and provide confidentiality only, so properties such as non-repudiation, per-call key pairs, and compression are not inherent to them.

Exam trap

The trap here is attributing asymmetric or compression features to stream ciphers, or overlooking that their main advantage for voice is low latency and no padding.

9
MCQmedium

A cloud security team wants to continuously monitor for misconfigured cloud resources that could expose data. Which tool category is specifically designed for this purpose?

A.Cloud Workload Protection Platform (CWPP)
B.Identity and Access Management (IAM)
C.Cloud Security Posture Management (CSPM)
D.Web Application Firewall (WAF)
AnswerC

Cloud Security Posture Management continuously scans cloud infrastructure for misconfigurations, comparing deployed resource settings against security baselines and compliance frameworks. It directly satisfies the stem's requirement for ongoing detection of exposed data risks, unlike CWPP (workload protection) or CASB (access control), which address different layers.

Why this answer

CSPM (Cloud Security Posture Management) tools detect misconfigurations like open storage buckets or overly permissive IAM roles. CWPP focuses on runtime workload protection. WAF protects web apps.

IAM manages identities, not configuration monitoring.

10
MCQeasy

In which access control model does the owner of a resource have full discretion over who can access it and with what permissions?

A.Attribute-Based Access Control (ABAC)
B.Discretionary Access Control (DAC)
C.Role-Based Access Control (RBAC)
D.Mandatory Access Control (MAC)
AnswerB

In DAC, the resource owner decides which subjects receive access and at what level, using ACLs they control. This owner-controlled discretion is the defining axis separating DAC from MAC, where a central policy authority sets labels and no owner can override them.

Why this answer

Discretionary Access Control (DAC) is the model where the resource owner has full authority to grant or deny access to other subjects and to set the permissions (e.g., read, write, execute) on the object. This is typically implemented through Access Control Lists (ACLs) on files or objects, as seen in Windows NTFS or Linux file permissions, where the owner can change permissions using commands like `chmod` or through GUI properties.

Exam trap

The trap here is that candidates often confuse DAC with RBAC because both involve user-based permissions, but the key distinction is that DAC gives the resource owner full discretion, whereas RBAC enforces access based on organizational roles, not individual owner decisions.

How to eliminate wrong answers

Option A (ABAC) is wrong because ABAC evaluates access based on attributes of the subject, object, and environment (e.g., time of day, location) using policy rules, not by owner discretion. Option C (RBAC) is wrong because RBAC assigns permissions based on predefined roles within an organization, and the owner does not have full discretion; access is determined by role membership, not individual owner decisions. Option D (MAC) is wrong because MAC enforces access decisions based on system-wide security labels (e.g., classification levels like Top Secret) and the owner cannot override these; labels are set by the system or security administrator, not the resource owner.

11
MCQeasy

A user reports that their computer is displaying a fake antivirus warning that demands payment. This is an example of which type of attack?

A.Social engineering
B.Ransomware
C.Phishing
D.Scareware
AnswerD

Scareware fabricates antivirus alerts demanding payment, directly matching the stem's fake warning. Unlike ransomware, which encrypts files, scareware relies on psychological manipulation alone, with no encryption or data theft. This social-engineering tactic satisfies the scenario's defining constraint: a fraudulent security prompt extorting money through fear.

Why this answer

Scareware is a type of malware that uses social engineering to trick users into believing their system is infected, then demands payment for a fake removal tool. The fake antivirus warning is a classic scareware tactic, as it creates urgency and fear to coerce payment, unlike ransomware which encrypts files and demands a ransom for decryption.

Exam trap

The trap here is that candidates confuse scareware with ransomware because both demand payment, but scareware does not encrypt files or lock the system—it only displays a fake warning, which is a key distinction tested on the SSCP exam.

How to eliminate wrong answers

Option A is wrong because social engineering is a broad manipulation technique that can be used in many attacks, but the specific attack described (fake antivirus demanding payment) is a form of scareware, not a standalone social engineering attack. Option B is wrong because ransomware typically encrypts files or locks the system and demands payment for decryption or access, whereas scareware only displays a fake warning without actually encrypting data. Option C is wrong because phishing is a social engineering attack that uses deceptive emails or websites to steal credentials or sensitive information, not to display fake antivirus warnings demanding payment.

12
MCQeasy

A security professional is implementing a solution to verify the authenticity of a digital certificate. Which component of a PKI is responsible for issuing and revoking certificates?

A.Online Certificate Status Protocol (OCSP) responder
B.Certificate Authority (CA)
C.Certificate Revocation List (CRL)
D.Registration Authority (RA)
AnswerB

The Certificate Authority issues digital certificates by signing them with its own private key, binding a public key to an identity, and publishes revocation status through CRLs or OCSP. That issuing and revoking function is precisely the PKI component the stem asks for.

Why this answer

The Certificate Authority (CA) is the core component of a Public Key Infrastructure (PKI) responsible for issuing digital certificates and, crucially, for revoking them when they are no longer trusted. While other components support certificate status checking or verification, only the CA has the authority to sign and publish certificates or revocation information.

Exam trap

The trap here is that candidates confuse the OCSP responder or CRL as the entity that performs revocation, when in fact they are merely mechanisms to check or distribute revocation status, while only the CA has the authority to issue or revoke a certificate.

How to eliminate wrong answers

Option A is wrong because an OCSP responder is a service that provides real-time certificate status (valid, revoked, or unknown) by querying the CA's database, but it does not issue or revoke certificates. Option C is wrong because a Certificate Revocation List (CRL) is a published list of revoked certificates maintained by the CA, but it is a data structure, not the entity that performs the revocation action. Option D is wrong because a Registration Authority (RA) is an optional component that verifies the identity of certificate requestors and forwards requests to the CA, but it does not have the authority to issue or revoke certificates itself.

13
MCQmedium

A security administrator is configuring a new web server and wants to ensure that the server's operating system and applications are hardened according to organizational standards. Which of the following should the administrator apply to enforce the desired security settings?

A.Change management process
B.Incident response plan
C.Vulnerability scan
D.Security baseline
AnswerD

A security baseline is a documented set of minimum security settings that must be applied to a system to meet organizational policy. Applying it to the new web server ensures consistent hardening, reduces attack surface, and provides a known configuration to compare against during audits. It directly addresses the need to enforce desired security settings.

Why this answer

A security baseline provides the specific, documented configuration settings that must be applied to a system to meet security standards. It is the authoritative source for hardening a new server. The other options are important security processes but do not directly enforce the desired technical settings on the server.

Exam trap

The trap here is confusing procedural controls like change management with technical configuration baselines.

14
Multi-Selecthard

A company is implementing a new SIEM. Which THREE factors are most important to ensure log integrity and usefulness for forensic investigations? (Choose THREE.)

Select 3 answers
A.Write-once storage to prevent modification
B.Digital signing of logs to verify authenticity
C.Minimizing log retention to reduce storage costs
D.Ensuring logs are retained for a period consistent with legal and regulatory requirements
E.Aggregating logs from all sources into one centralized repository
AnswersA, B, D

Write-once storage prevents logs from being altered or deleted after capture, preserving evidential integrity. This directly satisfies the forensic requirement that records remain tamper-evident and unmodified, ensuring investigators can trust that what they review reflects the original event data.

Why this answer

Option A (write-once storage to prevent modification) is correct because WORM (Write Once Read Many) media or immutable storage ensures that once log data is written it cannot be altered or deleted, preserving evidentiary integrity for forensics. Option B (digital signing of logs to verify authenticity) is correct because cryptographic signatures or hashes let investigators prove logs were not tampered with and confirm their origin, supporting non-repudiation and chain-of-custody requirements. Option D (ensuring logs are retained for a period consistent with legal and regulatory requirements) is correct because forensic usefulness depends on having the relevant logs still available when an investigation occurs, and retention periods are often mandated by laws such as HIPAA, PCI DSS, or GDPR.

Option C is not correct because minimizing retention to cut storage costs directly undermines forensic and compliance needs by destroying potentially critical evidence prematurely. Option E is not correct because centralizing logs improves correlation and management but does not by itself guarantee integrity or forensic usefulness, and it can even concentrate risk if the repository is not protected.

Exam trap

A common trap on the SSCP exam is to select 'centralized aggregation' (Option E) as a key factor for log integrity, but aggregation alone does not protect against modification. The correct factors focus on preserving log authenticity and immutability, such as write-once storage and digital signatures.

15
MCQhard

During a penetration test, an attacker was able to bypass input validation and execute commands on a web server. The server runs a PHP application. Which of the following is the MOST likely root cause?

A.The application uses unsanitized input in SQL queries.
B.The application reflects user input in HTTP responses without escaping.
C.The application passes user input to a shell command via exec() or system() functions.
D.The application uses hidden form fields to store session tokens.
AnswerC

Passing unsanitised input into exec() or system() lets shell metacharacters spawn arbitrary OS commands, which is command injection rather than SQL injection or XSS. This directly explains bypassed input validation and code execution on the PHP host.

Why this answer

The scenario describes command execution on the web server, which is a direct consequence of OS command injection. In PHP, passing unsanitized user input to functions like exec() or system() allows an attacker to execute arbitrary shell commands, bypassing input validation. This is the most likely root cause as it directly enables command execution, unlike other vulnerabilities that lead to different impacts.

Exam trap

The trap here is that candidates may confuse command injection with SQL injection or XSS, but the key differentiator is the ability to execute OS-level commands on the server, which only occurs through shell execution functions like exec() or system().

How to eliminate wrong answers

Option A is wrong because unsanitized input in SQL queries causes SQL injection, which manipulates the database, not executes OS commands on the server. Option B is wrong because reflecting user input in HTTP responses without escaping leads to cross-site scripting (XSS), which executes in the browser, not on the server. Option D is wrong because hidden form fields storing session tokens is a session management weakness, not a mechanism for command execution.

16
MCQhard

A security engineer is configuring a site-to-site VPN between two branch offices using IPsec in tunnel mode. Which protocol provides both authentication and encryption of the entire original IP packet?

A.IKEv2 in transport mode
B.ESP (Encapsulating Security Payload) in tunnel mode
C.L2TP in tunnel mode
D.AH (Authentication Header) in tunnel mode
AnswerB

ESP in tunnel mode encapsulates the entire original IP packet and applies both encryption and authentication, satisfying the stem's dual requirement. AH provides authentication only, without confidentiality, so it cannot encrypt payloads. ESP's tunnel encapsulation also hides original source and destination addresses, which transport mode does not.

Why this answer

ESP (Encapsulating Security Payload) in tunnel mode encrypts and authenticates the entire original IP packet, then encapsulates it inside a new IP packet with new headers. This provides confidentiality, integrity, and origin authentication for the payload, making it the standard choice for site-to-site VPNs.

Exam trap

SSCP often tests the AH vs. ESP distinction — the trap is selecting AH for 'authentication' when the question also requires encryption, which only ESP provides.

How to eliminate wrong answers

Option A is wrong because IKEv2 is a key-exchange protocol (used to negotiate SAs), not a data-encryption protocol, and transport mode does not encapsulate the original IP header. Option C is wrong because L2TP provides no encryption on its own — it is typically paired with IPsec for confidentiality. Option D is wrong because AH provides authentication and integrity but no encryption, so it cannot satisfy the 'encryption' requirement.

17
MCQhard

An organization uses smart cards with PKI certificates for authentication. Users must insert the card and enter a PIN. This is an example of which authentication method?

A.Three-factor authentication
B.Single-factor authentication
C.Two-factor authentication
D.Biometric authentication
AnswerC

The smart card holds a PKI certificate (something you have) while the PIN is something you know. Combining these two distinct factors satisfies two-factor authentication, unlike a single-factor method such as certificate-only or password-only verification.

Why this answer

Two-factor authentication requires two different categories of authentication factors. The smart card (something you have) plus the PIN (something you know) combine two distinct factor types, so this is two-factor authentication. The certificate on the card provides cryptographic proof of possession, while the PIN unlocks the card and proves knowledge.

Exam trap

SSCP often tests factor counting — candidates miscount because they treat the certificate and the PIN as two separate 'things' or forget that possession plus knowledge equals exactly two factors, not three.

How to eliminate wrong answers

Option A is wrong because three-factor authentication would require a third, different factor such as a biometric (something you are) in addition to the card and PIN. Option B is wrong because single-factor authentication uses only one factor category; here both possession and knowledge are required. Option D is wrong because biometric authentication relies on a physical characteristic (fingerprint, iris, face), which is not used in this scenario.

18
Multi-Selecthard

A security analyst is reviewing a TLS 1.3 deployment. Which THREE of the following are features of TLS 1.3?

Select 3 answers
A.Use of static RSA key exchange
B.Mandatory forward secrecy
C.Support for 0-RTT handshake
D.Removal of cipher suites like RC4 and DES
E.Support for SSL 3.0 compatibility
AnswersB, C, D

TLS 1.3 removes static RSA and plain Diffie-Hellman key exchange, leaving only ephemeral (EC)DHE and PSK modes. Every session therefore derives unique keys, so forward secrecy is mandatory rather than optional as in TLS 1.2.

Why this answer

Option B is correct because TLS 1.3 mandates forward secrecy by eliminating static RSA and static Diffie-Hellman key exchange, requiring ephemeral key exchanges (ECDHE or DHE) so that compromise of long-term keys cannot decrypt past sessions. Option C is correct because TLS 1.3 introduces a 0-RTT (early data) mode using PSK resumption, allowing the client to send application data in the first flight, though it carries replay risk. Option D is correct because TLS 1.3 removes all legacy cipher suites based on RC4, DES/3DES, CBC-mode, and MD5/SHA-1, restricting the protocol to AEAD ciphers such as AES-GCM, ChaCha20-Poly1305, and AES-CCM.

Option A is not correct because static RSA key exchange was explicitly removed in TLS 1.3, since it lacks forward secrecy. Option E is not correct because TLS 1.3 does not support SSL 3.0 compatibility; SSL 3.0 was already deprecated and TLS 1.3 removed backward compatibility with such legacy protocols.

Exam trap

SSCP often tests the misconception that TLS 1.3 is backward compatible with SSL 3.0 or that static RSA remains an option — candidates who confuse TLS 1.2 features with TLS 1.3 pick A or E.

19
MCQmedium

A network administrator notices that wireless users are experiencing intermittent connectivity. The controller shows excessive deauthentication frames. What is the most likely cause?

A.Rogue access point performing a deauthentication attack
B.Channel interference
C.Power save mode
D.DHCP server exhaustion
E.Weak encryption
AnswerA

Excessive deauthentication frames are the signature of a deauthentication flood, which a rogue access point runs to force clients off the legitimate AP. The intermittent connectivity users report is the direct symptom, since each forged frame drops an associated station.

Why this answer

Excessive deauthentication frames are a hallmark of a deauthentication attack, where a rogue access point sends forged 802.11 management frames to disconnect clients. This causes intermittent connectivity as clients repeatedly lose association and attempt to reconnect. The controller logs these frames as a clear indicator of an active attack.

Exam trap

ISC2 often tests the distinction between deauthentication attacks and other wireless issues like channel interference or DHCP exhaustion, trapping candidates who confuse symptoms of a DoS attack with normal network problems.

How to eliminate wrong answers

Option B is wrong because channel interference typically causes packet loss, retransmissions, and low signal quality, not a flood of deauthentication frames. Option C is wrong because power save mode reduces client power consumption by periodically sleeping, which may cause brief latency but does not generate deauthentication frames. Option D is wrong because DHCP server exhaustion prevents clients from obtaining IP addresses, leading to connectivity failure but not excessive deauthentication frames.

Option E is wrong because weak encryption (e.g., WEP or TKIP) makes the network vulnerable to decryption attacks but does not directly cause a flood of deauthentication frames; deauthentication attacks exploit unprotected management frames regardless of encryption strength.

20
MCQmedium

An analyst runs the netstat command on a web server. Based on the output, which connection is the MOST suspicious?

A.The connection from 203.0.113.5:8080
B.The connection from 192.168.1.10:54321
C.The connection from 10.0.2.50:44350
D.The listening on 0.0.0.0:80
AnswerA

Correct. The external IP from the documentation range connecting on port 8080 is unusual and potentially malicious, suggesting proxy or tunneling activity.

Why this answer

203.0.113.5 is from the documentation IP range (RFC 5737), which should not appear in real network traffic. This indicates potential spoofing or malicious activity. Options B and C are internal private IPs, which are expected.

Option D is the normal HTTP listening service.

21
MCQeasy

A small company with 50 employees uses a local file server for sharing documents. Each employee has a username and password for authentication. The company wants to implement an additional layer of security to protect sensitive data without incurring high costs. They are considering using smart cards or biometric scanners. However, the budget is limited, and employees often work remotely. Which of the following is the most cost-effective and practical approach to strengthen authentication?

A.Implement a one-time password (OTP) system via a mobile app.
B.Increase password complexity requirements and enforce periodic changes.
C.Issue USB tokens to all employees.
D.Use Windows Hello facial recognition on company laptops.
AnswerA

OTP via a mobile app delivers a second factor without issuing physical tokens or biometric hardware, so no per-user device cost arises. It works wherever employees have their phones, satisfying the remote-working constraint, and the app itself is typically free, meeting the limited budget.

Why this answer

A one-time password (OTP) system via a mobile app is the most cost-effective and practical approach because it adds a second factor (something the user has) without requiring additional hardware. It works remotely since employees can use their smartphones, and it is low-cost compared to smart cards or biometric scanners. It is also more secure than just increasing password complexity.

Exam trap

The trap is that candidates might think increasing password complexity is sufficient for 'additional layer of security', but the question asks for strengthening authentication, which implies MFA; also, they might overlook the remote work aspect, making hardware tokens less practical.

How to eliminate wrong answers

Option B is wrong because increasing password complexity and enforcing periodic changes does not add a second factor; it only strengthens the single factor (something the user knows) and can lead to poor password practices. Option C is wrong because issuing USB tokens requires purchasing hardware and managing distribution, which is more expensive and less practical for remote workers. Option D is wrong because Windows Hello facial recognition requires compatible hardware (infrared cameras) on company laptops, which may not be available and would require upgrading hardware, incurring costs.

22
Multi-Selecteasy

Which THREE of the following are common types of malware?

Select 3 answers
A.Trojan horse
B.Virus
C.Worm
D.Firewall
E.Patch
AnswersA, B, C

A Trojan horse is malware disguised as legitimate software, which the user willingly executes, granting the attacker a foothold. It is a distinct malware category defined by deception rather than self-replication, satisfying the question's requirement for a common malware type.

Why this answer

A Trojan horse (A) is a correct answer because it is a classic malware category: it disguises itself as legitimate software to trick a user into executing it, then performs malicious actions such as backdoor installation or data theft. A virus (B) is correct because it is self-replicating malicious code that attaches itself to a host file or boot sector and spreads when the infected host is executed. A worm (C) is correct because it is standalone self-replicating malware that spreads across networks (e.g., via SMB or email) without needing a host file or user action.

By contrast, a firewall (D) is a network security control that filters traffic based on rules, and a patch (E) is a software update that remediates vulnerabilities — neither is malware, so they are not correct.

23
MCQhard

A BYOD policy allows personal devices to access corporate email. What is the best control to enforce device encryption and remote wipe?

A.Network Access Control (NAC)
B.Mobile Device Management (MDM) profile
C.Containerization app
D.Mandatory VPN connection
AnswerB

An MDM profile enforces configuration on enrolled personal devices, mandating storage encryption and enabling remote wipe of corporate data. This satisfies the BYOD constraint by applying policy at the device-management layer, which email protocols alone cannot enforce.

Why this answer

An MDM profile pushes configuration and policy to enrolled personal devices, including enforced storage encryption, screen-lock requirements, and the ability to issue a remote wipe of corporate data. It is the standard control for BYOD because it operates at the OS management layer regardless of the network path.

Exam trap

SSCP often tests the misconception that network controls like NAC or VPN can enforce endpoint encryption — they cannot, because encryption at rest and remote wipe are device-management functions.

How to eliminate wrong answers

Option A is wrong because NAC only decides whether a device may join the network based on posture; it cannot enforce encryption at rest or perform a remote wipe. Option C is wrong because containerization isolates corporate apps and data but does not itself enforce full-device encryption or provide remote wipe of the device. Option D is wrong because a mandatory VPN only encrypts traffic in transit and provides no control over data at rest or lost-device remediation.

24
MCQmedium

An attacker sends a forged ARP reply associating the attacker's MAC address with the IP address of the default gateway. What type of attack is this?

A.ARP spoofing
B.MAC flooding
C.DHCP starvation
D.DNS poisoning
AnswerA

ARP spoofing fits because the attacker forges an ARP reply, binding their MAC address to the gateway's IP. This poisons the victim's ARP cache, redirecting traffic through the attacker for interception. The stem's defining constraint — a falsified ARP reply impersonating the default gateway — is precisely ARP spoofing, not DNS or IP spoofing.

Why this answer

ARP spoofing (also called ARP cache poisoning) is the attack in which a malicious host sends forged ARP replies to bind its own MAC address to the IP address of a legitimate host — here, the default gateway. Because ARP has no authentication mechanism, victims update their ARP caches with the attacker's MAC, causing traffic destined for the gateway to flow through the attacker, enabling man-in-the-middle interception.

Exam trap

The trap here is confusing layer-2 attacks: candidates may pick MAC flooding because it also involves MAC addresses, but only ARP spoofing forges the IP-to-MAC binding of the gateway.

How to eliminate wrong answers

Option B is wrong because MAC flooding overwhelms a switch's CAM table with bogus source MAC addresses, forcing the switch to flood frames out all ports — it does not forge ARP replies or impersonate a gateway. Option C is wrong because DHCP starvation exhausts a DHCP server's address pool by requesting all available leases with spoofed MACs, causing denial of service rather than gateway impersonation. Option D is wrong because DNS poisoning corrupts DNS resolver caches to redirect name resolution to attacker-controlled IPs, which operates at the DNS layer, not the ARP/L2 layer.

25
MCQhard

A financial services firm's incident response plan defines a Recovery Time Objective (RTO) of 2 hours for its online trading platform. During a tabletop exercise, the team discovers that the current disaster recovery runbook requires manual steps that take approximately 6 hours to complete. The Chief Information Security Officer (CISO) asks for a recommendation to align the recovery capability with the RTO without increasing the budget significantly. Which of the following is the MOST appropriate recommendation?

A.Outsource the entire recovery process to a managed security service provider (MSSP) with a 2-hour SLA.
B.Increase the RTO to 6 hours to match the current manual recovery process.
C.Automate the manual steps using existing orchestration tools and scripts to reduce recovery time.
D.Implement a hot site with real-time replication, which will guarantee a 2-hour recovery.
AnswerC

Automating manual steps with existing orchestration tools can significantly reduce recovery time without major new spending. Many organizations already have configuration management or scripting platforms that can be leveraged to streamline failover and recovery. This approach directly addresses the gap between the 6-hour manual process and the 2-hour RTO. It also reduces human error and improves consistency, making it the most appropriate recommendation given the budget constraint.

Why this answer

Automating manual recovery steps using existing orchestration tools is the most cost-effective way to reduce recovery time and meet the 2-hour RTO. It leverages current investments, minimizes new spending, and directly targets the delay. Increasing the RTO ignores business needs, while hot site or MSSP options likely exceed the budget and may not fully resolve the manual process bottleneck.

Exam trap

The trap here is assuming that achieving a lower RTO always requires expensive new infrastructure, when automation of existing manual steps can often close the gap within budget.

26
MCQmedium

Refer to the exhibit. A network engineer is configuring an IPsec VPN. Which protocol does this configuration apply to?

A.HTTPS
B.SSH
C.SSL/TLS
D.IKE (Internet Key Exchange)
AnswerD

IKE negotiates security associations and derives keys during IPsec phase one and phase two, so a configuration defining authentication, encryption and key-exchange parameters applies to IKE. It establishes the tunnel's cryptographic material before ESP or AH protects the actual traffic.

Why this answer

The configuration shown in the exhibit is for an IPsec VPN, which relies on IKE (Internet Key Exchange) to establish security associations and negotiate cryptographic keys. IKE (RFC 7296) is the mandatory key management protocol for IPsec, handling authentication and key exchange over UDP ports 500 and 4500. Without IKE, IPsec cannot dynamically negotiate the encryption and hashing parameters required for secure tunnel establishment.

Exam trap

The trap here is that candidates often confuse SSL/TLS with IPsec because both are used for VPNs, but SSL/TLS VPNs operate at the transport layer (e.g., OpenVPN) while IPsec VPNs require IKE for key exchange at the network layer.

How to eliminate wrong answers

Option A is wrong because HTTPS is an application-layer protocol (HTTP over TLS) used for secure web browsing, not for negotiating IPsec security associations. Option B is wrong because SSH is a protocol for secure remote login and command execution, operating at the application layer, and does not handle IPsec key management. Option C is wrong because SSL/TLS operates at the transport layer to secure TCP connections (e.g., HTTPS, FTPS) and is not used for IPsec VPN key exchange; IPsec uses IKE for this purpose.

27
MCQeasy

Which TCP port is commonly used for secure web traffic (HTTPS) and is often allowed through firewalls for web browsing?

A.22
B.443
C.80
D.3389
AnswerB

TCP 443 carries HTTPS, using TLS to encrypt web traffic. Firewalls commonly permit it outbound so users can browse securely, satisfying the stem's requirement. Port 80 is unencrypted HTTP, while 22 and 25 serve SSH and SMTP respectively.

Why this answer

HTTPS uses TCP port 443 by default, as defined in RFC 2818. Firewalls commonly allow outbound TCP 443 to permit secure web browsing, and it is the standard port for TLS-encrypted HTTP traffic.

Exam trap

The trap is confusing port 80 (HTTP) with port 443 (HTTPS); candidates may pick 80 because it is the well-known web port, but the question specifically asks for secure web traffic.

How to eliminate wrong answers

Option A is wrong because port 22 is used for SSH (Secure Shell), not HTTPS. Option C is wrong because port 80 is used for plain HTTP, which is unencrypted and not considered secure web traffic. Option D is wrong because port 3389 is used for RDP (Remote Desktop Protocol), not web traffic.

28
MCQeasy

A company is implementing application whitelisting on all endpoints. Which of the following is a primary consideration for maintaining operational efficiency?

A.Ensuring that all users have local administrator rights
B.Deploying a host-based firewall on each endpoint
C.Establishing a process to add approved applications to the whitelist
D.Disabling Windows Defender Antivirus to reduce resource usage
AnswerC

Whitelisting only permits explicitly approved executables, so any legitimate business application not yet listed is blocked. A defined approval process lets administrators vet and add new or updated software promptly, preserving user productivity while keeping the default-deny posture intact.

Why this answer

Application whitelisting only allows approved applications to run. To maintain operational efficiency, organizations must have a streamlined process to review and add new or updated applications to the whitelist as business needs evolve. Without this, users may be blocked from necessary tools, causing productivity loss.

Exam trap

SSCP often tests the misconception that whitelisting is a set-and-forget control, ignoring the need for ongoing management and user support to avoid operational disruptions.

How to eliminate wrong answers

Option A is wrong because granting local administrator rights undermines whitelisting by allowing users to bypass restrictions. Option B is wrong because a host-based firewall controls network traffic, not application execution, and does not address whitelist maintenance. Option D is wrong because disabling antivirus reduces security and does not relate to whitelisting efficiency.

29
MCQeasy

A medium-sized company recently experienced a phishing attack where an employee downloaded a malicious attachment, leading to a data breach. The incident response team has identified the affected user and the malware. However, the team is unsure whether the attacker has established persistence. The security analyst must recommend the next step. The company has a standard incident response plan that includes detection, containment, eradication, recovery, and lessons learned. The malware sample has been isolated for analysis. The user's account has been disabled temporarily. The network team has quarantined the user's workstation. The analyst needs to ensure the attacker cannot regain access after the initial cleanup. What should the analyst recommend next?

A.Check system logs for unauthorized registry modifications, scheduled tasks, or startup entries.
B.Perform a full malware analysis of the file to understand its capabilities.
C.Notify affected customers immediately as required by data breach notification laws.
D.Reimage the user's workstation from a known good backup.
AnswerA

Persistence mechanisms such as registry Run keys, scheduled tasks and startup entries let malware survive reboots and credential resets. Auditing these locations on the quarantined workstation confirms whether the attacker retained a foothold before eradication and recovery proceed.

Why this answer

The immediate priority after containment is to identify and remove any persistence mechanisms the attacker may have established. Checking system logs for unauthorized registry modifications (e.g., Run keys), scheduled tasks (e.g., schtasks), and startup entries (e.g., Startup folder or services) directly addresses the uncertainty about persistence. This step ensures the attacker cannot regain access after cleanup, aligning with the eradication phase of the incident response plan.

Exam trap

The trap here is that candidates may jump to reimaging (Option D) as a quick fix, but without first verifying and removing persistence, the attacker could have established footholds on other systems or in the backup itself, making reimaging ineffective.

How to eliminate wrong answers

Option B is wrong because performing a full malware analysis is a secondary step that can occur in parallel or after eradication; it does not directly address the immediate need to check for persistence mechanisms. Option C is wrong because notifying affected customers is part of the lessons learned or legal compliance phase, which occurs after containment, eradication, and recovery, not before ensuring the attacker cannot regain access. Option D is wrong because reimaging the workstation from a known good backup is a recovery step that assumes persistence has been checked and removed; if the backup itself is compromised or persistence exists elsewhere, reimaging alone may not prevent re-infection.

30
MCQmedium

A company is implementing a Single Sign-On (SSO) solution that uses XML-based assertions to exchange authentication and authorization data between an identity provider and a service provider. Which protocol is being used?

A.Kerberos
B.SAML
C.OAuth 2.0
D.OpenID Connect
AnswerB

SAML exchanges authentication and authorisation data as XML assertions between an identity provider and a service provider, exactly the flow described. Its assertion-based, XML-encoded token format is the defining characteristic distinguishing it from other SSO protocols.

Why this answer

SAML (Security Assertion Markup Language) is an XML-based standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP). It uses XML assertions to convey user identity and attributes, making it the correct protocol for this scenario.

Exam trap

The trap is confusing SAML with OAuth or OIDC, especially since all are used for SSO, but only SAML uses XML assertions.

How to eliminate wrong answers

Option A is wrong because Kerberos is a network authentication protocol that uses tickets, not XML assertions, and is typically used within a domain, not for web SSO. Option C is wrong because OAuth 2.0 is an authorization framework that uses tokens (often JSON) for delegated access, not XML assertions for authentication. Option D is wrong because OpenID Connect is an authentication layer on top of OAuth 2.0 that uses JSON Web Tokens (JWT), not XML assertions.

31
Multi-Selecteasy

Which TWO of the following are common indicators of a ransomware attack?

Select 2 answers
A.Files with .encrypted extension appearing in directories.
B.Unusual outbound network traffic to unknown IPs.
C.Decreased network latency.
D.A ransom note text file in each affected folder.
E.System log entries showing failed login attempts.
AnswersA, D

Ransomware encrypts victim files and typically renames them with a distinctive appended extension, so novel extensions such as .encrypted appearing en masse indicate encryption in progress. This is a direct file-system artefact of the attack, satisfying the stem's indicator requirement.

Why this answer

Option A is correct because ransomware typically renames victim files with a distinctive extension (e.g., .encrypted, .locked, .crypto) after encrypting them, so the sudden appearance of files with an .encrypted extension in directories is a classic indicator of an active ransomware attack. Option D is correct because most ransomware families drop a ransom note (often named README.txt, DECRYPT_INSTRUCTIONS.txt, or similar) into every affected folder to instruct the victim on how to pay for the decryption key, making its presence a strong forensic indicator. Option B is not the best choice here because while unusual outbound traffic can indicate malware or C2 communication, it is a generic indicator of many compromises rather than a specific hallmark of ransomware.

Option C is incorrect because ransomware does not typically reduce network latency; if anything, mass encryption and file operations tend to degrade system and network performance. Option E is incorrect because failed login attempts point to brute-force or credential-stuffing activity, which is an initial access technique rather than a ransomware-specific indicator.

Exam trap

SSCP often tests the distinction between generic malware indicators (like unusual outbound traffic) and ransomware-specific artifacts (file extensions and ransom notes), causing candidates to select broader but incorrect options.

32
MCQmedium

An organization wants to ensure that only authorized devices can connect to the corporate wired network. Which technology should they implement to enforce this?

A.Network Access Control (NAC) with 802.1X
B.VLAN segmentation
C.MAC address filtering
D.Firewall rules
AnswerA

802.1X port-based authentication requires a supplicant to authenticate against a RADIUS server before the switch port grants access, and NAC enforces the resulting policy. Together they ensure only authorised, compliant devices can connect to the wired network.

Why this answer

Network Access Control (NAC) with 802.1X authenticates devices before granting network access, enforcing compliance and authorization.

33
MCQeasy

An organization uses Infrastructure as a Service (IaaS) in the public cloud. Which of the following security responsibilities is the customer responsible for?

A.Network infrastructure security
B.Hypervisor security and patching
C.Operating system security and patch management
D.Physical security of the data center
AnswerC

In IaaS the provider secures the physical hosts, hypervisor and network fabric, but the guest operating system remains the customer's layer. Patching, hardening and OS-level controls therefore fall to the customer, satisfying the stem's IaaS responsibility split.

Why this answer

In IaaS, the customer is responsible for securing the operating system, including patch management, because the provider only manages the hypervisor and physical infrastructure. Operating system security and patching is therefore a customer responsibility. The other options are provider responsibilities in IaaS.

Exam trap

The trap is assuming the provider patches everything in IaaS — candidates forget that the customer owns the guest OS, so OS patching remains a customer duty even though the hypervisor is provider-managed.

How to eliminate wrong answers

Option A is wrong because network infrastructure security (physical network, routers, switches) is managed by the cloud provider in IaaS. Option B is wrong because hypervisor security and patching is always the provider's responsibility, as the customer has no access to the hypervisor. Option D is wrong because physical security of the data center is entirely the provider's responsibility in a public cloud.

34
Multi-Selectmedium

A security analyst is reviewing SIEM alerts and wants to identify potential data exfiltration. Which TWO of the following indicators are most relevant?

Select 2 answers
A.Successful logins during business hours
B.Large outbound data transfers to an external IP
C.A user connecting to a known command-and-control server
D.Multiple failed login attempts
E.Elevated CPU usage on a database server
AnswersB, C

Exfiltration requires data leaving the network, so unusually large outbound transfers to an external IP directly indicate possible data theft. Volume and destination are the measurable network-flow characteristics that distinguish exfiltration from normal egress traffic.

Why this answer

Option B is correct because large outbound data transfers to an external IP are a classic exfiltration indicator: data leaving the network in abnormal volume or to an unfamiliar destination suggests staging and transfer of stolen data, and SIEM correlation on bytes sent, destination reputation, and baseline deviation is the standard detection method. Option C is correct because a user or host connecting to a known command-and-control (C2) server indicates active adversary communication, which typically precedes or accompanies exfiltration and is detected via threat-intelligence feeds, DNS/HTTP beaconing patterns, and IOC matching. Option A does not belong because successful logins during business hours are normal expected activity and lack exfiltration context.

Option D does not belong because multiple failed login attempts indicate brute-force or credential-stuffing attempts (an access/integrity threat), not outbound data theft. Option E does not belong because elevated CPU usage on a database server is a performance or resource symptom that may have many benign causes and is not a direct exfiltration indicator.

Exam trap

The trap here is that candidates confuse indicators of compromise (like failed logins or CPU spikes) with exfiltration-specific signs, failing to focus on outbound data movement as the core criterion.

35
MCQhard

A security administrator is implementing change management for a critical financial system. Which of the following is the MOST important control to prevent unauthorized changes?

A.Implement a staging environment to test all changes
B.Enforce a formal approval process via a change advisory board
C.Notify all users before the change window
D.Require a documented backout plan for every change
AnswerB

A change advisory board enforces segregation of duties: the requester cannot self-approve, so every modification to the financial system requires independent review before implementation. This directly satisfies the stem's constraint of preventing unauthorised changes, since approval authority rests with a separate body rather than the administrator performing the work.

Why this answer

A formal approval process via a change advisory board (CAB) is the most important control because it ensures changes are reviewed, authorized, and documented by appropriate stakeholders before implementation, directly preventing unauthorized changes. While testing, notification, and backout plans are valuable, they do not provide the authorization gate that stops unauthorized changes from being deployed.

Exam trap

The trap is selecting a technical control (staging, backout) over the governance control (CAB approval); the question asks for the MOST important control to prevent unauthorized changes, which is authorization, not testing or rollback.

How to eliminate wrong answers

Option A is wrong because a staging environment tests changes for functionality but does not prevent an unauthorized change from being promoted to production. Option C is wrong because notifying users is a communication step, not an authorization control, and does not stop unauthorized changes. Option D is wrong because a backout plan mitigates failed changes but does not prevent unauthorized changes from being made in the first place.

36
MCQmedium

A company is deploying a VPN using IPsec. They want to ensure that even if the private key of the server is compromised, past session keys cannot be derived. Which key exchange method should they use?

A.Pre-shared key (PSK)
B.RSA key exchange
C.Ephemeral Diffie-Hellman (DHE or ECDHE)
D.Diffie-Hellman with static keys
AnswerC

Ephemeral Diffie-Hellman generates a fresh key pair per session, so the derived shared secret is never transmitted and cannot be recovered from the server's long-term private key. This satisfies the forward secrecy constraint: compromise of that key leaves previously negotiated session keys underivable.

Why this answer

Ephemeral Diffie-Hellman (DHE or ECDHE) provides perfect forward secrecy (PFS) because it generates a unique, temporary session key for each session using ephemeral key pairs. Even if the server's long-term private key is compromised, past session keys cannot be derived because they were created from ephemeral keys that are discarded after each session. This ensures that historical encrypted traffic remains secure.

Exam trap

The trap here is that candidates confuse authentication with key exchange, assuming that RSA or static DH provides PFS because they involve public-key cryptography, but only ephemeral DH ensures that session keys are not derived from long-term secrets.

How to eliminate wrong answers

Option A is wrong because pre-shared keys (PSK) are static and do not provide PFS; if the PSK is compromised, all past session keys can be derived. Option B is wrong because RSA key exchange uses the server's static private key to encrypt the session key, so compromising that private key allows decryption of all past session keys. Option D is wrong because Diffie-Hellman with static keys uses long-term Diffie-Hellman keys that do not change per session, so compromising the static private key enables recovery of all past session keys.

37
Multi-Selectmedium

After a ransomware incident, the incident response team is conducting recovery. Which THREE steps are essential to ensure a secure restoration and prevent reinfection? (Choose three.)

Select 3 answers
A.Restore from the most recent backup available, regardless of its integrity.
B.Reconnect the system to the network immediately after restoration to test functionality.
C.Perform a full system scan with updated antivirus on the restored system.
D.Remove persistence mechanisms from the registry and startup folders.
E.Patch the vulnerability that was exploited in the initial compromise.
AnswersC, D, E

Scanning the restored system with current antivirus signatures detects any residual malware or dormant payloads that survived restoration, satisfying the requirement to prevent reinfection. Because ransomware often leaves droppers or secondary implants, this verification step confirms the restored host is genuinely clean before returning it to production.

Why this answer

Option C is correct because after restoring data or a system image, a full scan with up-to-date antivirus signatures is needed to detect any residual malware that may have been present in the backup or reintroduced during restoration, preventing reinfection. Option D is correct because ransomware and other malware often establish persistence via Run/RunOnce registry keys, services, scheduled tasks, and Startup folders; these must be identified and removed so the threat cannot re-execute after reboot. Option E is correct because the initial compromise vector—such as an unpatched SMB, RDP, or VPN vulnerability—must be remediated; otherwise the same exploit can be used again to reinfect the restored system.

Option A is not appropriate because restoring from a backup without verifying its integrity risks reintroducing corrupted or already-infected data. Option B is not appropriate because reconnecting to the network immediately after restoration, before scanning, patching, and removing persistence, exposes the system to reinfection and lateral movement.

Exam trap

SSCP often tests the misconception that the most recent backup is always the safest choice, but the trap here is that integrity and cleanliness of the backup are more important than recency, and candidates may overlook the need to remove persistence mechanisms before reconnecting to the network.

38
MCQmedium

An organization's backup policy states: 'Maintain three copies of data on two different media types, with one copy stored offsite.' This is known as:

A.Incremental backup strategy
B.Grandfather-father-son rotation
C.3-2-1 rule
D.Disaster recovery plan
AnswerC

The 3-2-1 rule directly encodes the policy's three constraints: three copies of data, two distinct media types, and one copy held offsite. Its whole purpose is resilient recovery, so it satisfies the stated requirement exactly, whereas alternatives such as RAID or full backups address redundancy or scope but not the offsite and media-diversity conditions.

Why this answer

The 3-2-1 rule is a foundational data backup strategy that mandates maintaining three total copies of data, stored on two different types of media (e.g., disk and tape), with one copy located offsite to protect against site-level disasters. This directly matches the policy described, making option C correct.

Exam trap

The trap here is that candidates confuse the 3-2-1 rule with backup rotation schemes like GFS or incremental strategies, because all involve 'backup' and 'copies,' but only the 3-2-1 rule explicitly defines the count, media diversity, and offsite requirement.

How to eliminate wrong answers

Option A is wrong because an incremental backup strategy refers to a backup method that only copies data changed since the last full or incremental backup, not a rule about the number of copies, media diversity, or offsite storage. Option B is wrong because the grandfather-father-son (GFS) rotation is a tape rotation scheme that manages backup retention cycles (daily, weekly, monthly), not a specification for three copies on two media types with one offsite. Option D is wrong because a disaster recovery plan (DRP) is a comprehensive document outlining procedures for recovering IT infrastructure after a disaster, not a specific backup copy and media rule.

39
Multi-Selecteasy

Which TWO of the following are examples of physical security controls? (Select TWO)

Select 2 answers
A.Firewall
B.CCTV
C.Intrusion detection system (IDS)
D.Biometric reader
E.Encryption
AnswersB, D

CCTV is a physical security control because it monitors and records the tangible environment, deterring and detecting intrusions at a facility. It satisfies the scenario's requirement for controls operating on physical premises rather than logical access.

Why this answer

B (CCTV) is correct because closed-circuit television cameras are a physical security control that monitors and records activity in a facility to deter and detect intrusions. D (Biometric reader) is correct because it is a physical access control device that authenticates individuals via fingerprints, iris, or facial recognition to restrict entry to a protected area. A (Firewall) is incorrect because it is a logical/network security control that filters traffic based on rules, not a physical barrier.

C (Intrusion detection system) is incorrect because an IDS is a logical monitoring control that analyzes network or host activity for malicious behavior. E (Encryption) is incorrect because it is a cryptographic/logical control that protects data confidentiality, not a physical control.

Exam trap

The trap here is that candidates confuse 'security control' with 'security technology' and fail to distinguish between physical (tangible) and logical (digital) controls, leading them to select IDS or firewall as physical controls.

40
MCQmedium

An organization is migrating from 3DES to AES-256 for encrypting data at rest. Which mode of AES is recommended for authenticated encryption?

A.ECB
B.GCM
C.CBC
D.CTR
AnswerB

GCM provides authenticated encryption with associated data, combining AES-CTR confidentiality with a GHASH authentication tag in one pass. This satisfies the stem's requirement for authenticated encryption, unlike CBC or ECB, which supply confidentiality only and need a separate MAC.

Why this answer

GCM (Galois/Counter Mode) is the correct choice because it provides both confidentiality and authenticity in a single, efficient mode. For data at rest, authenticated encryption ensures that encrypted data cannot be tampered with undetected, which is critical for integrity. AES-256-GCM is widely recommended and standardized (NIST SP 800-38D) for this purpose.

Exam trap

ISC2 SSCP often tests the misconception that any mode providing confidentiality (like CBC or CTR) is sufficient for secure encryption, but the trap here is that authenticated encryption specifically requires a mode that also guarantees integrity, which only GCM (or CCM) provides among the listed options.

How to eliminate wrong answers

Option A is wrong because ECB (Electronic Codebook) mode encrypts each block independently, producing identical ciphertext for identical plaintext blocks, which leaks patterns and provides no authentication. Option C is wrong because CBC (Cipher Block Chaining) mode provides only confidentiality, not authentication; it requires a separate MAC (e.g., HMAC) to achieve authenticated encryption, and it is vulnerable to padding oracle attacks if not implemented carefully. Option D is wrong because CTR (Counter) mode provides only confidentiality and no integrity protection; it is a stream cipher mode that can be combined with a MAC but does not itself offer authenticated encryption.

41
MCQeasy

A company is developing an incident response plan. Which of the following stakeholders should be included in the initial planning phase?

A.External legal counsel
B.Internal audit
C.Only IT staff
D.Business unit leaders
AnswerD

Business unit leaders supply operational context on critical functions, acceptable downtime and communication channels, ensuring the plan reflects real business impact. Their early involvement secures the authority and resources needed to approve response actions across departments.

Why this answer

Business unit leaders (Option D) are essential in the initial planning phase because they define the critical assets, operational priorities, and recovery time objectives (RTOs) that shape the incident response strategy. Without their input, the plan may fail to align with business continuity requirements, leading to ineffective resource allocation during an actual incident.

Exam trap

The trap here is that candidates often assume incident response is purely a technical function, leading them to choose 'Only IT staff' (Option C), but the SSCP exam emphasizes that effective planning requires input from business stakeholders to ensure the plan supports organizational resilience, not just technical recovery.

How to eliminate wrong answers

Option A is wrong because external legal counsel is typically consulted during the later stages of plan development or during an actual incident to address regulatory compliance and liability, not during the initial planning phase where internal stakeholders define scope and priorities. Option B is wrong because internal audit provides oversight and compliance validation after the plan is drafted, not during initial planning; their role is to test controls, not to define incident response strategy. Option C is wrong because limiting planning to only IT staff ignores the cross-functional impact of incidents—business units, legal, HR, and PR must be involved to ensure the plan addresses communication, data classification, and operational continuity beyond technical remediation.

42
MCQmedium

A network administrator is tasked with segmenting the network to isolate a DMZ containing public-facing web servers from the internal corporate network. Which device should be placed between the DMZ and internal network, and what type of traffic should it allow?

A.Router; allow all traffic but use NAT.
B.IDS; monitor traffic but do not block.
C.Firewall; allow only specific traffic from internal to DMZ and block DMZ-initiated connections to internal.
D.Switch; allow all traffic between DMZ and internal network.
AnswerC

A firewall between the DMZ and internal network enforces stateful rules permitting only specific internal-to-DMZ traffic while blocking DMZ-initiated connections inward. This satisfies the segmentation requirement, containing a compromised public-facing web server so it cannot pivot into the corporate network.

Why this answer

A firewall is the correct segmentation control between a DMZ and the internal network because it enforces stateful policy that permits only specific, necessary flows (typically internal-initiated sessions to DMZ services) while blocking DMZ-initiated connections inbound to the internal network. This prevents a compromised public-facing web server from pivoting into the corporate LAN. The directional rule set is the key security property being tested.

Exam trap

SSCP often tests the misconception that NAT or an IDS provides segmentation — only a firewall (or equivalent policy-enforcing device) can block DMZ-initiated traffic into the internal network.

How to eliminate wrong answers

Option A is wrong because a router with NAT provides address translation, not security policy — NAT is not a security control and 'allow all traffic' defeats segmentation. Option B is wrong because an IDS is passive and only detects/alerts; it cannot block DMZ-to-internal traffic, so it fails the isolation requirement. Option D is wrong because a switch forwards frames within a broadcast domain and provides no policy enforcement between the DMZ and internal network, allowing unrestricted lateral movement.

43
MCQmedium

A security analyst is reviewing an application that accepts a user-supplied file path and uses it to read a configuration file from disk. The analyst observes that a user can enter ../../etc/passwd and the application returns the contents of that system file. Which of the following best describes this vulnerability?

A.Server-side request forgery
B.Insecure direct object reference
C.Path traversal
D.Cross-site scripting
AnswerC

Path traversal, also called directory traversal, occurs when user-supplied input containing sequences like ../ is used to access files outside the intended directory. The analyst's observation that ../../etc/passwd returns a system file demonstrates exactly this flaw. The application fails to validate or normalize the path, allowing access to arbitrary files readable by the process.

Why this answer

The ability to enter ../ sequences and retrieve a file outside the intended directory is the defining behavior of path traversal. The application fails to canonicalize and validate the supplied path, allowing access to files such as /etc/passwd. The other choices describe client-side script injection, object identifier manipulation, or forced server requests, none of which match the observed file-read behavior.

Exam trap

The trap here is confusing any unauthorized file or data access with insecure direct object reference, when the distinguishing feature of path traversal is the use of relative path sequences to escape the intended directory.

44
MCQeasy

A network administrator is configuring a switch to prevent unauthorized devices from connecting to a specific switch port. The administrator wants to restrict access based on the device's MAC address. Which feature should be implemented?

A.Dynamic ARP Inspection (DAI)
B.Port security
C.VLAN pruning
D.Spanning Tree Protocol (STP)
AnswerB

Port security allows the administrator to specify which MAC addresses are allowed on a switch port. It can restrict access to a single MAC address or a limited number, and can take actions like shutting down the port if a violation occurs. This directly meets the requirement to prevent unauthorized devices based on MAC address.

Why this answer

Port security is the switch feature that restricts access to a port based on MAC addresses. It can be configured to allow only specific MAC addresses or a maximum number of addresses. When a violation occurs, the switch can drop packets, send an alert, or shut down the port.

This effectively prevents unauthorized devices from connecting.

Exam trap

The trap here is confusing port security with other switch security features like DAI, which protect against specific attacks but do not control port access based on MAC addresses.

45
MCQmedium

A security analyst detects unusual outbound traffic from a server that normally communicates only with internal systems. The firewall logs show connections to an external IP address on port 443/tcp. Which incident response step should the analyst perform FIRST?

A.Run a full antivirus scan on the server.
B.Isolate the server from the network.
C.Immediately shut down the server.
D.Disconnect the entire network segment.
AnswerB

Isolating the server contains the suspected compromise, preventing further command-and-control communication or data exfiltration to the external IP on port 443. Containment precedes analysis and eradication, so it is the first step before investigating the anomalous outbound traffic.

Why this answer

The unusual outbound traffic to an external IP on port 443/tcp from a server that normally only communicates internally indicates a potential compromise, such as a command-and-control (C2) channel. The first priority in incident response is containment to prevent further data exfiltration or lateral movement, and isolating the server from the network achieves this without destroying volatile evidence. Shutting down the server or running an antivirus scan could destroy memory-resident malware or forensic artifacts, violating the order of volatility.

Exam trap

ISC2 often tests the misconception that immediate shutdown or antivirus scanning is the correct first step, but the trap here is that containment (isolation) must precede any destructive or investigative actions to preserve evidence and limit damage.

How to eliminate wrong answers

Option A is wrong because running a full antivirus scan on the server may alter volatile data (e.g., running processes, network connections) and could trigger the malware to wipe evidence or escalate its behavior, violating the principle of preserving forensic integrity. Option C is wrong because immediately shutting down the server destroys volatile evidence in memory (e.g., active C2 sessions, encryption keys) and may cause the malware to activate a kill switch, whereas isolation preserves the system state for analysis. Option D is wrong because disconnecting the entire network segment is overly disruptive and may impact critical business operations unnecessarily; the correct containment step is to isolate only the compromised server to minimize collateral damage.

46
Multi-Selectmedium

A network administrator is troubleshooting a DNS poisoning attack. Which TWO countermeasures can help prevent such attacks? (Select two)

Select 2 answers
A.Implement DNSSEC to validate DNS responses
B.Configure firewall rules to block UDP port 53
C.Disable DNS recursion on authoritative servers
D.Use secure DNS resolvers that enforce DNSSEC validation
E.Enable DHCP snooping on switches
AnswersA, D

DNSSEC cryptographically signs DNS records, letting resolvers verify responses originated from the authoritative zone and were not altered in transit. This directly defeats cache poisoning, where forged replies redirect users to attacker-controlled addresses, satisfying the stem's requirement to prevent spoofed DNS data from being trusted.

Why this answer

Option A (Implement DNSSEC to validate DNS responses) is correct because DNSSEC adds cryptographic signatures (RRSIG) to DNS records so a resolver can verify authenticity and integrity, preventing forged or spoofed records from being accepted during a poisoning attack. Option D (Use secure DNS resolvers that enforce DNSSEC validation) is correct because even with DNSSEC deployed, the resolver must actually perform validation of the chain of trust (via DS/DNSKEY records) to reject bogus answers; resolvers that enforce validation stop poisoned data from reaching clients. Option B is wrong because blocking UDP port 53 would break legitimate DNS resolution entirely rather than prevent poisoning.

Option C is wrong because disabling recursion on authoritative servers is a general hardening practice but does not by itself prevent cache poisoning of recursive resolvers. Option E is wrong because DHCP snooping protects against rogue DHCP servers and Layer 2 attacks, not DNS cache poisoning.

Exam trap

SSCP often tests the confusion between DNSSEC (integrity/authenticity) and encryption (DoH/DoT), and candidates may pick 'block port 53' as a quick fix, not realizing it breaks DNS entirely.

47
MCQhard

A security administrator is tasked with implementing a formal process for managing user access rights. The organization requires that access be granted based on job roles and that users receive only the permissions necessary to perform their duties. Which of the following should the administrator implement?

A.Role-based access control (RBAC)
B.Discretionary access control (DAC)
C.Mandatory access control (MAC)
D.Attribute-based access control (ABAC)
AnswerA

RBAC assigns permissions to roles rather than individuals, and users are assigned to roles based on their job functions. This directly enforces least privilege because users inherit only the permissions of their role. It matches the requirement to grant access based on job roles and minimal necessary permissions.

Why this answer

Role-based access control (RBAC) is designed to assign permissions to roles and then assign users to those roles, ensuring that users have only the access required for their job functions. This satisfies the requirement for role-based provisioning and least privilege. Other models like MAC, DAC, or ABAC do not align as directly with the stated need.

Exam trap

The trap here is confusing RBAC with ABAC; while both can enforce least privilege, the scenario explicitly mentions job roles, which is the defining characteristic of RBAC.

48
MCQmedium

An organization uses a central syslog server to collect logs from firewalls, servers, and network devices. Recently, the security team noticed that some critical events from the firewall are missing from the syslog server. The firewall configuration sends syslog messages using UDP to the syslog server. The syslog server administrator reports that the server is receiving a high volume of logs and occasionally drops packets due to buffer overflow. The team needs to ensure reliable delivery of all syslog messages without losing any. Which solution should the team implement?

A.Switch to TCP-based syslog with TLS.
B.Increase the UDP buffer size on the syslog server.
C.Implement log aggregation at each network segment.
D.Use a load balancer for syslog receivers.
AnswerA

TCP-based syslog with TLS provides acknowledged, ordered delivery, so dropped or lost packets are retransmitted rather than silently discarded. TLS also protects log integrity and confidentiality in transit, directly satisfying the requirement for reliable delivery without loss.

Why this answer

Syslog over UDP is fire-and-forget with no delivery guarantees, so packet loss from buffer overflow is expected. Switching to TCP-based syslog (ideally with TLS, i.e., RFC 5425) provides connection-oriented, reliable delivery with acknowledgments and retransmission, ensuring no messages are lost.

Exam trap

The trap here is assuming that tuning UDP (buffer size, aggregation, load balancing) can make it reliable — UDP is inherently lossy, and only a connection-oriented protocol like TCP/TLS guarantees delivery.

How to eliminate wrong answers

Option B is wrong because increasing the UDP buffer only delays overflow under sustained high volume — UDP still has no retransmission, so packets will eventually be dropped. Option C is wrong because log aggregation at each segment reduces traffic to the central server but does not change UDP's unreliable delivery semantics; messages can still be lost in transit. Option D is wrong because a load balancer distributes syslog traffic across receivers but does nothing to guarantee delivery of individual UDP datagrams that are dropped.

49
MCQhard

A company implements a password policy requiring a minimum length of 12 characters, including uppercase, lowercase, digits, and special characters. Passwords must be changed every 90 days, and the last 10 passwords cannot be reused. After a brute-force attack, several accounts were compromised despite the policy. Which additional control would most effectively mitigate such attacks?

A.Use a password blacklist
B.Increase minimum password length to 16 characters
C.Implement account lockout after 5 failed attempts
D.Require password change every 30 days
AnswerC

Account lockout after five failed attempts halts repeated authentication guesses, so a brute-force attack cannot continue indefinitely against an account. Length and complexity rules alone do not stop sustained automated guessing, making lockout the control that directly mitigates this attack.

Why this answer

Account lockout after a small number of failed attempts directly defeats brute-force attacks by halting the attack after a threshold, regardless of password complexity. Even a 12-character complex password can eventually be brute-forced given unlimited attempts; lockout removes that unlimited-attempt advantage. This is the most effective additional control because it targets the attack mechanism itself rather than the password's guessability.

Exam trap

SSCP often tests the misconception that stronger password complexity alone stops brute-force attacks — the real defense is limiting the number of attempts via lockout or rate limiting.

How to eliminate wrong answers

Option A is wrong because a password blacklist only blocks known-weak or breached passwords at creation/change time; it does nothing to stop an attacker from brute-forcing an existing valid password. Option B is wrong because increasing length to 16 characters raises the search space but still permits unlimited guessing, so a determined attacker with time and compute can eventually succeed — it slows but does not stop brute force. Option D is wrong because more frequent password changes (30 days) actually encourages weaker, predictable password patterns and does not prevent brute-force attempts against the current password; NIST SP 800-63B now discourages forced periodic rotation.

50
Multi-Selecthard

During forensic analysis, which THREE pieces of evidence should be preserved in original form?

Select 3 answers
A.Network traffic capture
B.Screenshots of malware dialogs
C.System event logs exported to CSV
D.RAM dump
E.Hard drive image
AnswersA, D, E

PCAP files preserve network evidence.

Why this answer

Network traffic captures (e.g., PCAP files) are raw, bit-for-bit recordings of network packets. They preserve the original timing, headers, and payloads without any transformation, which is critical for accurate forensic reconstruction and chain of custody. Any conversion or export (like CSV) would strip metadata and alter the original evidence.

Exam trap

ISC2 often tests the distinction between original/volatile evidence and derivative/converted evidence, trapping candidates who think exported logs or screenshots are acceptable substitutes for the raw, unaltered source.

51
MCQhard

A security analyst is reviewing a disaster recovery plan and notes that the organization has a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 2 hours for a critical database. Which of the following backup strategies BEST meets these objectives?

A.Continuous data protection (CDP) with asynchronous replication to a hot site.
B.Hourly incremental backups to a local NAS with nightly replication to a warm site.
C.Daily full backups with weekly tape rotation stored offsite.
D.Weekly full backups with daily differential backups stored in the cloud.
AnswerA

CDP captures every change and can provide an RPO of near zero, easily meeting the 15-minute requirement. Asynchronous replication to a hot site allows for rapid recovery, often within minutes, satisfying the 2-hour RTO. This combination ensures minimal data loss and quick restoration, aligning with the critical database's needs.

Why this answer

The RPO of 15 minutes requires that no more than 15 minutes of data can be lost, necessitating continuous or near-continuous backup. The RTO of 2 hours demands rapid recovery, which a hot site with asynchronous replication can provide. Continuous data protection combined with a hot site meets both objectives by minimizing data loss and downtime.

Exam trap

The trap here is assuming that hourly backups meet a 15-minute RPO or that a warm site can recover within 2 hours.

52
MCQmedium

A company is developing a DR plan for a critical database. The maximum acceptable downtime is 2 hours, and the maximum data loss is 1 hour. What are the RTO and RPO?

A.RTO = 2 hours, RPO = 1 hour
B.RTO = 1 hour, RPO = 1 hour
C.RTO = 1 hour, RPO = 2 hours
D.RTO = 2 hours, RPO = 2 hours
AnswerA

RTO defines the maximum tolerable downtime, so 2 hours maps directly to RTO. RPO defines the maximum tolerable data loss measured in time, so 1 hour maps to RPO. The option matches both stated constraints exactly.

Why this answer

The Recovery Time Objective (RTO) is the maximum acceptable downtime, which is 2 hours. The Recovery Point Objective (RPO) is the maximum acceptable data loss, which is 1 hour. Therefore, option A correctly identifies RTO = 2 hours and RPO = 1 hour.

Exam trap

The trap here is confusing RTO (time to recover) with RPO (data loss tolerance), leading candidates to swap the two values or assume they must be equal.

How to eliminate wrong answers

Option B is wrong because it swaps the RTO and RPO values, incorrectly setting RTO to 1 hour (the maximum data loss) and RPO to 1 hour (the maximum downtime). Option C is wrong because it inverts the definitions, setting RTO to 1 hour (data loss) and RPO to 2 hours (downtime). Option D is wrong because it sets both RTO and RPO to 2 hours, ignoring the specified 1-hour maximum data loss constraint.

53
MCQmedium

During the detection and analysis phase, an analyst receives a user report of unusual system behavior. The analyst reviews logs and finds several failed login attempts followed by a successful login from an unusual IP address. What is the next step?

A.Immediately disconnect the user's workstation from the network.
B.Rebuild the user's workstation from a known-good image.
C.Classify the incident and determine if escalation is needed.
D.Ignore the event as it may be a false positive.
AnswerC

Failed logins followed by a success from an unusual IP indicate probable compromise, so the analyst must classify the incident and decide whether escalation is warranted. Classification determines severity and the appropriate response path within detection and analysis.

Why this answer

During the detection and analysis phase of incident response, the primary goal is to assess the validity and scope of a potential security event before taking action. The analyst has observed indicators of a possible brute-force attack (failed logins followed by a successful login from an unusual IP), which requires classification to determine if it meets the criteria for a security incident. Escalation may be needed to involve a higher-tier incident response team or to initiate formal containment procedures, as per NIST SP 800-61 guidelines.

Exam trap

The trap here is that candidates often confuse the detection and analysis phase with the containment phase in the SSCP incident response lifecycle, leading them to choose immediate disconnection (Option A) instead of first classifying the incident and determining the need for escalation.

How to eliminate wrong answers

Option A is wrong because immediately disconnecting the user's workstation from the network is a premature containment action that should only occur after the incident has been confirmed and classified; doing so could disrupt business operations and destroy volatile evidence (e.g., active network connections, memory contents). Option B is wrong because rebuilding the workstation from a known-good image is a recovery step that occurs after containment, eradication, and evidence preservation; skipping analysis could result in losing forensic data needed to identify the root cause and prevent recurrence. Option D is wrong because ignoring the event as a false positive is negligent; the combination of multiple failed logins followed by a successful login from an unusual IP address is a classic indicator of a successful password-guessing attack and warrants investigation, not dismissal.

54
Matchingmedium

Match each security control to its type (administrative, technical, physical).

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Administrative

Technical

Physical

Technical

Why these pairings

Firewall, security policy, and biometric lock are correctly matched to technical, administrative, and physical controls respectively. Common confusions include misclassifying firewalls as physical controls or security policies as technical controls.

55
Multi-Selecteasy

Which TWO of the following are key components of a data classification policy? (Select the two best answers.)

Select 2 answers
A.Encryption algorithm selection
B.Firewall rules
C.Classification labels
D.Data custodian responsibilities
E.Backup schedules
AnswersC, D

Classification labels are the tangible tags (such as Public, Internal, Confidential) applied to data assets. Without defined labels, a classification policy cannot be enforced or communicated, making them a core structural component of the policy.

Why this answer

A data classification policy must define the classification labels (e.g., Public, Internal, Confidential, Restricted) that are applied to data so that handling requirements can be tied to each level, making option C correct. It must also assign data custodian responsibilities, since custodians are the roles accountable for implementing the handling, storage, and protection controls mandated for each classification level, making option D correct. Encryption algorithm selection (A) is a technical control chosen during implementation, not a defining component of the classification policy itself.

Firewall rules (B) are network security controls unrelated to how data is categorized. Backup schedules (E) are operational procedures typically documented in a backup or business continuity policy, not in the data classification policy.

Exam trap

SSCP often tests the distinction between policy components and technical controls, so candidates may mistakenly select encryption or firewall rules as part of the policy when they are actually implementation details derived from it.

56
MCQhard

An organization implements a hybrid encryption scheme to secure sensitive emails. The email body is encrypted with AES-256, and the AES key is encrypted with RSA-2048. What is the primary advantage of this approach?

A.Ensures forward secrecy
B.Simplifies key management by using a single key
C.Combines performance of symmetric with secure key distribution of asymmetric
D.Provides non-repudiation for the email
AnswerC

AES-256 provides fast bulk encryption of the email body, while RSA-2048 securely wraps the AES session key, solving symmetric key distribution without a shared secret channel. This hybrid design satisfies the scenario's need for efficient confidentiality plus safe key exchange across untrusted recipients.

Why this answer

Hybrid encryption combines the speed of symmetric encryption (AES-256) for bulk data with the secure key distribution of asymmetric encryption (RSA-2048). The symmetric key encrypts the email body efficiently, while the asymmetric key encrypts only the symmetric key, solving the key distribution problem without sacrificing performance.

Exam trap

The trap here is that candidates confuse hybrid encryption with forward secrecy or non-repudiation, but hybrid encryption specifically addresses the performance vs. key distribution trade-off, not security properties like forward secrecy or authentication.

How to eliminate wrong answers

Option A is wrong because forward secrecy requires ephemeral key exchange (e.g., Diffie-Hellman) where compromise of a long-term key does not expose past sessions; RSA-2048 alone does not provide forward secrecy. Option B is wrong because hybrid encryption actually increases key management complexity by requiring both a symmetric key and an asymmetric key pair, not simplifying to a single key. Option D is wrong because non-repudiation is provided by digital signatures (e.g., using RSA or DSA), not by encryption; encrypting the AES key with RSA does not prove the sender's identity.

57
MCQhard

A security team is designing an access control system for a research facility. They need a model that supports fine-grained, dynamic access decisions based on user department, project assignment, time of day, and the sensitivity of the resource. The model must also allow policies to be expressed in a human-readable language and evaluated at runtime. Which access control model best fits these requirements?

A.Attribute-based access control (ABAC)
B.Role-based access control (RBAC)
C.Mandatory access control (MAC)
D.Discretionary access control (DAC)
AnswerA

ABAC evaluates attributes of subjects, objects, and the environment to make access decisions. It can incorporate department, project, time of day, and resource sensitivity dynamically. Policies can be written in languages like XACML, which are human-readable. This model provides the fine-grained, runtime evaluation required, making it the best fit for the research facility's needs.

Why this answer

Attribute-based access control (ABAC) is designed to evaluate multiple attributes—user, resource, and environmental—at runtime, enabling dynamic and fine-grained decisions. It supports policy languages such as XACML, which are human-readable. RBAC, MAC, and DAC do not offer this combination of dynamic attribute evaluation and expressive policy language, so ABAC is the correct choice.

Exam trap

The trap here is confusing RBAC's role assignments with ABAC's dynamic attribute evaluation, overlooking that only ABAC can incorporate environmental conditions like time of day at runtime.

58
MCQhard

A forensic examiner is preparing to acquire a disk image from a compromised server. The server is still running and contains critical evidence in volatile memory. According to NIST SP 800-86, which of the following should the examiner do FIRST?

A.Capture the contents of RAM using a memory acquisition tool.
B.Document the system's physical configuration and cable connections.
C.Create a bit-for-bit image of the hard drive.
D.Shut down the server to preserve the disk state.
AnswerA

According to NIST SP 800-86 and the order of volatility, volatile data such as RAM contents should be collected first because it is lost when the system is powered off. Capturing RAM preserves critical evidence like running processes, network connections, and encryption keys. This step must precede disk imaging to ensure that the most perishable evidence is not lost.

Why this answer

The order of volatility in digital forensics dictates that the most perishable evidence, such as RAM and running processes, must be collected first. NIST SP 800-86 emphasizes capturing volatile memory before disk imaging or shutting down the system. This ensures that critical evidence like encryption keys, network connections, and malware artifacts are preserved for analysis.

Exam trap

The trap here is assuming that disk imaging is the first step, but volatile memory is more perishable and must be captured first.

59
MCQhard

An organization uses ABAC to control access to a document. Which attribute combination would be used to allow access only during business hours from a managed device?

A.User department and document creation date
B.User identity, time of day, and device compliance status
C.User role and document classification
D.Document owner and file size
AnswerB

User identity, time of day, and device compliance status map directly onto ABAC's three attribute categories: subject, environmental, and resource/device. Time of day satisfies the business-hours constraint, while device compliance status enforces the managed-device requirement, so the policy evaluates all three conditions together before granting document access.

Why this answer

ABAC (Attribute-Based Access Control) evaluates policies against attributes of the subject, resource, action, and environment. To allow access only during business hours from a managed device, the policy must combine a time-of-day environmental attribute with a device compliance attribute, plus the user identity to identify the subject. Option B lists exactly these three: user identity, time of day, and device compliance status.

Exam trap

The trap is confusing ABAC with RBAC — candidates pick role-based options (role + classification) because they look security-relevant, but ABAC specifically requires environmental and device attributes to enforce context-aware conditions like time and device posture.

How to eliminate wrong answers

Option A is wrong because department and document creation date do not address time-of-day or device posture — creation date is a resource attribute that has no bearing on when or from where access occurs. Option C is wrong because role and classification are RBAC/classification attributes; they cannot enforce time windows or device compliance, which are environmental and device attributes respectively. Option D is wrong because document owner and file size are irrelevant to temporal or device-based conditions; file size is not a security-relevant attribute for access decisions.

60
MCQeasy

Which type of IDS uses a database of known attack patterns to identify malicious activity?

A.Behavior-based IDS
B.Network-based IDS
C.Anomaly-based IDS
D.Signature-based IDS
AnswerD

Signature-based IDS matches network traffic against a database of known attack signatures, satisfying the stem's requirement to identify malicious activity using known attack patterns. It detects previously catalogued threats with high accuracy but cannot recognise novel or polymorphic attacks lacking an existing signature.

Why this answer

Signature-based IDS (D) is correct because it relies on a pre-defined database of known attack patterns, or signatures, to match against network traffic or system activity. When a packet or event matches a signature, the IDS generates an alert. This is the traditional method used by systems like Snort, which compares traffic against rule sets containing specific byte sequences or protocol anomalies.

Exam trap

The trap here is confusing the detection method (signature-based) with the deployment type (network-based), leading candidates to pick 'Network-based IDS' because they associate it with monitoring network traffic, even though the question specifically asks about the detection methodology using known attack patterns.

How to eliminate wrong answers

Option A is wrong because behavior-based IDS (also known as anomaly-based) establishes a baseline of normal activity and flags deviations, not known attack patterns. Option B is wrong because network-based IDS describes the deployment location (monitoring network traffic) rather than the detection methodology; a network-based IDS can be either signature-based or anomaly-based. Option C is wrong because anomaly-based IDS uses statistical models or machine learning to detect deviations from a baseline of normal behavior, not a database of known attack signatures.

61
MCQhard

In RSA, the public exponent e is often chosen as 65537. What is the primary reason for this choice?

A.It ensures that the private key d is small
B.It prevents side-channel attacks
C.It provides the highest security level
D.It offers a balance between security and performance due to low Hamming weight
AnswerD

65537 is 2¹⁶+1, so its binary form has only two set bits, giving a low Hamming weight. Modular exponentiation then needs far fewer multiplications than a random exponent of similar size, satisfying the performance constraint while remaining large enough to resist small-exponent attacks.

Why this answer

65537 (0x10001) has a low Hamming weight of only 2 bits set, which makes modular exponentiation significantly faster than using a random large exponent, while still providing strong security. This choice balances computational efficiency with cryptographic strength, as a larger exponent would slow down encryption without proportional security gains.

Exam trap

ISC2 often tests the misconception that a larger exponent always means higher security, when in fact the exponent's size has negligible impact on security compared to the modulus length, and the real benefit of 65537 is performance due to its low Hamming weight.

How to eliminate wrong answers

Option A is wrong because a small public exponent e does not ensure a small private key d; in fact, d is typically large and unpredictable due to the modular inverse calculation. Option B is wrong because 65537 does not inherently prevent side-channel attacks; those require specific countermeasures like blinding or constant-time algorithms. Option C is wrong because 65537 does not provide the highest security level; security in RSA depends on key size (e.g., 2048-bit modulus), not on the exponent value, and larger exponents do not increase security.

62
Multi-Selectmedium

Which TWO of the following are examples of technical threat sources that should be considered during risk identification?

Select 2 answers
A.Earthquake
B.Hardware failure
C.Unauthorized access by employee
D.Software bug
E.Social engineering
AnswersB, D

Hardware failure counts as a technical threat source because it arises from the failure of technology components themselves, such as disk crashes or component degradation, rather than from environmental forces or human actors. Risk identification must catalogue it alongside software and network weaknesses.

Why this answer

Hardware failure (B) is a technical threat source because it arises from the failure of IT infrastructure components such as servers, disks, or network devices, which is a classic technology-originated risk considered in risk identification. Software bug (D) is also a technical threat source, as flaws in application or system code can introduce vulnerabilities and cause failures or exploitable conditions. These two are correct because they stem from technology itself rather than from natural events or deliberate human behavior.

In contrast, earthquake (A) is an environmental/natural threat source, unauthorized access by employee (C) is a human/internal threat source, and social engineering (E) is a human-driven threat that exploits people rather than a technical fault.

Exam trap

The trap here is that candidates confuse threat categories, mistakenly classifying human-based threats like social engineering or insider actions as technical threat sources, when the SSCP exam strictly separates technical threats (hardware/software failures) from human and environmental threats.

63
MCQhard

A forensic examiner is preparing to acquire a forensic image of a running Linux server that is suspected of being compromised. The server has active network connections and encrypted volumes. Which of the following should the examiner do FIRST according to the order of volatility?

A.Record the current network connections using netstat or ss.
B.Capture the swap partition to preserve encrypted volume keys.
C.Capture the contents of physical memory (RAM) using a tool such as LiME or AVML.
D.Create a bit-for-bit image of the hard drive using dd or a similar tool.
AnswerC

According to the order of volatility, memory (RAM) is more volatile than disk storage and network connections. Capturing RAM first preserves critical evidence such as running processes, network connections, encryption keys, and malware that may only exist in memory. If the system is shut down or the memory is overwritten, this evidence is lost forever. Tools like LiME or AVML allow for memory acquisition on Linux systems while minimizing impact on the running system.

Why this answer

The order of volatility dictates that the most volatile data should be collected first. RAM is more volatile than disk storage and contains critical evidence such as running processes, network connections, and encryption keys. Capturing RAM first with tools like LiME or AVML ensures that this ephemeral data is preserved before it is lost or altered.

Disk imaging, network connection recording, and swap capture are important but should follow memory acquisition to maintain the integrity of the most volatile evidence.

Exam trap

The trap here is assuming that disk imaging or recording network connections should come first, but the order of volatility requires capturing RAM before any disk-based or less volatile sources.

64
MCQmedium

A user reports that they cannot access a network share. The administrator checks the share permissions and NTFS permissions. The share permission allows Everyone: Read, and the NTFS permission allows the user: Full Control. What is the user's effective access?

A.Read
B.Full Control
C.No access
D.Modify
AnswerA

Share and NTFS permissions combine, and the most restrictive wins. Everyone grants Read at share level, while NTFS grants Full Control. The effective access is therefore Read, because the share permission caps what NTFS allows.

Why this answer

When accessing a network share, the effective permissions are the most restrictive of the share permissions and the NTFS permissions. Here, the share permission is Read and the NTFS permission is Full Control. The most restrictive permission is Read, so the user's effective access is Read.

Exam trap

The trap here is that candidates often assume the user gets the higher of the two permissions (Full Control) rather than the most restrictive, leading them to incorrectly select Full Control.

How to eliminate wrong answers

Option B is wrong because Full Control is not the effective access; the share permission restricts it to Read, as the effective permission is the most restrictive of the two sets. Option C is wrong because the user does have access—specifically Read access—since neither permission denies access outright. Option D is wrong because Modify is a higher permission than Read and is not granted; the share permission explicitly limits access to Read only.

65
MCQhard

A security operations team suspects that an attacker has compromised a Linux web server and is maintaining persistence. The team wants to identify unauthorized scheduled tasks that survive reboots. Which set of locations should the team review FIRST?

A.The /etc/hosts file and the resolver configuration in /etc/resolv.conf.
B.The systemd timer units, cron tables in /etc/cron* and /var/spool/cron, and the /etc/rc.local startup script.
C.The bash history files in each user's home directory.
D.The /var/log/auth.log and /var/log/secure authentication logs.
AnswerB

On modern Linux, persistence that survives reboot is typically implemented through systemd timers, user and system cron entries, or legacy startup scripts such as rc.local. Reviewing these locations directly targets mechanisms that re-launch malicious code after a restart, making this the correct first step for identifying reboot-surviving persistence.

Why this answer

Reboot-surviving persistence on Linux resides in scheduled execution mechanisms such as systemd timers, cron directories, and legacy startup scripts. These are the components that automatically run code after a restart. Name resolution files, shell history, and authentication logs are valuable for context and detection but do not themselves relaunch an implant.

Exam trap

The trap here is equating general incident-response artifacts such as logs and shell history with persistence mechanisms, when only scheduled execution structures survive a reboot.

66
MCQmedium

During a quarterly risk review, a hospital's security team identifies that legacy medical devices cannot be patched and run outdated operating systems. Which risk treatment strategy is most appropriate for these devices?

A.Remediate by applying vendor patches
B.Implement compensating controls such as network segmentation and strict access control
C.Retire and replace all devices immediately
D.Transfer the risk by purchasing cyber insurance
AnswerB

Because the legacy devices cannot be patched, the residual risk must be reduced through compensating controls: network segmentation isolates them and strict access control limits exposure. This treats the risk without requiring the unavailable patching the stem rules out.

Why this answer

Since the legacy medical devices cannot be patched due to vendor obsolescence, the most appropriate risk treatment strategy is to implement compensating controls. Network segmentation (e.g., VLANs or firewalls) isolates the devices from the main hospital network, while strict access control (e.g., 802.1X or MAC-based filtering) limits exposure to threats. This reduces the likelihood of exploitation without relying on patching the outdated operating systems.

Exam trap

ISC2 often tests the misconception that 'remediate' always means patching, but for legacy systems where patching is impossible, compensating controls are the correct risk treatment strategy, not immediate replacement or insurance.

How to eliminate wrong answers

Option A is wrong because applying vendor patches is not feasible for legacy devices that are no longer supported or have no available patches, making remediation impossible. Option C is wrong because retiring and replacing all devices immediately is often impractical due to cost, downtime, and regulatory approval processes, and is not the most appropriate first step in risk treatment. Option D is wrong because transferring risk via cyber insurance does not reduce the actual vulnerability or likelihood of exploitation; it only provides financial compensation after an incident, which is insufficient for protecting patient safety and data.

67
MCQmedium

An organization's web application experienced a data breach due to a SQL injection vulnerability. During the risk analysis phase, the security team calculated the SLE as $25,000 and the ARO as 0.5. What is the ALE?

A.$50,000
B.$25,000
C.$6,250
D.$12,500
AnswerD

ALE is derived by multiplying single loss expectancy by annualised rate of occurrence: $25,000 × 0.5 = $12,500. This satisfies the stem's requirement to quantify expected yearly loss from the SQL injection breach, giving the security team a monetary figure for risk prioritisation.

Why this answer

The Annualized Loss Expectancy (ALE) is calculated by multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO). Given an SLE of $25,000 and an ARO of 0.5, the ALE is $25,000 × 0.5 = $12,500. This quantifies the expected annual financial loss from the SQL injection vulnerability.

Exam trap

The trap here is that candidates often confuse multiplication with division or forget to apply the ARO, selecting the SLE value directly instead of computing the product.

How to eliminate wrong answers

Option A is wrong because $50,000 results from incorrectly dividing SLE by ARO (i.e., $25,000 / 0.5) rather than multiplying. Option B is wrong because $25,000 equals the SLE itself, ignoring the ARO factor entirely. Option C is wrong because $6,250 comes from dividing SLE by 4 or multiplying by 0.25, which does not correspond to any standard risk calculation formula.

68
MCQmedium

A security administrator is configuring a Linux server that hosts a shared project directory. The requirement is that new files created in the directory /projects/team must automatically inherit the group owner of the parent directory rather than the primary group of the user who created them. The administrator wants the setting to apply only to that directory. Which command should the administrator use?

A.chmod +t /projects/team
B.setfacl -d -m g:team:rwx /projects/team
C.chown :team /projects/team
D.chmod g+s /projects/team
AnswerD

Setting the setgid bit on a directory causes new files and subdirectories created within it to inherit the directory's group ownership instead of the creator's primary group. This directly satisfies the requirement that files in /projects/team retain the team group. The command applies only to the specified directory and does not affect other paths, which matches the scoped requirement.

Why this answer

The setgid bit on a directory is the standard Unix mechanism for ensuring that files and subdirectories created within it inherit the directory's group ownership. This is commonly used for shared project directories where collaboration among group members is required. Other options either alter permissions without affecting ownership, change only the directory's group, or set the sticky bit, which controls deletion rather than ownership inheritance.

Exam trap

The trap here is confusing the sticky bit with the setgid bit, since both are special permission bits applied to directories but serve entirely different purposes.

69
Multi-Selectmedium

A security analyst is reviewing a web application that stores user session identifiers in cookies. The analyst wants to recommend cookie attributes that reduce the risk of session hijacking through cross-site scripting (XSS) and cross-site request forgery (CSRF). Which TWO of the following cookie attributes should the analyst recommend? (Choose two.)

Select 2 answers
A.Max-Age
B.Domain
C.SameSite
D.HttpOnly
E.Secure
AnswersC, D

The SameSite attribute controls whether the browser sends the cookie with cross-site requests. Setting SameSite to Lax or Strict prevents the cookie from being included in requests originating from other sites, which blocks CSRF attacks. This directly addresses the CSRF concern and complements HttpOnly for XSS protection, making it one of the two correct recommendations.

Why this answer

HttpOnly prevents JavaScript from reading the session cookie, mitigating session theft via XSS. SameSite restricts the browser from sending the cookie on cross-site requests, mitigating CSRF. Together they address both threats named in the scenario.

Secure, Domain, and Max-Age provide other benefits but do not directly counter XSS cookie theft or CSRF in the way the analyst requires.

Exam trap

The trap here is selecting Secure as a mitigation for XSS, when Secure only protects cookies in transit and does not stop client-side script access.

70
Multi-Selecteasy

A system administrator is applying CIS Benchmarks to a Windows server. Which TWO hardening measures are typically recommended by CIS? (Select TWO.)

Select 2 answers
A.Enable all Windows features by default
B.Disable audit logging
C.Enforce strong password policies
D.Disable unused services
E.Allow anonymous enumeration of SAM accounts
AnswersC, D

Strong password policies enforce complexity, length and expiry through Group Policy, blocking weak credentials that brute-force and credential-stuffing attacks exploit. CIS Benchmarks recommend this account-policy hardening for Windows servers, satisfying the stem's requirement for a typically recommended measure.

Why this answer

Option C (Enforce strong password policies) is correct because CIS Benchmarks for Windows Server explicitly require configuring account policies such as minimum password length (typically 14 characters), password complexity, maximum password age, and password history to reduce the risk of brute-force and credential-guessing attacks. Option D (Disable unused services) is correct because CIS hardening guidance mandates disabling or setting to Disabled any unnecessary services (e.g., Fax, Windows Search, Remote Registry) to shrink the attack surface and eliminate unneeded listening ports and privileged functionality. Option A is wrong because enabling all Windows features by default directly contradicts CIS least-functionality principles, which call for removing or not installing unneeded roles and features.

Option B is wrong because CIS Benchmarks require enabling and configuring audit logging (e.g., via Advanced Audit Policy) to capture security-relevant events, not disabling it. Option E is wrong because allowing anonymous enumeration of SAM accounts is a known information-disclosure weakness that CIS explicitly prohibits by requiring the Anonymous Enumeration of SAM Accounts and Shares setting to be Disabled.

Exam trap

The trap here is that 'enable all features' sounds like maximum functionality, but hardening exams consistently test that CIS Benchmarks are about minimization — fewer services, fewer features, stronger authentication, and more logging.

71
Multi-Selectmedium

A security analyst is configuring a network intrusion detection system (NIDS) to monitor traffic for signs of a SYN flood attack. The analyst wants to generate alerts when the number of half-open connections exceeds a threshold. Which TWO of the following metrics are MOST relevant for detecting a SYN flood? (Choose two.)

Select 2 answers
A.Number of SYN packets received per second
B.Number of established connections
C.Number of half-open connections
D.Number of ICMP echo requests
E.Number of RST packets sent
AnswersA, C

A high rate of SYN packets is a primary indicator of a SYN flood, as the attacker sends many SYN requests to exhaust the target's connection table. Monitoring the rate of SYN packets helps detect the initial phase of the attack. However, it must be correlated with other metrics to avoid false positives from legitimate traffic spikes.

Why this answer

A SYN flood is characterized by a high volume of SYN packets and a corresponding increase in half-open connections. Monitoring these two metrics allows the NIDS to detect the attack by recognizing the abnormal rate of SYNs and the accumulation of incomplete handshakes. The other metrics do not directly reflect the mechanics of a SYN flood and would not provide reliable detection.

Exam trap

The trap here is confusing SYN floods with other types of floods (e.g., ICMP or UDP) and focusing on metrics that are not specific to TCP half-open connections.

72
MCQmedium

An organization wants to identify risks related to a new cloud-based customer relationship management (CRM) system. Which approach would best identify threats and vulnerabilities specific to this system?

A.Run a vulnerability scan on the CRM
B.Execute a business impact analysis (BIA)
C.Perform a threat modeling exercise such as STRIDE
D.Conduct a qualitative risk assessment using a generic framework
AnswerC

STRIDE systematically enumerates spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege across the CRM's data flows, trust boundaries and components, exposing threats and vulnerabilities unique to its cloud architecture rather than relying on generic checklists.

Why this answer

Threat modeling with STRIDE is the best approach because it systematically identifies threats (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) specific to the CRM's architecture, data flows, and trust boundaries. Unlike generic scans or assessments, STRIDE focuses on the unique attack surface of a cloud-based system, such as API endpoints, multi-tenancy risks, and shared responsibility model gaps.

Exam trap

The trap here is that candidates confuse vulnerability scanning (Option A) with threat modeling, assuming that scanning for known flaws is sufficient, when in fact threat modeling is required to identify design-level and cloud-specific threats that scanners cannot detect.

How to eliminate wrong answers

Option A is wrong because a vulnerability scan only identifies known software flaws (e.g., CVEs) but does not uncover design-level threats, business logic flaws, or cloud-specific risks like misconfigured IAM roles or insecure API endpoints. Option B is wrong because a business impact analysis (BIA) prioritizes criticality and recovery objectives (RTO/RPO) but does not identify threats or vulnerabilities; it assumes risks are already known. Option D is wrong because a qualitative risk assessment using a generic framework lacks the structured, system-specific decomposition needed to uncover threats unique to the CRM's cloud architecture, such as tenant isolation failures or data leakage via shared storage.

73
MCQmedium

Which security control can prevent a rogue DHCP server from assigning incorrect gateway addresses to clients?

A.IP source guard
B.Dynamic ARP inspection
C.Port security
D.DHCP snooping
AnswerD

DHCP snooping designates trusted ports and filters server replies on untrusted ones, so a rogue DHCP server cannot hand out a falsified default gateway. This directly satisfies the stem's constraint of preventing incorrect gateway assignment.

Why this answer

DHCP snooping is a switch feature that filters DHCP messages based on trusted ports, blocking rogue DHCP servers.

74
MCQhard

Refer to the exhibit. A security analyst reviews these iptables rules and expects SSH access to be blocked, but it is still allowed. What is the MOST likely reason?

A.The DROP rule does not apply to SSH.
B.The DROP rule is misconfigured with wrong source.
C.The ACCEPT rule matches before the DROP rule.
D.The default policy allows traffic, overriding the DROP rule.
AnswerC

iptables evaluates rules sequentially within a chain and stops at the first match. If a permissive ACCEPT rule for SSH appears above the DROP rule, traffic is accepted before the DROP is ever evaluated, so ordering, not rule logic, causes the block to fail.

Why this answer

C is correct because iptables processes rules in sequential order, and the first matching rule determines the packet's fate. In this scenario, the ACCEPT rule for SSH (typically matching on port 22) appears before the DROP rule in the chain, so incoming SSH packets match the ACCEPT rule first and are permitted, never reaching the subsequent DROP rule. This is a classic ordering issue where a more specific allow rule precedes a general deny rule.

Exam trap

The trap here is that candidates often assume iptables evaluates all rules and applies the most restrictive one, but in reality, iptables uses first-match logic, so rule order is critical.

How to eliminate wrong answers

Option A is wrong because the DROP rule likely does apply to SSH if it matches on the SSH port (22) or protocol (TCP), but the rule order prevents it from being evaluated. Option B is wrong because the DROP rule's source address is irrelevant if the rule is never reached due to a preceding ACCEPT rule; a misconfigured source would cause a different behavior (e.g., blocking wrong traffic), not allow SSH when it should be blocked. Option D is wrong because the default policy (typically ACCEPT or DROP) only applies to packets that do not match any explicit rule; here, an explicit ACCEPT rule matches SSH, so the default policy is never consulted.

75
Multi-Selectmedium

A security team is conducting a lessons learned meeting after a major security incident. Which TWO of the following are PRIMARY objectives of this meeting? (Choose two.)

Select 2 answers
A.Identify the root cause of the incident to prevent recurrence.
B.Determine the financial cost of the incident for insurance claims.
C.Evaluate the effectiveness of the incident response process and identify improvements.
D.Assign blame to the individuals responsible for the incident.
E.Update the disaster recovery plan with new backup procedures.
AnswersA, C

One primary objective of a lessons learned meeting is to determine the root cause of the incident. By understanding what allowed the incident to occur, the team can implement corrective actions to prevent similar incidents in the future. This analysis is a core part of the post-incident activity phase in NIST SP 800-61.

Why this answer

The primary objectives of a lessons learned meeting are to identify the root cause of the incident and to evaluate the effectiveness of the incident response process. These objectives help the organization prevent future incidents and improve its response capabilities. Blame assignment, financial cost determination, and specific plan updates are not primary goals of this meeting.

Exam trap

The trap here is thinking that assigning blame or determining financial costs are key objectives, when the focus should be on learning and improvement.

Page 1 of 13

Page 2