Courseiva

Systems Security Certified Practitioner SSCP (SSCP) — Questions 676–750

971 questions total · 13pages · All types, answers revealed

Page 9

Page 10 of 13

Page 11
676
MCQmedium

A security administrator receives an alert from the SIEM indicating a configuration change on a critical server. The change was not part of any approved change request. What should be the first step?

A.Investigate the change to determine its source and impact
B.Notify the server owner
C.Revert the server to the last known good configuration
D.Disable the server's network access
AnswerA

Investigating first establishes whether the unapproved configuration change is malicious or accidental and what it affected, which determines the appropriate containment or rollback. This satisfies the stem's requirement to identify the change's source and impact before acting.

Why this answer

The first step when an unauthorized configuration change is detected is to investigate the change to determine its source and impact. This aligns with the incident response process, where initial assessment (identification and scoping) precedes containment or remediation. Without investigation, reverting or disabling could destroy forensic evidence or disrupt legitimate services.

Exam trap

The trap here is that candidates often jump to immediate containment (revert or disable) without recognizing that the first step in incident response is always to verify and scope the incident before taking action.

How to eliminate wrong answers

Option B is wrong because notifying the server owner is premature; the security administrator must first gather information about the change to provide accurate context. Option C is wrong because reverting the server to the last known good configuration could destroy forensic evidence and may not address the root cause, potentially allowing the change to reoccur. Option D is wrong because disabling the server's network access is a containment step that should only be taken after investigation confirms malicious intent or immediate threat, as it could cause unnecessary service disruption.

677
MCQmedium

A healthcare organization is implementing an access control system to ensure that employees can only access patient records necessary for their job functions. Which model best enforces this principle?

A.Role-Based Access Control (RBAC)
B.Rule-Based Access Control (RuBAC)
C.Discretionary Access Control (DAC)
D.Mandatory Access Control (MAC)
AnswerA

RBAC assigns permissions to roles rather than individuals, so each employee inherits only the access their job function requires. This directly enforces least privilege for the healthcare scenario, since patient record access is granted by role membership and revoked automatically when someone changes positions.

Why this answer

Role-Based Access Control (RBAC) is the correct model because it assigns permissions based on job roles, ensuring employees only access patient records necessary for their duties. In healthcare, RBAC aligns with the principle of least privilege by mapping roles (e.g., nurse, doctor, billing) to specific data access, as defined in standards like NIST SP 800-53. This directly enforces the requirement that access is tied to job functions, not individual discretion or system-wide rules.

Exam trap

ISC2 often tests the distinction between RBAC and Rule-Based Access Control, where candidates mistakenly choose RuBAC because they confuse 'rules' with 'roles,' not realizing RuBAC applies static conditions to all users rather than dynamic role assignments.

How to eliminate wrong answers

Option B (Rule-Based Access Control) is wrong because it uses global rules (e.g., time-of-day or IP-based conditions) applied uniformly to all users, not role-specific job functions, making it too coarse for granular patient record access. Option C (Discretionary Access Control) is wrong because it allows data owners to grant access at their discretion, violating the mandatory job-function restriction and risking unauthorized sharing of patient records. Option D (Mandatory Access Control) is wrong because it enforces system-wide labels (e.g., classification levels like 'Confidential') rather than job roles, which is overly rigid and does not map to specific healthcare job functions.

678
MCQhard

Which network security control can enforce that only authorized devices with current antivirus and patches can connect to the network?

A.Firewall rules
B.Network Access Control
C.Intrusion Prevention System
D.Port security
AnswerB

Network Access Control enforces endpoint compliance at connection time, quarantining or denying devices whose antivirus definitions or patches are missing or outdated. It is the only listed control that gates network admission on the device's current security posture.

Why this answer

Network Access Control (NAC) is designed to enforce endpoint compliance before granting network access. It checks devices for up-to-date antivirus, patches, and other security posture requirements, and can quarantine or deny access if they fail. This matches the requirement of ensuring only authorized devices with current antivirus and patches can connect.

Exam trap

The trap here is confusing network access control with other security controls that also restrict access, such as firewalls or port security, but do not perform endpoint posture checking.

How to eliminate wrong answers

Option A is wrong because firewall rules filter traffic based on IP addresses, ports, and protocols, but they do not assess the security posture of endpoints (e.g., antivirus status or patch level). Option C is wrong because an Intrusion Prevention System monitors network traffic for malicious activity and can block attacks, but it does not enforce endpoint compliance before allowing connection. Option D is wrong because port security on a switch restricts which MAC addresses can use a port, preventing unauthorized devices but not checking antivirus or patch status.

679
MCQmedium

A software vendor ships a Java-based payment service to a customer's data center. The customer's security team requires that the application run with only the minimum privileges necessary and cannot be trusted to restrict itself. Which mechanism should the security team use to enforce these restrictions on the JVM?

A.Java security policy files configured with a SecurityManager
B.Running the JVM as a Windows service under Local System
C.Enabling verbose garbage collection logging
D.Code signing the JAR with a trusted certificate
AnswerA

A Java security policy file lists the exact permissions granted to code, and the SecurityManager enforces them at runtime by checking each sensitive operation against the policy. This gives the security team an external, declarative way to restrict the application to only the privileges it needs, independent of how the application is written.

Why this answer

Java's SecurityManager works with a policy file that enumerates granted permissions, so code is denied anything not explicitly allowed. This lets the security team enforce least privilege from outside the application, which matches the requirement that the application itself not be trusted to limit its own access.

Exam trap

The trap here is assuming that signing an application's code automatically restricts what it can do, when signing addresses authenticity rather than runtime privilege.

680
MCQmedium

A security metric shows that patch compliance is at 85%. The goal is 95%. Which action should be taken first?

A.Increase the frequency of vulnerability scans
B.Disable automatic updates to prevent issues
C.Prioritize patching based on vulnerability criticality
D.Exclude non-critical systems from patching
AnswerC

Prioritising by vulnerability criticality directs remediation toward the highest-risk exposures first, satisfying the stem's requirement to close the 10% compliance gap efficiently. Rather than chasing every missing patch equally, risk-based sequencing reduces exploitable attack surface fastest when resources cannot immediately achieve full coverage.

Why this answer

When patch compliance is below target, the first step is to prioritize patching based on vulnerability criticality so that the most exploitable and highest-impact systems are remediated first. This maximizes risk reduction per unit of effort and directly addresses the gap between 85% and 95% by focusing resources where they matter most. Simply scanning more or excluding systems does not improve compliance meaningfully.

Exam trap

The trap is choosing 'increase scanning frequency' because it sounds proactive, when the metric measures patching — candidates must distinguish detection activities from remediation activities.

How to eliminate wrong answers

Option A is wrong because increasing scan frequency identifies vulnerabilities but does not remediate them — compliance is about patching, not detection, so this does not move the metric. Option B is wrong because disabling automatic updates would reduce patch coverage and worsen compliance, directly contradicting the goal. Option D is wrong because excluding non-critical systems from patching artificially inflates the compliance percentage without reducing actual risk, which is a policy violation and a security anti-pattern.

681
MCQeasy

After containing a malware outbreak, the incident response team needs to ensure the malware is completely removed from all systems. Which phase of the incident response process is this?

A.Post-Incident
B.Eradication
C.Detection
D.Recovery
AnswerB

Eradication removes malware artefacts, root causes and persistence mechanisms from affected systems, satisfying the stem's requirement for complete removal after containment. Unlike recovery, which restores normal operations, eradication focuses on eliminating the threat itself, ensuring no residual infection remains before systems return to production.

Why this answer

The eradication phase is specifically focused on removing the root cause of the incident, such as deleting malware files, registry keys, and disabling malicious services from all affected systems. After containment (which stops the spread), eradication ensures the threat is completely eliminated before recovery begins. This aligns with the NIST SP 800-61 incident response lifecycle, where eradication follows containment and precedes recovery.

Exam trap

The trap here is confusing eradication with recovery, as candidates often think 'removing malware' is part of getting systems back online, but recovery only begins after the threat is fully eradicated to avoid restoring infected data.

How to eliminate wrong answers

Option A is wrong because the post-incident phase occurs after recovery and involves lessons learned, documentation, and forensic analysis, not active removal of malware. Option C is wrong because detection is the initial phase where the incident is identified through alerts or anomalies, not the phase for removing the threat. Option D is wrong because recovery focuses on restoring systems to normal operation (e.g., restoring from clean backups, reconnecting to networks) after the malware has already been eradicated.

682
Multi-Selecthard

A network administrator is designing a secure remote access solution for employees using company laptops. The solution must support strong authentication, encryption, and be resistant to man-in-the-middle attacks. Which THREE components should be included?

Select 3 answers
A.L2TP tunneling protocol
B.EAP-TLS for authentication
C.IPsec in tunnel mode
D.PPTP with MPPE encryption
E.IKEv2 key exchange protocol
AnswersB, C, E

EAP-TLS authenticates both client and server using X.509 certificates, delivering mutual authentication without shared secrets. This satisfies the stem's strong authentication requirement and, because the server proves its identity, resists man-in-the-middle attacks against the remote access tunnel.

Why this answer

EAP-TLS (B) is correct because it uses digital certificates on both client and server to perform mutual authentication, providing strong identity verification and enabling the certificate-based trust needed to resist impersonation. IPsec in tunnel mode (C) is correct because it encrypts and authenticates the entire original IP packet between endpoints, protecting confidentiality and integrity of the traffic across an untrusted network. IKEv2 (E) is correct because it securely negotiates and rekeys IPsec security associations using strong cryptographic exchanges, and its support for MOBIKE helps maintain secure sessions while resisting man-in-the-middle interception.

L2TP (A) is not correct here because by itself it provides tunneling but no encryption or strong authentication, so it must be paired with IPsec rather than being the security component. PPTP with MPPE (D) is not correct because PPTP is obsolete and its MS-CHAPv2 authentication and MPPE encryption have well-known weaknesses that make it vulnerable to credential cracking and MITM attacks.

Exam trap

The trap is selecting L2TP or PPTP as they are VPN protocols, but they lack strong encryption or have known vulnerabilities. Candidates must recognize that EAP-TLS, IPsec tunnel mode, and IKEv2 are the secure components.

683
MCQmedium

A security analyst is tuning a SIEM to reduce false positives. Which of the following actions is most likely to reduce false positives while maintaining detection of real threats?

A.Increase the severity of all alerts to high
B.Modify correlation rules to require multiple events before alerting
C.Disable all anomaly-based detection rules
D.Create a whitelist for known benign IP addresses
AnswerB

Requiring several correlated events before an alert fires suppresses single-event noise, which is the main source of false positives, while genuine multi-stage attacks still trigger. This threshold tuning preserves detection fidelity better than disabling rules outright.

Why this answer

Modifying correlation rules to require multiple events before alerting reduces false positives by ensuring that a single benign event does not trigger an alert. This technique, often called 'thresholding' or 'event correlation,' filters out noise while still detecting multi-step attack patterns, such as a brute-force login attempt that requires multiple failed logins within a time window.

Exam trap

The trap here is that candidates often confuse 'reducing false positives' with 'eliminating all alerts,' leading them to choose disabling detection rules (Option C) or whitelisting (Option D), rather than understanding that correlation tuning preserves detection capability while filtering noise.

How to eliminate wrong answers

Option A is wrong because increasing the severity of all alerts to high does not reduce false positives; it merely reclassifies them, potentially causing alert fatigue and desensitizing analysts to critical incidents. Option C is wrong because disabling all anomaly-based detection rules would eliminate the ability to detect unknown or zero-day threats, which rely on behavioral baselines rather than static signatures. Option D is wrong because creating a whitelist for known benign IP addresses reduces false positives only for those specific IPs, but does not address false positives from other sources or from legitimate traffic that does not match the whitelist; it also risks missing real threats if an attacker spoofs a whitelisted IP.

684
MCQmedium

A financial services firm wants to let customers authorize a third-party budgeting application to read their account transaction history without sharing their banking password. Which technology should the firm deploy?

A.Remote Authentication Dial-In User Service (RADIUS)
B.Security Assertion Markup Language (SAML)
C.Kerberos
D.OAuth 2.0
AnswerD

OAuth 2.0 is an authorization framework that lets a resource owner grant a third-party application limited access to protected resources without sharing credentials. The budgeting app receives an access token scoped to reading transaction history, and the customer's banking password is never disclosed. This exactly matches the requirement for delegated, limited access to account data with user consent.

Why this answer

The scenario requires delegated authorization: a customer lets a third-party budgeting app read transaction history without revealing the banking password. OAuth 2.0 is built for this purpose, issuing scoped access tokens that the application presents to the resource server. The customer authenticates with the bank, approves specific scopes, and the app operates within those limits, so credentials are never shared and access can be revoked.

Exam trap

The trap here is confusing authentication with authorization and selecting SAML because it is a familiar federated identity standard, even though the requirement is delegated, scoped access rather than single sign-on.

685
MCQeasy

A security administrator is reviewing a vulnerability scan report and notices a finding labeled as a false positive. What is the most appropriate immediate action?

A.Apply the recommended patch immediately to resolve the finding.
B.Document the false positive and tune the scanner to reduce recurrence.
C.Ignore the finding because it is not a real vulnerability.
D.Escalate the finding to the incident response team as a potential breach.
AnswerB

When a vulnerability scan yields a false positive, the correct immediate step is to verify it, document the finding, and adjust scanner settings or exclusions to prevent similar false alerts. This maintains the integrity of the vulnerability management process and reduces wasted effort. Patching or ignoring without documentation would be inappropriate, making documentation and tuning the best course of action.

Why this answer

False positives in vulnerability scans should be verified, documented, and used to tune the scanner to reduce future occurrences. This ensures that the vulnerability management process remains efficient and credible. Applying patches unnecessarily, ignoring without documentation, or escalating to incident response are all incorrect because they either waste resources or fail to address the root cause of the false alert.

Exam trap

The trap here is treating a false positive as either a real vulnerability requiring patching or as something to ignore, rather than as a scanner accuracy issue to be documented and tuned.

686
Multi-Selecteasy

A company is adopting a role-based access control (RBAC) model. Which TWO principles are fundamental to RBAC?

Select 2 answers
A.Roles can be organized in a hierarchy to inherit permissions
B.Users are assigned to roles based on their job functions
C.Access is controlled by the data owner
D.Permissions are assigned directly to users
E.Access decisions are based on subject and object attributes
AnswersA, B

Role hierarchies let senior roles inherit permissions from junior ones, so a manager role automatically gains the permissions assigned to the employee role beneath it. This satisfies RBAC's structural requirement that permissions attach to roles rather than individual users, reducing administrative overhead when many users share common access needs.

Why this answer

Option A is correct because RBAC supports role hierarchies, where a senior role (e.g., Manager) inherits the permissions of a junior role (e.g., Employee), which is a core RBAC capability for structuring permissions efficiently. Option B is correct because the defining characteristic of RBAC is assigning users to roles according to their job functions or responsibilities, and permissions are then granted to those roles rather than to individual users. Option C is incorrect because control by the data owner describes discretionary access control (DAC), not RBAC.

Option D is incorrect because assigning permissions directly to users is the opposite of RBAC, which assigns permissions to roles. Option E is incorrect because access decisions based on subject and object attributes describe attribute-based access control (ABAC), not RBAC.

Exam trap

SSCP often tests the distinction between RBAC (job-function roles and hierarchy), DAC (owner-controlled), MAC (labels/clearances), and ABAC (attributes) — candidates who confuse role hierarchy with attribute-based rules pick E or C.

687
MCQhard

A financial institution uses a quantitative risk analysis to evaluate a new online payment system. The asset value is $5 million, the exposure factor is 40%, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?

A.$1,000,000
B.$800,000
C.$2,000,000
D.$2,500,000
AnswerA

Multiplying the asset value of $5 million by the 40% exposure factor gives a single loss expectancy of $2 million. Multiplying that by the 0.5 annualised rate of occurrence yields an annualised loss expectancy of $1,000,000, satisfying the quantitative risk analysis constraint in the stem.

Why this answer

The annualized loss expectancy (ALE) is calculated as single loss expectancy (SLE) multiplied by the annualized rate of occurrence (ARO). SLE is asset value ($5,000,000) times exposure factor (40%) = $2,000,000. Then ALE = $2,000,000 × 0.5 = $1,000,000.

This quantitative risk analysis formula is standard in financial risk assessments for payment systems.

Exam trap

ISC2 often tests the distinction between SLE and ALE, trapping candidates who stop after calculating SLE ($2,000,000) and forget to multiply by the ARO (0.5).

How to eliminate wrong answers

Option B ($800,000) is wrong because it incorrectly multiplies the asset value by the ARO without applying the exposure factor (i.e., $5,000,000 × 0.5 × 0.4? No, it's $5,000,000 × 0.4 × 0.5 = $1,000,000; $800,000 suggests a miscalculation like using 0.4 × 0.5 = 0.2 then $5,000,000 × 0.2 = $1,000,000? Actually $800,000 would come from $5,000,000 × 0.4 × 0.4 or similar error). Option C ($2,000,000) is wrong because it represents the SLE only (asset value × exposure factor) and fails to multiply by the ARO of 0.5. Option D ($2,500,000) is wrong because it incorrectly multiplies the asset value by the ARO only ($5,000,000 × 0.5) and ignores the exposure factor entirely.

688
MCQmedium

A company stores log files on a dedicated log server. To ensure log integrity, they implement a solution where logs are written to a WORM (Write Once, Read Many) device. Which property does this primarily protect?

A.Integrity
B.Non-repudiation
C.Availability
D.Confidentiality
AnswerA

WORM media prevent modification or deletion of records once written, so any tampering becomes evident. This directly upholds integrity, the property concerned with unauthorised alteration, rather than confidentiality or availability, satisfying the stem's requirement that stored log files remain trustworthy for forensic and compliance purposes.

Why this answer

WORM (Write Once, Read Many) technology ensures that once data is written, it cannot be altered, deleted, or overwritten. This directly protects the integrity of the log files by preventing any unauthorized or accidental modification, which is critical for maintaining a reliable audit trail.

Exam trap

Candidates often confuse integrity with non-repudiation, thinking that preventing modification also proves who wrote the data, but WORM alone does not provide proof of origin without additional authentication mechanisms.

How to eliminate wrong answers

Option B is wrong because non-repudiation is primarily about proving the origin of data (e.g., through digital signatures or PKI), not about preventing modification after writing. Option C is wrong because availability concerns ensuring data is accessible when needed, which WORM does not directly address (it may even hinder availability if the device fails). Option D is wrong because confidentiality involves preventing unauthorized access or disclosure, whereas WORM focuses on write protection, not read access controls.

689
Matchingmedium

Match each access control model to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Owner sets permissions

System-enforced labels

Roles determine access

Attributes and policies

Why these pairings

The four primary access control models are DAC (owner-determined), MAC (label-based), RBAC (role-based), and ABAC (attribute-based). Common confusions include mixing up DAC and MAC, or RBAC with DAC.

690
Multi-Selecthard

Which THREE of the following are security features of WPA3 compared to WPA2? (Select THREE)

Select 3 answers
A.Backward compatibility with WEP
B.Protected Management Frames (PMF) mandatory
C.192-bit security suite for Enterprise mode
D.Simultaneous Authentication of Equals (SAE) replaces PSK
E.Use of TKIP encryption
AnswersB, C, D

WPA3 makes Protected Management Frames mandatory, whereas WPA2 left PMF optional. PMF cryptographically protects management frames such as deauthentication and disassociation, preventing forgery and denial-of-service attacks. This mandatory enforcement is a specific WPA3 security improvement over WPA2 that the stem asks you to identify.

Why this answer

Option B is correct because WPA3 mandates Protected Management Frames (PMF, defined in 802.11w), which cryptographically protect management frames such as deauthentication and disassociation, preventing forgery and denial-of-service attacks that were possible under WPA2 where PMF was optional. Option C is correct because WPA3-Enterprise offers an optional 192-bit security suite aligned with CNSA guidance, using stronger cryptographic algorithms (GCMP-256, HMAC-SHA-384, ECDHE with a 384-bit curve) that WPA2-Enterprise did not provide. Option D is correct because WPA3 replaces the WPA2 Pre-Shared Key handshake with Simultaneous Authentication of Equals (SAE), a Dragonfly-based password-authenticated key exchange that provides forward secrecy and resists offline dictionary attacks against captured handshakes.

Option A is incorrect because WPA3 does not support backward compatibility with WEP, a deprecated and broken encryption protocol; WPA3 requires modern ciphers such as CCMP-128 or GCMP-256. Option E is incorrect because TKIP is a legacy, deprecated encryption protocol from WPA/WPA2 and is not used by WPA3, which relies on AES-based CCMP and GCMP instead.

Exam trap

SSCP often tests the confusion between WPA2 and WPA3 features; candidates may incorrectly select TKIP or WEP compatibility because they associate older encryption with broader compatibility, but WPA3 explicitly drops these legacy protocols.

691
Multi-Selectmedium

A company is migrating from WPA2 to WPA3 for wireless security. Which THREE features does WPA3 introduce? (Select three)

Select 3 answers
A.192-bit security suite for Enterprise networks
B.Wi-Fi Protected Setup (WPS)
C.Simultaneous Authentication of Equals (SAE)
D.Protected Management Frames (PMF) mandatory
E.CCMP encryption as mandatory
AnswersA, C, D

WPA3-Enterprise adds an optional 192-bit cryptographic suite aligned with CNSA guidance, using stronger AES-GCM-256 and SHA-384 within EAP-TLS negotiations. This satisfies the stem's requirement for a genuinely new WPA3 feature, unlike WPA2's 128-bit-only Enterprise mode. Simultaneous Authentication of Equals and protected management frames are separate additions.

Why this answer

WPA3 introduces the 192-bit security suite for Enterprise networks (option A), which is based on CNSA Suite algorithms and provides stronger cryptographic protection for government, defense, and high-security enterprise environments. Simultaneous Authentication of Equals (SAE) (option C) is the new WPA3-Personal handshake that replaces WPA2's PSK method, providing forward secrecy and resistance to offline dictionary attacks. Protected Management Frames (PMF) mandatory (option D) is correct because WPA3 requires PMF (802.11w) to protect management frames from forging and eavesdropping attacks, whereas it was optional in WPA2.

Wi-Fi Protected Setup (WPS) (option B) is not a WPA3-introduced feature; it predates WPA3 and is actually discouraged due to security weaknesses. CCMP encryption as mandatory (option E) is incorrect because CCMP is the WPA2 mandatory cipher, while WPA3-Personal still uses CCMP-128 but also introduces GCMP-256 in the 192-bit suite, so CCMP being 'mandatory' is not a new WPA3 feature.

Exam trap

SSCP often tests the distinction between features that are new in WPA3 versus those that were already present or optional in WPA2, such as CCMP and WPS, causing candidates to incorrectly select them as WPA3 introductions.

692
MCQeasy

An administrator wants to ensure that users cannot share passwords. Which control is most effective at reducing the risk of password sharing?

A.Account lockout policies
B.Multifactor authentication
C.Password complexity
D.Password history
AnswerB

Multifactor authentication reduces password sharing because a stolen or shared password alone no longer grants access; the second factor, such as a push notification or FIDO2 key, stays bound to the legitimate user's device. This directly satisfies the stem's constraint of preventing users from sharing credentials successfully.

Why this answer

Multifactor authentication (MFA) is the most effective control because it requires users to present two or more distinct factors (e.g., something you know, something you have, something you are) to authenticate. Even if a user shares their password (something you know), an attacker cannot authenticate without the second factor (e.g., a one-time passcode from a hardware token or biometric). This directly reduces the risk of password sharing by making the shared credential insufficient for access.

Exam trap

The trap here is that candidates often choose password complexity or account lockout policies because they associate them with 'stronger security,' but they fail to recognize that these controls do not address the specific threat of voluntary password sharing, which MFA directly mitigates by adding an independent authentication factor.

How to eliminate wrong answers

Option A is wrong because account lockout policies (e.g., locking after 5 failed attempts) are designed to prevent brute-force attacks, not to prevent users from voluntarily sharing their passwords; a shared password still works until the account is locked. Option C is wrong because password complexity (e.g., requiring uppercase, numbers, symbols) only makes passwords harder to guess or crack, but does nothing to stop a user from sharing that complex password with another person. Option D is wrong because password history (e.g., remembering the last 10 passwords) prevents users from reusing old passwords, but it has no effect on sharing the current password with others.

693
MCQeasy

A risk analyst is documenting threats for a new cloud-hosted application. The analyst must classify threat sources. Which of the following is an example of an environmental threat source rather than a human threat source?

A.A flood that damages the regional data center hosting the application.
B.A software bug in a third-party library used by the application.
C.A disgruntled administrator with privileged access to the application database.
D.An organized criminal group targeting the application for ransomware.
AnswerA

Floods, fires, earthquakes, and similar natural events are environmental threat sources because they originate from physical surroundings rather than from people or technology. Classifying them correctly matters because environmental risks are typically addressed with geographic redundancy, backup sites, and facility controls, not with access management or patching. This distinction drives which controls a risk treatment plan selects.

Why this answer

Threat sources are grouped into human, technical, and environmental categories. A flood is a classic environmental source because it stems from natural conditions rather than from a person or a code defect. Correct classification guides the risk response: environmental threats call for geographic redundancy, resilient facilities, and continuity planning, while human and technical sources call for access controls, monitoring, and remediation of flaws.

Exam trap

The trap here is confusing a technical flaw such as a vulnerable library with an environmental threat source, when each category drives a different set of controls.

694
MCQmedium

A company uses multiple virtual machines on a single hypervisor. To prevent a VM from escaping its virtualized environment and compromising the hypervisor, which of the following should be implemented?

A.Use a separate network for VM management traffic
B.Apply hypervisor security patches and disable unnecessary VM guest tools
C.Deploy a host-based firewall on each VM
D.Enable VM snapshots to restore in case of compromise
AnswerB

Patching the hypervisor closes known privilege-escalation vulnerabilities that permit VM escape, while removing unnecessary guest tools shrinks the guest-to-host attack surface, such as shared folders and clipboard channels. Together these directly satisfy the stem's requirement to stop a VM compromising the hypervisor.

Why this answer

The correct answer is B because VM escape attacks typically exploit vulnerabilities in the hypervisor itself or in the guest tools (like VMware Tools or VirtualBox Guest Additions) that run with elevated privileges. Applying hypervisor security patches closes known vulnerabilities that could allow a VM to break out, while disabling unnecessary guest tools reduces the attack surface that an attacker could leverage to interact with the hypervisor. Together, these measures directly harden the virtualization layer against escape attempts.

Exam trap

The trap here is confusing network segmentation or host-based firewalls with hypervisor-level security; candidates often pick option A or C because they think isolating management traffic or adding a firewall prevents escape, but the question specifically asks about preventing a VM from escaping its virtualized environment, which requires securing the hypervisor and guest tools.

How to eliminate wrong answers

Option A is wrong because a separate network for management traffic only isolates administrative access; it does not prevent a compromised VM from exploiting hypervisor vulnerabilities to escape. Option C is wrong because a host-based firewall on each VM filters network traffic but cannot stop a VM from exploiting a hypervisor bug or misconfigured guest tools to break isolation. Option D is wrong because snapshots are for recovery and rollback, not prevention; they do nothing to stop a VM escape and may even introduce additional attack surface if snapshot files are not secured.

695
MCQmedium

A new employee needs access to the CRM, email, and file servers. The security policy requires that access privileges are granted based on job function. Which process should be used?

A.The employee completes a request form detailing the access they need
B.The IT department grants full access to all systems and later reviews
C.The identity management team assigns the employee to a role that includes the necessary permissions
D.The employee's supervisor decides which access is appropriate and informs IT
AnswerC

Role-based access control assigns permissions to a role matching the job function, and the employee inherits exactly those rights. This satisfies the policy requiring access based on job function, rather than granting individual discretionary permissions per resource.

Why this answer

Role-based access control (RBAC) assigns permissions based on job functions, not individual requests or ad-hoc approvals. By placing the employee into a predefined role (e.g., 'Sales Rep'), the identity management team ensures that the CRM, email, and file server permissions are granted consistently and in compliance with the security policy. This process enforces the principle of least privilege and simplifies auditing.

Exam trap

The trap here is that candidates often choose the supervisor's approval (Option D) because it seems logical, but the SSCP exam emphasizes automated role-based assignment over manual approval to enforce consistent, policy-driven access control.

How to eliminate wrong answers

Option A is wrong because allowing the employee to self-select access needs violates the principle of least privilege and bypasses the job-function-based policy; it introduces risk of over-provisioning. Option B is wrong because granting full access upfront and reviewing later is a 'trust but verify' model that contradicts the security policy's requirement to grant access based on job function, and it creates a window of excessive privilege. Option D is wrong because while the supervisor may understand the role, the decision should be automated through role assignment rather than relying on a manual, subjective decision that could lead to inconsistent or excessive permissions.

696
MCQeasy

A healthcare provider must ensure that stored patient records remain unreadable if an attacker steals the physical disk from a database server. The server runs a mainstream Linux distribution and the requirement applies to the entire volume, not just individual files. Which control best meets this requirement?

A.Full disk encryption with LUKS on the data volume
B.Enforcing strict file permissions on the data directory
C.Enabling SELinux in enforcing mode on the server
D.Per-file encryption performed by the database engine
AnswerA

LUKS encrypts the block device itself, so every sector written to the volume is ciphertext while at rest. If the disk is removed and mounted elsewhere, the data is unreadable without the passphrase or key file. This satisfies whole-volume confidentiality for a stolen physical disk.

Why this answer

Whole-volume encryption converts all data on the block device into ciphertext at rest and requires a key to mount it. When the disk is stolen, the ciphertext is useless without that key, which directly satisfies the requirement to keep records unreadable after physical theft.

Exam trap

The trap here is confusing access control mechanisms like file permissions or SELinux with data-at-rest encryption, which are different layers solving different threats.

697
MCQmedium

An organization's disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour for its critical database. Which of the following DR site configurations BEST meets these requirements?

A.Cold site with weekly backup tapes shipped offsite
B.Cloud-based cold site with daily backups
C.Hot site with synchronous replication
D.Warm site with hourly log shipping to a standby database
AnswerD

Hourly log shipping to a standby database delivers an RPO of roughly one hour, and a warm site can be brought online within the four-hour RTO. Hot sites exceed the requirement at unnecessary cost, while cold sites cannot meet either target.

Why this answer

A warm site with hourly log shipping to a standby database can achieve an RPO of 1 hour (by losing at most one hour of transactions) and an RTO of 4 hours (by applying the logs and bringing the standby online within that window). The standby database is kept nearly current with minimal lag, meeting both recovery objectives without the cost of full synchronous replication.

Exam trap

The trap here is that candidates often choose a hot site (Option C) because it provides the best protection, but the question asks for the configuration that BEST meets the specified RTO/RPO, not the most robust or expensive option, making the warm site the most cost-effective and appropriate choice.

How to eliminate wrong answers

Option A is wrong because a cold site requires hardware setup and restoration from weekly backup tapes, which cannot meet a 4-hour RTO (setup alone often takes days) and the weekly backups exceed the 1-hour RPO (potential data loss of up to a week). Option B is wrong because a cloud-based cold site still requires provisioning resources and restoring from daily backups, which cannot achieve a 4-hour RTO (provisioning and restoration take longer) and the daily backups exceed the 1-hour RPO (potential data loss of up to 24 hours). Option C is wrong because a hot site with synchronous replication provides near-zero RPO and very low RTO (minutes), which over-delivers on the requirements and is unnecessarily expensive; the question asks for the configuration that BEST meets the stated RTO/RPO, not exceeds them with higher cost.

698
MCQeasy

During an incident, the IR team needs to collect volatile data. Which order should they follow?

A.Hard disk, memory, network connections, running processes
B.Network connections, running processes, memory, hard disk
C.Running processes, memory, network connections, hard disk
D.Memory, running processes, network connections, hard disk
AnswerD

Volatile data disappears on power loss or reboot, so it must be captured in order of volatility: memory first, then running processes, then network connections, and finally the hard disk. This sequence preserves the most perishable evidence before it is lost.

Why this answer

Volatile data must be collected in order of decreasing volatility to minimize data loss. Memory (RAM) is the most volatile, followed by running processes, network connections, and finally the hard disk, which is non-volatile. This order ensures that transient evidence (e.g., encryption keys, active network sessions) is captured before it disappears.

Exam trap

ISC2 often tests the order of volatility (OOV) principle, and the trap here is that candidates mistakenly think running processes are more volatile than memory, or they confuse the order by prioritizing network connections over process state.

How to eliminate wrong answers

Option A is wrong because it starts with the hard disk, which is non-volatile, and delays collection of memory and network connections, risking loss of critical transient data. Option B is wrong because it places network connections before running processes and memory, but network connections depend on process state and can change rapidly; memory should be captured first to preserve process artifacts. Option C is wrong because it lists running processes before memory, but memory contains the actual process data (e.g., code, variables) that must be captured before processes are terminated or altered.

699
MCQmedium

A Linux system administrator needs to restrict network traffic to a server, allowing only HTTP and HTTPS from the internet. Which tool should be used to configure packet filtering rules?

A.PAM
B.SELinux
C.auditd
D.iptables
AnswerD

iptables is the Linux kernel's packet-filtering framework, configuring rules in the filter table to accept TCP ports 80 and 443 and drop other inbound traffic. It directly satisfies the requirement to restrict network traffic at the host level.

Why this answer

iptables is the standard Linux user-space utility for configuring the kernel's Netfilter packet filtering rules, including allowing only HTTP (TCP 80) and HTTPS (TCP 443) from the internet. It operates at the network layer and is the correct tool for host-based firewall configuration on Linux.

Exam trap

SSCP often tests tool-to-function mapping — candidates confuse security frameworks like SELinux or auditing tools like auditd with packet filtering tools.

How to eliminate wrong answers

Option A is wrong because PAM (Pluggable Authentication Modules) handles authentication and session management, not packet filtering. Option B is wrong because SELinux is a mandatory access control framework that confines processes and files, not a network packet filter. Option C is wrong because auditd is the Linux auditing daemon that logs system events for compliance and forensics, not a firewall tool.

700
MCQeasy

Which of the following is a secure protocol for remote administration of a server, replacing insecure protocols like Telnet?

A.FTP
B.SSH
C.HTTP
D.Telnet
AnswerB

SSH encrypts the entire session, including authentication credentials and commands, over TCP port 22. Telnet transmits everything in cleartext, exposing passwords to sniffing. SSH's host key verification and encrypted channel satisfy the requirement for secure remote administration.

Why this answer

SSH (Secure Shell) is the correct answer because it provides encrypted remote administration capabilities, replacing insecure protocols like Telnet that transmit data in plaintext. SSH uses public-key cryptography for authentication and symmetric encryption (e.g., AES, ChaCha20) for session confidentiality, protecting against eavesdropping and man-in-the-middle attacks.

Exam trap

The trap here is that candidates may confuse Telnet with SSH or think that FTP or HTTP can be used for remote administration, but the question specifically asks for a secure replacement for Telnet, which is SSH.

How to eliminate wrong answers

Option A (FTP) is wrong because it is a file transfer protocol, not a remote administration protocol, and it transmits credentials and data in plaintext unless secured with FTPS or SFTP. Option C (HTTP) is wrong because it is a web protocol used for transferring hypertext, not for remote server administration, and it lacks encryption by default (HTTPS is the secure variant). Option D (Telnet) is wrong because it is the very insecure protocol that SSH replaces, sending all data including passwords in cleartext over TCP port 23.

701
Multi-Selecteasy

During the containment phase of incident response, a security analyst identifies malware on a critical server. Which TWO actions should be taken FIRST to contain the threat and preserve evidence? (Choose two.)

Select 2 answers
A.Capture a forensic image of the hard drive.
B.Reboot the server to clear the malware from memory.
C.Disconnect the network cable from the server.
D.Run a full antivirus scan on the server.
E.Capture the contents of RAM using a tool like WinPmem.
AnswersC, E

Disconnecting the network cable immediately severs the malware's command-and-control channel and lateral movement paths, satisfying the containment requirement. Unlike powering down, it preserves volatile memory and running processes, so forensic evidence such as RAM artefacts survives for later analysis. This makes it the fastest physical isolation method for a critical server.

Why this answer

Option C is correct because physically disconnecting the network cable from the server immediately isolates the host, preventing lateral movement, command-and-control callbacks, and data exfiltration while the incident is being contained. Option E is correct because capturing RAM with a tool like WinPmem preserves volatile evidence such as running processes, network connections, injected code, and encryption keys that would be lost on shutdown or reboot, and it should be done before any power state change. Option A is not among the first actions because a full forensic disk image is time-consuming and is typically acquired after volatile memory is preserved and the host is isolated.

Option B is wrong because rebooting destroys volatile memory evidence and may allow malware to re-infect the system or trigger destructive payloads. Option D is wrong because running a full antivirus scan alters system state, can quarantine or delete files, and does not isolate the server from the network, thereby contaminating evidence and leaving the threat active.

Exam trap

SSCP often tests the order of volatility and the containment-vs-eradication distinction; candidates who choose reboot or antivirus scan first confuse eradication/remediation with containment and destroy evidence.

702
Multi-Selectmedium

A security analyst is investigating a network incident. Which TWO of the following are indicators of a man-in-the-middle attack using ARP spoofing? (Select TWO)

Select 2 answers
A.High number of TCP retransmissions from a single host.
B.An ARP entry for the default gateway points to an unknown MAC address.
C.The ARP cache shows two different MAC addresses for the same IP address (e.g., gateway IP).
D.The switch's CAM table has multiple MAC entries on the same port.
E.Multiple IP addresses resolve to the same MAC address in the ARP cache.
AnswersB, C

ARP spoofing poisons the victim's cache so the gateway's IP resolves to the attacker's MAC. A gateway ARP entry mapping to an unknown MAC therefore directly evidences cache poisoning, satisfying the man-in-the-middle indicator requirement in the stem.

Why this answer

Option B is correct because in ARP spoofing the attacker sends forged ARP replies claiming the gateway's IP, so the victim's ARP entry for the default gateway resolves to the attacker's (unknown/unexpected) MAC address instead of the legitimate router MAC. Option C is correct because duplicate/conflicting ARP entries—two different MAC addresses bound to the same IP such as the gateway IP—are a classic sign of ARP cache poisoning, where the attacker's reply overwrites or races with the legitimate mapping. Option A is not specific to ARP spoofing, since TCP retransmissions can result from many causes (congestion, packet loss, duplex mismatch) and are only a generic symptom.

Option D describes MAC flooding against a switch CAM table, not ARP spoofing. Option E (multiple IPs mapping to one MAC) is typical of NAT, proxy ARP, or a router interface, not an ARP spoofing indicator.

Exam trap

The trap is selecting generic network symptoms (retransmissions, CAM table anomalies) as ARP-spoofing indicators instead of the specific ARP cache anomalies — a gateway IP mapped to an unknown MAC or duplicate MACs for one IP — that directly evidence ARP poisoning.

703
MCQeasy

A web application is vulnerable to SQL injection. Which security control would be MOST effective at detecting and blocking such attacks at the network perimeter?

A.Intrusion Detection System (IDS)
B.Web Application Firewall (WAF)
C.Application whitelisting
D.Host-based firewall
AnswerB

A Web Application Firewall inspects HTTP traffic at the network perimeter, matching request patterns against signatures for SQL injection and blocking malicious payloads before they reach the application, satisfying the requirement to detect and block attacks at the perimeter.

Why this answer

A Web Application Firewall (WAF) inspects HTTP/HTTPS traffic at the application layer and can detect and block SQL injection patterns using signature-based and anomaly-based rules (e.g., OWASP Core Rule Set). It sits at the network perimeter in front of the web application, making it the most effective control for this requirement.

Exam trap

SSCP often tests the distinction between detection and prevention — candidates may pick IDS because it 'detects' SQL injection, but the question asks for a control that both detects and blocks at the perimeter, which only a WAF does.

How to eliminate wrong answers

Option A is wrong because an IDS only detects and alerts on suspicious traffic — it does not block attacks, and it is not specifically tuned to parse HTTP payloads for SQL injection signatures. Option C is wrong because application whitelisting controls which executables can run on a host, not which HTTP requests reach a web application. Option D is wrong because a host-based firewall filters traffic by IP, port, and protocol — it cannot inspect HTTP payloads for SQL injection strings.

704
MCQmedium

Which UDP port is used by the Simple Network Management Protocol (SNMP) for receiving traps?

A.UDP 161
B.UDP 162
C.UDP 123
D.UDP 514
AnswerB

SNMP traps are asynchronous notifications sent by agents to a manager, and they arrive on UDP port 162 rather than the polling port 161. This separation lets the manager listen for unsolicited alerts on 162 while still issuing requests to agents on 161, satisfying the stem's requirement for the trap-receiving port.

Why this answer

SNMP agents listen for requests on UDP port 161, but SNMP traps (and inform requests) are sent by the agent to the manager on UDP port 162. The manager must listen on UDP 162 to receive unsolicited notifications. This separation of ports lets the manager distinguish inbound trap traffic from its own outbound polling.

Exam trap

The trap is mixing up the agent's polling port (UDP 161) with the manager's trap-receiving port (UDP 162); candidates often assume traps use the same port as requests.

How to eliminate wrong answers

Option A is wrong because UDP 161 is the port on which the SNMP agent listens for GET, GETNEXT, GETBULK, and SET requests from the manager, not the trap-receiving port. Option C is wrong because UDP 123 is used by NTP for time synchronization, unrelated to SNMP. Option D is wrong because UDP 514 is used by syslog (and historically rsh), not SNMP traps.

705
MCQmedium

A financial services firm needs to detect unauthorized changes to its public DNS records that could redirect customers to a phishing site. The security team wants a control that validates DNS responses cryptographically so that a resolver can verify the data originated from the authoritative zone. Which technology should they implement?

A.DNS over HTTPS (DoH)
B.DNSSEC (Domain Name System Security Extensions)
C.DNS sinkholing
D.Split-horizon DNS
AnswerB

DNSSEC adds digital signatures to DNS records so a validating resolver can confirm that the data came from the authoritative zone and was not altered in transit. It directly addresses cache poisoning and record tampering by using a chain of trust from the root down to the zone. This matches the requirement for cryptographic validation of DNS responses.

Why this answer

DNSSEC is the only listed control that signs DNS records and lets a validating resolver verify their origin and integrity through a chain of trust. Encryption options such as DoH protect the query path but not the data's authenticity, while sinkholing and split-horizon DNS address different problems. For detecting tampering with public records, DNSSEC provides the required cryptographic assurance.

Exam trap

The trap here is confusing encryption of DNS traffic with authentication of DNS data, so a privacy feature like DoH is mistaken for an integrity control.

706
Multi-Selecthard

A security team is reviewing how their organization's DNS infrastructure could be abused. They want to reduce the risk of DNS cache poisoning and of data being smuggled out of the network through DNS queries. Which two measures best address these risks? (Choose two.)

Select 2 answers
A.Increase the default TTL on all internal DNS records so that cached entries remain valid longer
B.Deploy DNSSEC validation on the recursive resolvers so that responses can be cryptographically verified against the authoritative zone
C.Enable EDNS0 Client Subnet on the authoritative servers to return geographically accurate answers
D.Force all internal clients to use only the organization's internal recursive resolvers and block outbound DNS to external resolvers at the perimeter
E.Configure the internal resolvers to forward all queries to a public open resolver such as a large third-party service
AnswersB, D

DNSSEC adds digital signatures to DNS records, allowing a validating resolver to prove that a response genuinely came from the authoritative zone and was not altered in transit. This directly mitigates cache poisoning, because a forged or injected answer fails signature validation and is discarded rather than cached and served to internal clients. It does not by itself stop tunneling, but it is a core control for answer integrity.

Why this answer

DNSSEC validation gives resolvers cryptographic proof that answers are authentic, which neutralizes forged responses used in cache poisoning. Constraining clients to internal resolvers and blocking outbound DNS to arbitrary servers keeps all resolution inside a monitored path, enabling detection of tunneling and preventing bypass of the validating resolver. Together they cover both integrity of answers and visibility into query behavior.

Exam trap

The trap here is treating DNS performance or privacy features such as EDNS Client Subnet as security controls, when they do not authenticate answers or expose covert channels.

707
MCQmedium

A company is implementing a biometric authentication system for physical access to a data center. The system must minimize false acceptances. Which metric is most directly related to false acceptance rate (FAR)?

A.Crossover error rate (CER)
B.Equal error rate (EER)
C.False rejection rate (FRR)
D.Threshold setting
AnswerD

The threshold determines how closely a biometric sample must match the stored template; a stricter threshold lowers FAR.

Why this answer

FAR is the rate at which an unauthorized person is incorrectly accepted. The threshold setting directly impacts FAR; a higher (more stringent) threshold reduces FAR but may increase FRR.

708
MCQhard

An organization uses User Behavior Analytics (UBA) to detect insider threats. Which of the following activities would most likely trigger an alert for a compromised account?

A.User receives a large number of emails
B.User logs in from a recognized corporate device
C.User attempts to access a database at 2:00 AM, which is outside their normal pattern
D.User accesses the same files as usual during business hours
AnswerC

UBA baselines each user's normal behaviour, so a 2:00 AM database access falling outside that learned pattern deviates from the established profile. This temporal anomaly is exactly the behavioural signal UBA is designed to flag for a potentially compromised account.

Why this answer

User Behavior Analytics (UBA) establishes a baseline of normal user activity, including typical login times, locations, and access patterns. An attempt to access a database at 2:00 AM, which falls outside the user's established temporal baseline, represents a significant deviation that UBA algorithms flag as anomalous. This behavior is a classic indicator of a compromised account, as attackers often operate during off-hours to avoid detection.

Exam trap

The trap here is that candidates may confuse 'anomalous behavior' with 'malicious behavior,' but UBA specifically flags deviations from a baseline, and off-hours access is a textbook anomaly for a compromised account, whereas the other options represent normal or expected activities.

How to eliminate wrong answers

Option A is wrong because receiving a large number of emails is a common occurrence and does not inherently indicate compromise; UBA focuses on deviations in access and authentication patterns, not email volume. Option B is wrong because logging in from a recognized corporate device is expected behavior and aligns with the user's baseline, thus it would not trigger an alert for a compromised account. Option D is wrong because accessing the same files as usual during business hours is consistent with the user's normal pattern and would be considered low-risk, not indicative of compromise.

709
MCQhard

A healthcare organization is deploying a containerized patient records application on Kubernetes. The security team wants to prevent a compromised container from accessing the underlying node's filesystem and from escalating privileges. Which Kubernetes control should be configured to restrict the container's capabilities and prevent privilege escalation?

A.Configure a resource quota that limits CPU and memory for the pod.
B.Enable PodSecurityPolicy with the privileged profile applied to the namespace.
C.Set the pod's securityContext to allowPrivilegeEscalation: false and drop all Linux capabilities.
D.Configure a NetworkPolicy that denies all ingress and egress traffic to the pod.
AnswerC

The securityContext fields allowPrivilegeEscalation and capabilities directly control whether a process can gain more privileges than its parent and which Linux capabilities are available. Setting allowPrivilegeEscalation to false blocks setuid and similar escalation paths, while dropping capabilities removes the ability to perform privileged operations such as mounting filesystems or modifying kernel parameters. This precisely mitigates the described risk.

Why this answer

Restricting a container's privileges requires configuring its securityContext to prevent privilege escalation and to drop unnecessary Linux capabilities. These settings directly limit what the container process can do on the host, including mounting filesystems or using privileged system calls. Network policies, privileged pod security profiles, and resource quotas address different concerns and do not prevent host filesystem access or privilege escalation.

Exam trap

The trap here is confusing network isolation or resource limits with process-level privilege restriction, when only securityContext capability and privilege escalation settings control what the container process can do on the host.

710
MCQmedium

A security analyst receives a user report about a workstation exhibiting unusual behavior, such as unexpected pop-ups and slow performance. The analyst first checks the antivirus logs and finds no alerts. What is the NEXT step in the detection and analysis phase?

A.Escalate the incident to senior management
B.Isolate the workstation from the network immediately
C.Perform a forensic memory capture
D.Classify the severity of the potential incident
AnswerD

With antivirus logs clear, the analyst must still triage the report; classifying severity determines whether it becomes a formal incident and drives escalation and resourcing, which is the next detection-and-analysis action before containment or eradication.

Why this answer

In the detection and analysis phase of incident response, after initial validation and checking antivirus logs, the analyst must classify the severity of the potential incident to determine the appropriate response level and prioritization. Classification guides whether the incident warrants escalation, isolation, or deeper forensic investigation. This step aligns with NIST SP 800-61 and SSCP incident handling principles.

Exam trap

The trap is jumping to containment (isolating the workstation) or escalation because those feel urgent; the exam tests whether you follow the correct sequence where severity classification precedes containment and escalation in the detection and analysis phase.

How to eliminate wrong answers

Option A is wrong because escalating to senior management is premature before the incident has been classified and validated; escalation follows severity determination. Option B is wrong because isolating the workstation is a containment action that belongs to the containment phase, not the detection and analysis phase, and should occur after severity classification. Option C is wrong because performing a forensic memory capture is a detailed investigative step that comes after the incident has been classified and prioritized, not as the immediate next step.

711
MCQeasy

A small business owner wants to implement access control for a shared file server. The owner wants each department manager to be able to decide which of their employees can access specific folders, without involving the IT department for every change. Which access control model is most appropriate for this requirement?

A.Mandatory access control (MAC)
B.Attribute-based access control (ABAC)
C.Discretionary access control (DAC)
D.Role-based access control (RBAC)
AnswerC

DAC allows resource owners to set permissions at their discretion, enabling department managers to control access to their folders without IT intervention. This matches the small business owner's requirement for delegated, flexible access control. DAC is simple to implement and commonly used in file systems, making it the most appropriate model here.

Why this answer

Discretionary access control (DAC) lets resource owners decide who can access their resources, which directly supports the requirement for department managers to control access to their folders without IT involvement. MAC, RBAC, and ABAC are more centralized or policy-driven and do not offer this level of delegated, owner-controlled discretion.

Exam trap

The trap here is assuming that any model allowing managers some control is DAC, when in fact only DAC gives resource owners full discretion to set permissions on their own resources.

712
MCQmedium

A security administrator is implementing a security awareness training program. The administrator wants to measure the effectiveness of the training in reducing phishing susceptibility. Which of the following metrics would be MOST indicative of the training's success?

A.The total number of phishing emails blocked by the email gateway.
B.The average time taken by employees to complete the training module.
C.The number of phishing emails reported by employees during simulated campaigns.
D.The percentage of employees who completed the training module.
AnswerC

The number of phishing emails reported by employees during simulations directly measures their ability to recognize and respond to phishing attempts. An increase in reporting indicates improved awareness and vigilance. This metric reflects behavioral change, which is the ultimate goal of security awareness training. It is a strong indicator of the training's effectiveness in reducing susceptibility.

Why this answer

To measure the effectiveness of phishing awareness training, the best metric is behavioral. The number of phishing emails reported during simulations shows whether employees are applying what they learned. Completion rate, gateway blocks, and training time do not directly measure reduced susceptibility.

Therefore, reported phishing emails is the most indicative metric.

Exam trap

The trap here is equating training completion or technical blocks with behavioral change, when the real measure of effectiveness is how employees act when faced with a phishing attempt.

713
Multi-Selecthard

Which THREE of the following are common methods for implementing multifactor authentication (MFA)?

Select 3 answers
A.Retina scan and facial recognition
B.Password and SMS code
C.Smart card and PIN
D.Password and security question
E.Fingerprint and smart card
AnswersB, C, E

Combining a password (knowledge factor) with an SMS code (possession factor) satisfies the stem's requirement for a common MFA method, since it draws on two distinct authentication categories. SMS delivery to a registered mobile number is widely deployed, though vulnerable to SIM-swapping and interception, which is why Microsoft Entra ID now favours stronger possession factors.

Why this answer

Option B (Password and SMS code) is correct because it combines something you know (a password) with something you have (a one-time code delivered to your registered phone), which are two distinct authentication factors. Option C (Smart card and PIN) is correct because it pairs something you have (the smart card) with something you know (the PIN), satisfying MFA's requirement for different factor types. Option E (Fingerprint and smart card) is correct because it combines something you are (a biometric fingerprint) with something you have (the smart card), again using two separate factor categories.

Option A is not correct because a retina scan and facial recognition are both inherence (biometric) factors, so they represent the same factor type rather than multifactor authentication. Option D is not correct because a password and a security question are both knowledge-based factors, so they do not constitute true MFA.

Exam trap

ISC2 often tests the distinction between using multiple instances of the same factor (e.g., two biometrics or two passwords) versus using factors from different categories, which is the core requirement for true MFA.

714
MCQmedium

During a full interruption test of the disaster recovery plan, which of the following is the PRIMARY risk?

A.Vendor unavailability during the test
B.Employee confusion about their roles
C.Extended downtime or data loss if the plan fails
D.Cost overruns due to overtime pay
AnswerC

A full interruption test actually shuts down production systems and invokes recovery, so if the plan proves flawed, the organisation suffers real extended downtime or data loss. This is the primary risk that distinguishes it from tabletop or simulation testing.

Why this answer

A full interruption test simulates a complete disaster by actually shutting down the primary site and failing over to the recovery site. The primary risk is that if the recovery plan fails, the organization may experience extended downtime or data loss because the production environment is already down and cannot be quickly restored. This directly impacts business continuity and is the most severe consequence.

Exam trap

SSCP often tests the distinction between the primary risk of a full interruption test (extended downtime/data loss) and secondary risks like cost or employee confusion, which are less critical.

How to eliminate wrong answers

Option A is wrong because vendor unavailability is a secondary concern; while it could hinder the test, it does not directly cause downtime or data loss. Option B is wrong because employee confusion about roles is a people/process risk that can be mitigated with training and documentation, but it is not the primary risk of a full interruption test. Option D is wrong because cost overruns due to overtime pay are a financial concern, not the primary operational risk of extended downtime or data loss.

715
MCQeasy

A security administrator is tasked with implementing a defense-in-depth strategy for the organization's data center. The administrator wants to ensure that physical access to servers is restricted to authorized personnel only. Which of the following controls should be implemented to achieve this?

A.Install security cameras throughout the data center.
B.Deploy a mantrap at the entrance to the data center.
C.Use raised flooring to protect cabling and improve airflow.
D.Implement biometric authentication for server logins.
AnswerB

A mantrap is a physical security control that consists of a small space with two interlocking doors. It allows only one person to enter at a time and can detect tailgating. By requiring authentication at both doors, it ensures that only authorized personnel can access the data center. This directly restricts physical access to authorized individuals and is a strong preventive control.

Why this answer

To restrict physical access to authorized personnel, a preventive physical control is needed. A mantrap enforces one-person-at-a-time entry and prevents tailgating, directly restricting access. Cameras are detective, biometric server logins are logical, and raised flooring is infrastructural.

Therefore, the mantrap is the correct choice.

Exam trap

The trap here is confusing detective controls like cameras with preventive controls, or logical controls with physical ones, when the requirement is specifically for physical access restriction.

716
MCQeasy

A security administrator needs to verify the integrity and authenticity of a downloaded software package. The vendor provides a separate file containing a cryptographic hash of the package, but the hash file itself is not signed. Which action BEST mitigates the risk of a modified package being accepted?

A.Compare the provided hash with a hash computed locally using the same algorithm.
B.Decrypt the package using the vendor's public key before hashing it.
C.Recompute the hash using a different algorithm and compare it to the vendor's hash.
D.Obtain the hash value from a trusted, independent source and compare it to a locally computed hash.
AnswerD

Integrity verification requires a trusted reference. By retrieving the hash from an independent, authenticated channel, the administrator can detect whether the package or the accompanying hash file was altered. A locally computed hash of the downloaded package compared against that trusted value provides assurance of integrity and authenticity, which the unsigned hash file alone cannot.

Why this answer

Hashes alone provide integrity only when the reference value is trusted. Since the provided hash file is unsigned and could be altered alongside the package, the administrator must obtain the expected hash through an independent, authenticated channel. Comparing a locally computed hash against that trusted value detects tampering, whereas using the untrusted file or changing algorithms does not.

Exam trap

The trap here is treating any hash comparison as sufficient for integrity, overlooking that the hash itself must come from a trusted source to provide assurance.

717
MCQhard

A financial services firm operates a Security Operations Center that ingests NetFlow records, firewall logs, and endpoint telemetry into a SIEM. An analyst wants to reduce alert fatigue while still surfacing high-fidelity detections. Which approach best supports this goal?

A.Tune correlation rules with asset context and threat intelligence, and implement risk-based alert scoring to prioritize detections
B.Increase the severity rating of every rule so that analysts prioritize all alerts equally
C.Route all alerts to a shared mailbox and require analysts to review them only during weekly meetings
D.Disable all correlation rules that generate more than ten alerts per day and rely solely on raw log review
AnswerA

Combining asset criticality, threat intelligence, and risk-based scoring lets the SIEM rank alerts by actual business risk rather than raw event volume. Rules can be tuned to suppress known-good activity, while enrichment highlights activity tied to critical systems or active threat campaigns. This preserves detection coverage and directs analyst attention to the alerts most likely to represent real incidents, directly reducing fatigue without weakening monitoring.

Why this answer

Alert fatigue is reduced by improving the quality and context of detections, not by removing or delaying them. Enriching correlation rules with asset criticality and threat intelligence, then scoring alerts by risk, lets analysts focus on events that matter to the business. This maintains coverage while cutting noise, which is the core objective of a mature monitoring program.

Exam trap

The trap here is assuming that fewer alerts always means better monitoring, when the real goal is higher-fidelity alerts prioritized by risk.

718
MCQmedium

You work for a hospital that has recently transitioned to an electronic health record (EHR) system. The system stores protected health information (PHI) and must comply with HIPAA. The hospital's security policy requires that all access to PHI be logged and that any unauthorized access be detected promptly. The IT department has implemented logging on the EHR system, but the security team is overwhelmed by the volume of logs and cannot review them in a timely manner. Additionally, there have been incidents where employees accessed patient records without a legitimate need, but these were only discovered months later during random audits. The hospital needs to improve its detection capabilities. Which of the following is the most effective solution?

A.Deploy a Security Information and Event Management (SIEM) system with automated alerting.
B.Retain logs for a longer period to allow more thorough audits.
C.Assign additional staff to manually review logs on a daily basis.
D.Increase the verbosity of logging to capture more details.
AnswerA

A SIEM correlates and analyses EHR log events centrally, applying automated alerting rules so unauthorised PHI access is flagged promptly rather than discovered months later. This directly addresses the stated constraint: the security team cannot manually review the log volume in a timely manner.

Why this answer

A SIEM system aggregates logs from the EHR system and applies correlation rules to detect patterns indicative of unauthorized access, such as an employee viewing records outside their department or during off-hours. It generates real-time alerts, enabling the security team to respond promptly rather than relying on manual log review. This directly addresses the problem of being overwhelmed by log volume and delayed detection.

Exam trap

The trap here is that candidates may think increasing log verbosity or retention improves detection, but without automated analysis, more data only worsens the signal-to-noise ratio and delays incident discovery.

How to eliminate wrong answers

Option B is wrong because retaining logs for a longer period does not improve detection speed; it only preserves evidence for later audits, which still occur months after the incident. Option C is wrong because assigning additional staff to manually review logs is not scalable and would still be overwhelmed by the high volume of logs, leading to delayed or missed detections. Option D is wrong because increasing log verbosity would generate even more log data, exacerbating the existing problem of log overload without providing automated analysis or alerting.

719
MCQeasy

A security analyst is reviewing logs and finds multiple failed login attempts from an external IP address followed by a successful login. Which type of attack is most likely occurring?

A.Password spraying
B.Brute force attack
C.Credential stuffing
D.Social engineering
AnswerB

Repeated failed authentications from one external address immediately followed by success indicates systematic credential guessing until the correct password was found. Brute force attacks iterate through password combinations against a known account, matching the log pattern of many failures then one success.

Why this answer

A brute force attack involves systematically trying all possible password combinations until the correct one is found. The log pattern of multiple failed attempts from a single external IP followed by a success is the classic signature of a brute force attack, as the attacker iterates through a password list or character space against the same username.

Exam trap

The trap here is that candidates confuse 'brute force' with 'credential stuffing' because both involve multiple login attempts, but credential stuffing uses known breached credentials (often from different IPs) and shows a higher initial success rate, whereas brute force targets a single account with many guesses from one IP.

How to eliminate wrong answers

Option A is wrong because password spraying involves trying a small set of common passwords against many usernames, not multiple failed attempts from a single IP against one account. Option C is wrong because credential stuffing uses previously breached username/password pairs from other services, which would typically show a high success rate or rapid failures, not a long sequence of failures from one IP. Option D is wrong because social engineering relies on manipulating users (e.g., phishing or pretexting) to reveal credentials, not on automated login attempts visible in logs.

720
MCQeasy

A security analyst is reviewing the access control policy and notices that some users have been granted 'write' access to a directory that contains sensitive financial reports. Which principle of information security is being violated?

A.Non-repudiation
B.Least privilege
C.Availability
D.Confidentiality
AnswerB

Granting write access to sensitive financial reports exceeds what users need to perform their duties, breaching least privilege — the principle that subjects receive only the minimum access rights required. The stem's constraint is unnecessary write permission on a sensitive directory, which least privilege directly prohibits.

Why this answer

The principle of least privilege dictates that users should be granted only the minimum permissions necessary to perform their job functions. Granting 'write' access to a directory containing sensitive financial reports to users who do not require that level of access violates this principle, as it introduces unnecessary risk of unauthorized modification or data leakage.

Exam trap

The trap here is that candidates may confuse the violation of least privilege with a breach of confidentiality, but the question specifically highlights the granting of unnecessary write permissions, which is a direct violation of the least privilege principle, not merely a confidentiality issue.

How to eliminate wrong answers

Option A is wrong because non-repudiation ensures that a party cannot deny having performed an action, typically achieved through digital signatures or audit logs, and is not directly related to the level of access granted. Option C is wrong because availability ensures that systems and data are accessible when needed, often addressed through redundancy and fault tolerance, not by restricting write permissions. Option D is wrong because confidentiality protects data from unauthorized disclosure, which is a concern here, but the specific violation described is the granting of excessive permissions (write access) rather than the exposure of data itself; the core principle being violated is least privilege, not confidentiality.

721
MCQeasy

An organization uses role-based access control (RBAC). An employee transfers from the Sales department to the Marketing department. What is the most secure way to update the employee's access?

A.Remove the Sales role and then add the Marketing role
B.Add the Marketing role and remove the Sales role after 30 days
C.Modify the Sales role to include Marketing permissions
D.Create a new custom role with combined permissions
AnswerA

Removing the Sales role first revokes all inherited Sales permissions before the Marketing role is granted, preventing any window where the employee holds both roles' privileges. This satisfies RBAC's least-privilege constraint during the transfer, avoiding cumulative access that sequential addition alone would leave in place.

Why this answer

In RBAC, access is determined by the roles assigned to a user. The most secure method is to remove the old role (Sales) first to eliminate any residual permissions, then add the new role (Marketing). This ensures the employee does not retain access to Sales resources during the transition, adhering to the principle of least privilege.

Exam trap

The trap here is that candidates may think adding the new role first ensures continuity of access, but the most secure approach is to remove the old role first to prevent any period of dual access.

How to eliminate wrong answers

Option B is wrong because adding the Marketing role before removing the Sales role creates a 30-day window where the employee has permissions from both departments, violating least privilege and increasing the risk of unauthorized access. Option C is wrong because modifying the Sales role to include Marketing permissions would grant those permissions to all Sales users, not just the transferring employee, leading to privilege creep and potential data leakage. Option D is wrong because creating a new custom role with combined permissions is unnecessary and inefficient; it complicates role management and may inadvertently grant the employee access to both departments' resources if the Sales role is not removed.

722
MCQmedium

A security administrator at a financial firm is configuring access control for a new document management system. The system must enforce access decisions based on the sensitivity labels of documents and the clearance levels of employees, and it must prevent users from delegating their access to others. Which access control model should the administrator implement?

A.Discretionary access control (DAC)
B.Mandatory access control (MAC)
C.Attribute-based access control (ABAC)
D.Role-based access control (RBAC)
AnswerB

MAC enforces access based on security labels assigned to subjects and objects, and users cannot change or delegate these labels. This matches the requirement to use sensitivity labels and clearance levels while preventing delegation. The system, not the user, makes access decisions, ensuring strict confidentiality and integrity controls suitable for a financial firm.

Why this answer

Mandatory access control (MAC) is the only model that uses system-enforced labels for both subjects and objects, and it prohibits users from changing or delegating access. The scenario requires sensitivity labels, clearance levels, and no delegation, which are defining characteristics of MAC. DAC, RBAC, and ABAC do not provide these mandatory, non-delegable controls by default.

Exam trap

The trap here is assuming that any label-based or role-based model can enforce mandatory, non-delegable access, when only MAC uses system-controlled security labels that users cannot alter.

723
Multi-Selecthard

Which THREE of the following are essential elements of an effective incident response plan? (Choose three.)

Select 3 answers
A.Containment, eradication, and recovery
B.Detection and analysis
C.Public relations and media notification
D.Cyber insurance purchasing
E.Preparation and training
AnswersA, B, E

These steps limit damage, remove threats, and restore operations.

Why this answer

The incident response plan lifecycle, as defined by NIST SP 800-61, includes four core phases: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity. Options A, B, and E directly map to these essential phases, ensuring the organization can detect an incident, contain it to prevent spread, eradicate the root cause, recover normal operations, and continuously improve through training and preparation.

Exam trap

The trap here is that candidates confuse supporting activities (like PR or insurance) with the mandatory operational phases defined in the NIST incident response lifecycle, leading them to select non-essential business functions instead of the core technical steps.

724
MCQmedium

A company deploys a RADIUS server for wireless 802.1X authentication. Users report that after a password change, their devices still authenticate successfully for several hours using cached credentials. Which RADIUS behavior most likely explains this?

A.RADIUS encrypts only the password field and relies on a shared secret, so cached credentials are replayed
B.The authenticator caches the successful authentication and continues to authorize the supplicant until reauthentication is triggered
C.RADIUS uses UDP and therefore cannot immediately propagate a password change to the client
D.The wireless controller performs local authentication and never contacts the RADIUS server
AnswerB

In 802.1X, the authenticator can maintain an authorized state for a supplicant after a successful RADIUS exchange and only reauthenticate at a configured interval or on a session event. Until reauthentication occurs, the device remains authorized even though the password changed. This caching of authorization state, governed by session and reauthentication timers, is the most likely reason users keep working for hours after the change.

Why this answer

In 802.1X, the authenticator keeps a supplicant in an authorized state after a successful RADIUS exchange and only reauthenticates at defined intervals or on session events. A password change does not tear down existing authorized sessions, so devices continue to work until reauthentication is forced. Transport protocol and local authentication do not explain the observed delay.

Exam trap

The trap here is blaming RADIUS transport or encryption for stale sessions, when the real cause is the authenticator caching an authorized state between reauthentications.

725
MCQmedium

A financial services firm wants to reduce the risk of unauthorized access to its customer database. The security manager proposes implementing role-based access controls, encrypting data at rest, and enabling database activity monitoring. After these controls are in place, the residual risk is still considered high by the CISO. Which risk response strategy is the firm currently applying, and what should be done next?

A.Risk avoidance; the firm should discontinue the customer database entirely.
B.Risk transference; the firm should purchase cyber insurance to cover all potential losses.
C.Risk acceptance; the firm should document the residual risk and take no further action.
D.Risk mitigation; the firm should consider additional controls or risk transfer for the remaining risk.
AnswerD

The firm is applying mitigation by adding access controls, encryption, and monitoring. However, residual risk remains high, so they should evaluate further mitigation or transfer options such as cyber insurance. Mitigation reduces likelihood or impact, but does not eliminate risk entirely; therefore, continued treatment is appropriate.

Why this answer

The firm is actively reducing risk through technical controls, which is risk mitigation. Since residual risk remains high, they should consider additional mitigation or risk transfer. Mitigation lowers likelihood or impact but does not eliminate risk, so ongoing evaluation is necessary.

Avoidance would mean stopping the activity, acceptance would mean no further action, and transference would involve insurance or outsourcing—none of which match the described controls.

Exam trap

The trap here is confusing risk mitigation with risk acceptance because controls are already in place, but residual risk being high means mitigation is ongoing, not accepted.

726
Multi-Selectmedium

Which TWO of the following are functions of a network firewall?

Select 2 answers
A.Resolving domain names to IP addresses
B.Filtering traffic based on IP addresses and ports
C.Performing Network Address Translation (NAT)
D.Encrypting data at rest
E.Assigning IP addresses to hosts
AnswersB, C

Core function of a firewall.

Why this answer

A network firewall's primary function is to enforce access control policies by filtering traffic based on Layer 3 (IP addresses) and Layer 4 (ports) information. This stateless or stateful inspection allows the firewall to permit or deny packets according to rules, such as allowing HTTP traffic (TCP port 80) from a specific source IP. This is a core security mechanism to segment networks and block unauthorized access.

Exam trap

The trap here is that candidates confuse optional features (like NAT or DHCP) with core firewall functions, or they mistake DNS resolution for a firewall capability, when the SSCP exam expects you to know that filtering based on IP/port is the fundamental purpose.

727
MCQmedium

After a ransomware attack, the recovery team must restore encrypted files from backups. The backups are stored on a separate network segment and were last verified three days ago. What should the team do FIRST?

A.Disconnect the infected systems from the network.
B.Verify the integrity and cleanliness of the backup.
C.Contact law enforcement.
D.Restore all files from the most recent backup.
AnswerB

Confirming the backup's integrity and freedom from malware before restoring prevents reinfection and ensures recoverable data. Since the backup resides on an isolated segment and was verified three days ago, validation must precede any restoration attempt.

Why this answer

Before restoring anything, the team must confirm the backup itself is intact and free of malware — ransomware operators frequently target or linger in backup repositories, and a three-day-old verification does not guarantee current cleanliness. Restoring a compromised backup would re-infect the environment and waste the recovery window. Only after validating integrity and scanning for malicious artifacts should restoration proceed.

Exam trap

The trap here is choosing the most dramatic-sounding action (disconnect, call law enforcement) or the fastest action (restore immediately) instead of the methodical verification step that SSCP emphasizes as the first recovery action.

How to eliminate wrong answers

Option A is wrong because although isolating infected systems is important, the question asks what to do FIRST in the recovery/restoration process — containment should already be underway, and the immediate recovery risk is restoring a tainted backup. Option C is wrong because contacting law enforcement is a parallel notification activity, not a prerequisite technical step before restoration, and it does not protect the restore operation. Option D is wrong because blindly restoring the most recent backup without verifying its integrity or cleanliness can reintroduce the ransomware or restore corrupted data, defeating the purpose of recovery.

728
Multi-Selecteasy

Which TWO of the following are considered secure cryptographic hash functions as of current standards? (Select TWO.)

Select 2 answers
A.SHA-3
B.RC4
C.SHA-1
D.MD5
E.SHA-256
AnswersA, E

SHA-3 remains collision- and preimage-resistant under current standards, satisfying the stem's requirement for a secure hash function. Its sponge construction (Keccak) differs fundamentally from SHA-2's Merkle–Damgård design, providing an independent security margin should SHA-2 weaknesses emerge. NIST standardised it in FIPS 202, so it meets current cryptographic approval.

Why this answer

SHA-3 (Option A) is correct because it is the latest NIST-standardized hash function family (FIPS 202), based on the Keccak sponge construction, and remains resistant to known collision and preimage attacks. SHA-256 (Option E) is correct because it is part of the SHA-2 family (FIPS 180-4) and is still considered cryptographically secure for collision resistance and preimage resistance in current standards. RC4 (Option B) is a stream cipher, not a hash function, and is deprecated due to biases in its keystream.

SHA-1 (Option C) is no longer considered secure because practical collision attacks (e.g., SHAttered) have been demonstrated. MD5 (Option D) is also broken, with trivial collision generation, so it is unsuitable for security purposes.

Exam trap

SSCP often tests the confusion between deprecated algorithms (MD5, SHA-1) and secure ones, and between hash functions and ciphers (RC4), tempting candidates to pick SHA-1 because it is a SHA family member.

729
Matchingmedium

Match each cryptography term to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Same key for encryption and decryption

Key pair: public and private

One-way function producing fixed output

Ensures authenticity and non-repudiation

Why these pairings

Correct matches: Symmetric encryption uses one key; asymmetric uses a key pair; hashing produces fixed-size digests; digital signatures ensure non-repudiation. Common confusions include swapping symmetric/asymmetric definitions or treating hashing as encryption.

730
MCQhard

A network analyst reviews firewall logs and sees multiple SYN packets to various ports from the same external IP in a short time, with no subsequent ACK. What is the most likely cause?

A.Brute force password attack on SSH
B.Distributed denial-of-service (DDoS) attack
C.ICMP ping sweep
D.Port scan using SYN scan technique
AnswerD

A SYN scan sends TCP SYN probes to many ports but never completes the handshake, so no ACK follows. This half-open pattern across multiple ports from one source in a short window is the signature of port scanning rather than a flood or misconfiguration.

Why this answer

A SYN scan sends SYN packets to multiple ports; if a port is open, the target responds with SYN-ACK, but the scanner never completes the handshake (no ACK). The absence of ACK packets after the SYN packets indicates the scanner is not establishing connections, which is characteristic of a SYN scan, not a brute force or DDoS attack.

Exam trap

ISC2 often tests the distinction between a SYN scan and a DDoS attack; the trap is that candidates see 'multiple SYN packets' and immediately think 'SYN flood DDoS,' but a SYN flood typically uses spoofed IPs and aims to exhaust resources, whereas a single IP scanning various ports without ACKs indicates reconnaissance.

How to eliminate wrong answers

Option A is wrong because a brute force password attack on SSH would involve repeated SSH connection attempts (complete TCP handshakes) to port 22, not just SYN packets to various ports without ACKs. Option B is wrong because a DDoS attack typically floods with traffic from many sources (distributed) to overwhelm a target, not just a single external IP sending SYN packets to various ports without completing connections. Option C is wrong because an ICMP ping sweep uses ICMP Echo Request packets, not TCP SYN packets, to discover live hosts.

731
MCQhard

A security analyst is reviewing a script that performs automated backups. The script uses a hardcoded password to connect to the database. What is the most secure alternative?

A.Change the password manually every week.
B.Store the password in an environment variable.
C.Replace the password with SSH key authentication.
D.Retrieve the password from a secrets management service at runtime.
E.Use a more complex password.
AnswerD

A secrets management service stores credentials encrypted and issues them only to authenticated, authorised callers at runtime, so the password never resides in the script or source control. This removes the hardcoded secret, satisfying the requirement for a more secure alternative.

Why this answer

Retrieving the password from a secrets management service at runtime is the most secure alternative because it eliminates hardcoded credentials from the script and centralizes secret storage with access controls, auditing, and rotation. Services like AWS Secrets Manager, HashiCorp Vault, or Azure Key Vault issue short-lived credentials and log access. This removes the secret from source code and version control entirely.

Exam trap

The trap is thinking that environment variables or frequent password changes are 'secure enough'; the exam expects recognition that only a secrets manager removes the hardcoded secret and provides rotation, auditing, and least-privilege access.

How to eliminate wrong answers

Option A is wrong because manually changing the password weekly still leaves a hardcoded credential in the script between changes and does not scale or provide auditability. Option B is wrong because environment variables can be exposed via process listings, logs, or crash dumps, and they are not encrypted at rest or audited. Option C is wrong because SSH key authentication is for shell/remote access, not for database authentication in a script connecting via a database protocol.

Option E is wrong because a more complex password is still hardcoded and thus discoverable in the script or repository.

732
MCQeasy

Which of the following is the BEST definition of Recovery Point Objective (RPO)?

A.The cost of data recovery
B.The time it takes to recover data after a disaster
C.The maximum acceptable data loss in terms of time
D.The number of backup copies stored
AnswerC

RPO defines the maximum tolerable data loss measured as elapsed time before the disruption, setting the required backup or replication frequency. This satisfies the definition requested: it expresses how much data, in time terms, the organisation can afford to lose.

Why this answer

Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time, indicating how far back in time the data must be restored to resume operations after a disaster. It directly drives backup frequency and replication intervals, such as setting a 15-minute RPO requiring transaction log backups every 15 minutes in SQL Server or continuous data replication in a SAN environment.

Exam trap

ISC2 often tests the confusion between RPO and RTO, where candidates mistakenly select 'the time it takes to recover data' (RTO) instead of the maximum acceptable data loss in time (RPO).

How to eliminate wrong answers

Option A is wrong because RPO is not a cost metric; cost of data recovery is typically associated with Recovery Cost Objective (RCO) or total cost of ownership, not RPO. Option B is wrong because the time to recover data after a disaster is defined as Recovery Time Objective (RTO), not RPO; RTO focuses on downtime duration, while RPO focuses on data loss tolerance. Option D is wrong because the number of backup copies stored relates to backup retention policies or the 3-2-1 rule, not RPO; RPO is a time-based metric, not a count of copies.

733
MCQhard

An organization is migrating from on-premises servers to a cloud IaaS model. The security team must ensure that virtual machine (VM) images are hardened before deployment. Which of the following is the MOST effective control to ensure consistency and compliance with security baselines?

A.Perform vulnerability scans on each VM after deployment
B.Apply the latest OS patches to each VM immediately after deployment
C.Create a golden image that is hardened and approved for use, and deploy VMs from that image
D.Train administrators on hardening procedures and rely on manual configuration
AnswerC

A hardened golden image bakes the security baseline into a single approved artefact, so every deployed VM inherits identical configuration. This removes per-deployment drift and manual hardening errors, giving consistent, auditable compliance across all cloud instances.

Why this answer

Creating a golden image that is hardened and approved for use ensures that every VM deployed from it inherits a consistent, pre-configured security baseline. This approach eliminates configuration drift and manual errors by baking security controls into the image before deployment, making it the most effective control for consistency and compliance.

Exam trap

The trap here is that candidates often choose vulnerability scanning or patching because they focus on security after deployment, missing the core principle that proactive, immutable infrastructure via golden images is the most reliable way to enforce consistent baselines at scale.

How to eliminate wrong answers

Option A is wrong because performing vulnerability scans after deployment is a detective control, not a preventive one; it identifies issues but does not ensure consistent hardening across all VMs. Option B is wrong because applying patches after deployment is reactive and does not guarantee that other hardening configurations (e.g., registry settings, service disabling, group policies) are consistently applied. Option D is wrong because relying on manual configuration by administrators introduces human error and inconsistency, making it impossible to maintain a uniform security baseline across multiple VMs.

734
MCQmedium

A security administrator is hardening a data center switch. Management requires that only the switch's configured management station can initiate a remote CLI session, and that the switch never accept an inbound management connection from any other host. Which control should the administrator implement on the switch to meet this requirement?

A.An inbound access control list applied to the management VLAN interface that permits only the management station's IP address to reach TCP port 22
B.BPDU Guard enabled on all access ports to prevent rogue spanning-tree devices
C.Port security configured on every access port with a maximum of one learned MAC address
D.A TACACS+ or RADIUS server that authenticates all administrative logins with individual accounts
AnswerA

Filtering inbound traffic to the management VLAN so that only the designated management host can reach the SSH service enforces exactly the stated requirement: the switch accepts remote CLI sessions only when they originate from the approved station. All other source addresses are dropped before they can reach the management plane, which also reduces the attack surface of the device itself.

Why this answer

Restricting the management plane by source address is the only control listed that limits who may initiate an administrative session. An inbound ACL bound to the management interface permits the approved management station and denies everything else, directly matching the stated policy. Authentication, port security, and loop-prevention features address different problems and leave the management service reachable from any host on the network.

Exam trap

The trap here is assuming that strong authentication alone limits who can connect to a device, when reachability filtering must be applied separately to restrict session sources.

735
MCQmedium

A security analyst notices that an employee's account has been sending large amounts of data to an external IP address during non-business hours. The analyst suspects the employee's credentials have been compromised. What is the FIRST step the analyst should take according to incident response procedures?

A.Block the external IP address at the firewall.
B.Disable the employee's user account.
C.Contact law enforcement.
D.Inform the employee's manager.
AnswerB

Disabling the employee's user account stops the unauthorized access and data exfiltration immediately, aligning with incident response containment procedures.

Why this answer

Disabling the employee's user account immediately stops the unauthorized activity and prevents further data exfiltration, as per incident response procedures. Option A is wrong; blocking the external IP address may not stop the attacker if they have other methods or can change IPs. Option C is wrong; informing the manager is important but not the first action, as containment is the priority.

Option D is wrong; contacting law enforcement is premature before containing the incident and gathering evidence.

736
MCQhard

A security analyst is investigating a network where an attacker successfully redirected traffic from a legitimate web server to a malicious server by corrupting the target domain's DNS records in a local resolver cache. Which attack technique was used?

A.SYN flood
B.DNS poisoning
C.ARP spoofing
D.Smurf attack
AnswerB

DNS poisoning corrupts a resolver's cached records, substituting a malicious IP for the legitimate domain. Because the local resolver returns the forged entry, traffic is silently redirected to the attacker's server, matching the scenario's cache corruption and redirection.

Why this answer

DNS poisoning (also called DNS cache poisoning or DNS spoofing) is the attack where an attacker injects forged DNS records into a resolver's cache, causing the resolver to return a malicious IP address for a legitimate domain. This matches the scenario exactly: the target domain's records were corrupted in a local resolver cache, redirecting traffic to a malicious server. The other options describe volumetric or Layer 2 attacks unrelated to DNS record manipulation.

Exam trap

The trap here is confusing DNS poisoning with ARP spoofing — both redirect traffic, but ARP spoofing works at Layer 2 by manipulating MAC-to-IP mappings, while DNS poisoning corrupts name resolution records in a resolver cache.

How to eliminate wrong answers

Option A is wrong because a SYN flood is a Layer 4 denial-of-service attack that exhausts TCP connection state by sending many SYN packets without completing the handshake — it does not alter DNS records or redirect traffic. Option C is wrong because ARP spoofing operates at Layer 2 by sending forged ARP replies to associate an attacker's MAC with a legitimate IP, enabling man-in-the-middle on a LAN, not DNS cache corruption. Option D is wrong because a Smurf attack is an ICMP amplification DoS that sends spoofed broadcast pings to a network, causing many hosts to reply to a victim — it has nothing to do with DNS records.

737
MCQhard

During a vulnerability scan, a tool reports a critical vulnerability on a web server. The system owner claims it is a false positive because the server is not accessible from the internet. However, the server is accessible from the internal network. What is the best course of action?

A.Accept the risk and close the finding
B.Ignore the finding as the vulnerability scanner is known for false positives
C.Remove the server from the network to eliminate the risk
D.Verify the vulnerability manually and if confirmed, remediate according to internal risk
AnswerD

Internal reachability still constitutes real exposure, so the finding cannot be dismissed as a false positive. Manually confirming the vulnerability and then remediating it according to internal risk tolerances satisfies the stem's constraint that the server, while not internet-facing, remains accessible to internal actors and lateral movement.

Why this answer

A vulnerability that is exploitable from the internal network still poses a significant risk, as internal threats (e.g., compromised endpoints, malicious insiders) can leverage it. The system owner’s claim that the server is not internet-facing does not negate the need for verification and remediation; internal attack surfaces must be managed according to the organization’s risk appetite. Manual verification ensures the scanner’s report is accurate, and if confirmed, remediation should follow internal risk-based prioritization.

Exam trap

The trap here is that candidates assume a server not accessible from the internet is automatically low-risk, ignoring the reality that internal network threats are a primary attack vector in many breaches, and that risk must be evaluated based on the asset’s exposure and criticality within the internal environment.

How to eliminate wrong answers

Option A is wrong because accepting the risk without verification ignores the fact that internal network access can lead to exploitation, and risk acceptance requires formal approval and justification, not a simple dismissal. Option B is wrong because dismissing a finding solely because the scanner is known for false positives is negligent; each finding must be manually verified, as scanners can produce both false positives and false negatives, and internal threats are real. Option C is wrong because removing the server from the network is an extreme, unnecessary measure that disrupts business operations; the correct approach is to verify and remediate the vulnerability, not isolate the asset without analysis.

738
MCQmedium

A security analyst is reviewing logs and notices multiple failed login attempts from a single IP address against an administrative account. The SIEM has not generated an alert. Which configuration change would best detect this scenario?

A.Enable signature-based detection on the IDS
B.Implement a host-based IDS on the server
C.Create a SIEM correlation rule to alert on multiple failed logins from the same source
D.Increase log retention to 1 year
AnswerC

A correlation rule aggregates multiple failed authentication events sharing the same source IP within a defined window, generating an alert that the SIEM's default logging alone does not produce. This directly addresses the brute-force pattern against the administrative account that currently goes undetected.

Why this answer

A SIEM correlation rule can specifically detect multiple failed login attempts from the same source IP address by aggregating and analyzing log events in real time. Unlike signature-based or host-based IDS solutions, a SIEM correlation rule can be tuned to match this exact behavioral pattern, triggering an alert when the configured threshold (e.g., 5 failures within 10 minutes) is exceeded. This directly addresses the gap where the SIEM failed to generate an alert due to the absence of such a rule.

Exam trap

The trap here is that candidates often confuse the roles of IDS/IPS and SIEM, mistakenly thinking signature-based or host-based IDS can natively correlate login failures from a single source, when in fact SIEM correlation rules are specifically designed for this multi-event behavioral detection.

How to eliminate wrong answers

Option A is wrong because signature-based detection on an IDS relies on known attack patterns (e.g., SQL injection signatures) and cannot detect behavioral anomalies like multiple failed logins from a single IP unless a specific signature is written for that pattern, which is inefficient and not the standard approach. Option B is wrong because a host-based IDS (HIDS) monitors local system calls and file integrity on the server, but it does not natively correlate login attempts across multiple log sources or aggregate events from a single source IP; it would only see individual login failures without context. Option D is wrong because increasing log retention to 1 year does not enable detection of ongoing attacks; it only preserves historical data for forensic analysis after an incident has occurred, failing to provide real-time alerting.

739
MCQmedium

A security administrator receives an alert about a potential SYN flood attack on a web server. At which OSI layer does this attack occur?

A.Layer 7 (Application)
B.Layer 3 (Network)
C.Layer 2 (Data Link)
D.Layer 4 (Transport)
AnswerD

SYN floods exploit the TCP three-way handshake, exhausting half-open connection tables. TCP operates at Layer 4, the Transport layer, where ports and connection state reside, so the attack is classified there rather than at Layers 3 or 7.

Why this answer

A SYN flood attack exploits the TCP three-way handshake by sending a barrage of SYN packets without completing the handshake, exhausting server resources. This attack targets the Transport Layer (Layer 4), where TCP operates, as defined in RFC 793. The security administrator's alert specifically involves TCP SYN segments, which are Layer 4 protocol data units.

Exam trap

The trap here is that candidates confuse the attack's effect on the application (e.g., web server unavailability) with the layer being attacked, incorrectly selecting Layer 7 instead of recognizing the TCP handshake at Layer 4.

How to eliminate wrong answers

Option A is wrong because Layer 7 (Application) deals with application protocols like HTTP, FTP, and SMTP, not the TCP handshake mechanics exploited in a SYN flood. Option B is wrong because Layer 3 (Network) handles IP addressing and routing, not the stateful connection establishment that SYN floods abuse. Option C is wrong because Layer 2 (Data Link) covers MAC addresses and frame delivery on a local network segment, with no involvement in TCP's connection-oriented behavior.

740
MCQmedium

A company uses a SOAR platform for incident response. Which factor is most critical for effective automation?

A.High-quality playbooks
B.Integration with all security tools
C.Low false positive rate
D.Real-time threat intelligence feeds
AnswerA

High-quality playbooks supply the deterministic, machine-readable decision logic that SOAR automation executes without human intervention. Since the platform orchestrates actions from predefined workflows, their accuracy and completeness directly determine whether responses fire reliably, satisfying the stem's demand for the most critical automation factor.

Why this answer

High-quality playbooks are the most critical factor because SOAR automation relies on predefined, tested, and context-rich workflows to orchestrate response actions. Without accurate playbooks that map to specific incident types, automated actions can misidentify threats, execute incorrect containment steps, or fail to adapt to evolving attack patterns, rendering integrations and feeds ineffective.

Exam trap

ISC2 often tests the misconception that more integrations or real-time data automatically improve automation, but the trap here is that without high-quality playbooks, even perfect integrations and feeds lead to chaotic or harmful automated responses.

How to eliminate wrong answers

Option B is wrong because integration with all security tools is not the most critical factor; while broad integration enables data collection and action execution, it is useless without well-defined playbooks to orchestrate those tools effectively. Option C is wrong because a low false positive rate is a prerequisite for any detection system, but SOAR automation specifically depends on playbook logic to handle alerts correctly, not just on alert quality. Option D is wrong because real-time threat intelligence feeds enrich context but do not drive automation; playbooks must incorporate that intelligence into decision trees and response steps for it to be actionable.

741
MCQeasy

When using CBC mode encryption, what is the purpose of the initialization vector (IV)?

A.To provide authentication
B.To increase the key length
C.To add randomness and prevent identical ciphertext for repeated plaintext
D.To enable parallel encryption
AnswerC

The IV is XORed with the first plaintext block before encryption, so identical plaintext blocks produce different ciphertext across messages. This satisfies the randomness requirement, preventing pattern disclosure when the same data is encrypted repeatedly under one key.

Why this answer

The initialization vector (IV) in CBC mode ensures that each encryption of the same plaintext with the same key produces a different ciphertext. The IV is XORed with the first plaintext block before encryption, introducing randomness that prevents patterns from being exposed in the ciphertext, which is critical for semantic security.

Exam trap

The trap here is that candidates confuse the IV's role in adding randomness with authentication or key extension, or they mistakenly think CBC supports parallel encryption because they overlook the sequential dependency of ciphertext blocks.

How to eliminate wrong answers

Option A is wrong because CBC mode provides no inherent authentication; it is a confidentiality-only mode, and authentication requires a separate MAC or an authenticated encryption mode like GCM or CCM. Option B is wrong because the IV does not increase the effective key length; the key length remains fixed, and the IV is a non-secret, random value used per message. Option D is wrong because CBC mode is inherently sequential—each ciphertext block depends on the previous one—so it cannot be parallelized during encryption; only decryption can be parallelized.

742
MCQmedium

An Identity Provider (IdP) sends an XML-based assertion to a Service Provider (SP) to grant access. Which federated identity standard is being used?

A.OAuth 2.0
B.Security Assertion Markup Language (SAML)
C.OpenID Connect (OIDC)
D.Kerberos
AnswerB

SAML exchanges authentication and authorisation data as XML assertions between an Identity Provider and a Service Provider. The stem's XML-based assertion from IdP to SP matches SAML's protocol exactly, unlike OAuth 2.0, which uses JSON access tokens rather than XML assertions.

Why this answer

SAML (Security Assertion Markup Language) is the standard that uses XML-based assertions to exchange authentication and authorization data between an Identity Provider (IdP) and a Service Provider (SP). The IdP sends a SAML assertion to the SP to grant access, which is exactly the scenario described.

Exam trap

The trap is confusing SAML with OAuth or OIDC; candidates may pick OAuth because it's commonly used for access delegation, but the exam expects recognition that XML-based assertions are the hallmark of SAML.

How to eliminate wrong answers

Option A is wrong because OAuth 2.0 is an authorization framework that uses tokens (typically JSON Web Tokens) for delegated access, not XML assertions for authentication. Option C is wrong because OpenID Connect (OIDC) is an authentication layer built on OAuth 2.0 that uses JSON Web Tokens (JWTs), not XML assertions. Option D is wrong because Kerberos is a network authentication protocol that uses tickets (not XML assertions) and is typically used within a single domain or realm, not for federated identity across organizations.

743
Multi-Selecthard

Which TWO of the following are appropriate actions when preserving digital evidence at a crime/incident scene?

Select 2 answers
A.Document all actions taken
B.Take photographs of the scene
C.Connect to the internet to check online resources
D.Use the system to check files
E.Power off the system immediately
AnswersA, B

Documentation ensures chain of custody and reproducibility.

Why this answer

Documenting all actions taken (Option A) is a fundamental principle of digital forensics, as it creates a verifiable chain of custody and ensures the integrity of evidence. This documentation includes timestamps, tools used, and any changes made to the system, which is critical for admissibility in legal proceedings. Without proper documentation, the evidence may be challenged as tampered or unreliable.

Exam trap

ISC2 often tests the misconception that immediately powering off a system is always the safest action, but in digital forensics, this can destroy volatile evidence and trigger data loss or corruption.

744
MCQmedium

A security analyst detects a workstation communicating with a known command-and-control server. The workstation is running critical applications. What should be the analyst's first step according to the NIST incident response lifecycle?

A.Power off the workstation immediately to stop the communication.
B.Isolate the workstation from the network while preserving volatile data.
C.Run a full antivirus scan on the workstation.
D.Notify management and wait for instructions.
AnswerB

Isolation stops the workstation communicating with the command-and-control server, containing the compromise, while preserving volatile data such as memory and active connections for later forensic analysis. This aligns with the NIST lifecycle's containment objective before eradication.

Why this answer

According to the NIST incident response lifecycle, the first priority is containment. Isolating the workstation from the network stops communication with the command-and-control server while preserving volatile data (e.g., memory, running processes, network connections) for forensic analysis. Powering off would destroy this critical evidence, and running a scan or waiting for instructions delays containment and risks further compromise.

Exam trap

A common misconception in incident response is that immediate power-off is the safest containment action, but the trap is that it destroys volatile evidence required for forensic analysis, as emphasized in the NIST incident response lifecycle and SSCP exam objectives.

How to eliminate wrong answers

Option A is wrong because powering off the workstation destroys volatile data (e.g., RAM contents, active network connections, process lists) that are essential for forensic analysis and identifying the scope of the compromise. Option C is wrong because running a full antivirus scan on a live, compromised system can alter evidence, trigger destructive malware behaviors, and does not immediately stop the command-and-control communication. Option D is wrong because notifying management and waiting for instructions violates the NIST principle of immediate containment; delaying action allows the attacker to continue exfiltration or lateral movement.

745
MCQeasy

A financial services company has recently deployed a new customer-facing web application on port 443. The application is essential for client transactions. Within the first week, the security team's monitoring system detected thousands of failed login attempts originating from a wide range of IP addresses across multiple countries. The attempts are using common usernames and passwords, indicating a coordinated brute-force attack. The company's perimeter firewall is configured with a default allow rule for inbound TCP traffic on port 443 to the web server's public IP address. The company operates with a small IT team and has a limited security budget. The web application is custom-developed and cannot be modified quickly. The security analyst must recommend a solution to mitigate the attack while maintaining availability for legitimate users. Which of the following is the most effective first step?

A.Implement IP blacklisting by manually adding offending IP addresses to the firewall's deny list
B.Change the web server port from 443 to a non-standard high port
C.Deploy a Web Application Firewall (WAF) configured with rate limiting and CAPTCHA challenges
D.Enable SSH access to the web server for administrative purposes
AnswerC

A WAF inspects HTTP/HTTPS at layer 7, so rate limiting throttles the distributed brute-force attempts and CAPTCHA blocks automated credential stuffing while genuine clients still reach port 443. This satisfies the availability constraint without modifying the custom application or relying on the firewall's coarse default allow rule.

Why this answer

A WAF with rate limiting and CAPTCHA challenges directly mitigates brute-force attacks by throttling repeated login attempts from the same source and challenging suspicious clients, while still allowing legitimate users to access the application. It requires no application code changes, fits a limited budget, and can be deployed quickly in front of the existing web server. This addresses the attack at Layer 7 where the malicious traffic is occurring.

Exam trap

SSCP often tests the distinction between network-layer controls (firewalls, IP blacklists) and application-layer controls (WAF); the trap is choosing a network-layer fix for an application-layer attack, or opting for a manual, unscalable solution.

How to eliminate wrong answers

Option A is wrong because manual IP blacklisting is reactive and unscalable against a distributed attack from thousands of IPs across multiple countries; the small IT team cannot keep up. Option B is wrong because changing the port from 443 to a non-standard high port breaks legitimate client access (users expect HTTPS on 443) and does not stop determined attackers who can scan ports. Option D is wrong because enabling SSH access for administrative purposes does not mitigate the brute-force attack and actually increases the attack surface.

746
MCQmedium

A security administrator is deploying a new web application on a Linux server. The application must be isolated from the host and other applications, and it must only be able to read its own configuration files. The administrator decides to use a container. Which of the following should the administrator implement to meet these requirements?

A.Run the container as the root user to ensure it has permission to read the configuration files.
B.Run the container with the --privileged flag to ensure it has all necessary permissions.
C.Disable all Linux capabilities for the container to prevent any file access.
D.Use a read-only root filesystem and mount only the required configuration files as a read-only volume.
AnswerD

A read-only root filesystem prevents the container from modifying its own files, and mounting only the necessary configuration files as read-only volumes enforces least privilege. This meets the requirement that the application can only read its own configuration files while being isolated from the host and other applications.

Why this answer

The requirement is to isolate the application and restrict it to reading only its own configuration files. A read-only root filesystem combined with read-only volume mounts for specific configuration files enforces this least-privilege model. Other options either grant excessive privileges or break functionality by removing all capabilities.

Exam trap

The trap here is assuming that running a container as root or with privileged flags is necessary for it to function, when in fact it increases the attack surface and violates isolation.

747
Multi-Selectmedium

Which TWO of the following are essential steps in a security incident response process according to the SSCP common body of knowledge? (Select the two best answers.)

Select 2 answers
A.Vulnerability scanning
B.Penetration testing
C.Eradication
D.Identification
E.Risk assessment
AnswersC, D

Eradication removes the root cause — malware, compromised accounts or vulnerable services — after containment, restoring systems to a trusted state. It is a core SSCP incident response phase, alongside preparation, identification, containment, recovery and lessons learned.

Why this answer

According to the SSCP common body of knowledge, the incident response process includes the phases of identification, containment, eradication, recovery, and lessons learned. Option D (Identification) is correct because it is the phase in which the incident is detected, validated, and scoped, determining whether an event is truly a security incident before further action is taken. Option C (Eradication) is correct because it is the phase in which the root cause and malicious artifacts (malware, compromised accounts, backdoors) are removed to prevent the incident from recurring.

Vulnerability scanning (A) and penetration testing (B) are proactive security assessment activities performed before incidents occur, not phases of incident response, and risk assessment (E) is a risk management activity used to evaluate and prioritize risk, not a step in the incident response lifecycle.

Exam trap

SSCP often tests the difference between incident response phases and proactive security activities — candidates pick vulnerability scanning or risk assessment because they sound like security processes.

748
Multi-Selectmedium

Which TWO of the following are best practices for password management?

Select 2 answers
A.Implement account lockout after a few failed attempts
B.Allow reuse of the last 5 passwords
C.Store passwords in plaintext for quick recovery
D.Share passwords via email for convenience
E.Enforce password complexity requirements
AnswersA, E

Account lockout after a small number of failed attempts throttles online brute-force and password-guessing attacks, since further tries are refused for a set period. It satisfies the best-practice requirement by limiting an attacker's attempt rate against a known account.

Why this answer

Option A is correct because implementing account lockout after a few failed attempts mitigates brute-force and password-guessing attacks by temporarily disabling the account after a threshold of invalid logins, a core control in standards like NIST SP 800-53 and CIS Benchmarks. Option E is correct because enforcing password complexity requirements (e.g., minimum length, mixed character classes) increases the search space an attacker must cover, making dictionary and brute-force attacks less likely to succeed. Option B is incorrect because allowing reuse of the last 5 passwords undermines password history policies and lets compromised or previously breached credentials remain valid.

Option C is incorrect because storing passwords in plaintext exposes them to any attacker or insider with file access; passwords should be salted and hashed with a strong algorithm such as bcrypt, scrypt, or Argon2. Option D is incorrect because sharing passwords via email transmits credentials in cleartext over untrusted channels and violates the principle of individual accountability; credentials should never be shared, and privileged access should use vaulting or PAM solutions instead.

Exam trap

SSCP often tests the misconception that password reuse or plaintext storage are acceptable for convenience, or that sharing passwords via email is secure, when these are clear violations of security best practices.

749
Multi-Selectmedium

Which TWO of the following are methods to defend against SYN flood attacks? (Select TWO)

Select 2 answers
A.Enabling IP routing
B.Using UDP instead of TCP
C.Increasing the SYN backlog queue size
D.SYN cookies
E.Disabling TCP timestamps
AnswersC, D

Enlarging the SYN backlog queue lets the server hold more half-open connections before exhausting the table, absorbing bursts rather than dropping legitimate handshakes. It directly mitigates the stem's SYN flood constraint by raising the volume of pending requests the TCP stack tolerates.

Why this answer

Option C (Increasing the SYN backlog queue size) is correct because a SYN flood exhausts the backlog of half-open connections; enlarging the backlog lets the server hold more pending SYNs so legitimate clients can still complete the three-way handshake before the queue overflows. Option D (SYN cookies) is correct because it eliminates the need to store half-open state: the server encodes connection parameters into the SYN-ACK sequence number and only allocates resources when the final ACK returns, so spoofed SYNs cannot exhaust memory. Option A (Enabling IP routing) is unrelated to SYN flood mitigation and would only forward packets between interfaces, potentially worsening exposure.

Option B (Using UDP instead of TCP) is not a defense—SYN floods are specific to TCP's handshake, and switching protocols changes the application entirely rather than protecting it. Option E (Disabling TCP timestamps) has no effect on SYN flood resistance; timestamps are an optional TCP extension for RTT measurement and PAWS, not a resource-exhaustion control.

Exam trap

The trap here is confusing general TCP hardening features (timestamps, routing) with actual SYN flood mitigations — candidates often pick 'increase backlog' as the only answer and miss SYN cookies, or select UDP as a workaround without realizing it breaks the protocol.

750
MCQhard

A patch management process is being audited. Which finding indicates a critical gap in the process?

A.Exception requests for unpatched systems are documented
B.Patches are not tested in a staging environment before production deployment
C.Critical systems are patched monthly
D.Patches are deployed within 30 days of release
AnswerB

Deploying untested patches straight to production risks breaking critical systems and forces emergency rollback, so defects escape detection. Staging validation is the control that catches compatibility and regression issues before they affect live services, making its absence a critical process gap.

Why this answer

A patch management process must include testing patches in a staging environment before production deployment to validate compatibility and avoid breaking critical systems. Without staging validation, patches can introduce regressions, incompatibilities, or outages in production. This is a critical gap because it removes the safety net that catches patch-related issues before they impact live operations.

Exam trap

SSCP often tests whether candidates confuse 'documented exceptions' or 'monthly patching' with process gaps — the real gap is skipping pre-production validation, not the cadence or documentation.

How to eliminate wrong answers

Option A is wrong because documenting exception requests for unpatched systems is actually a sign of a mature process — exceptions should be tracked and approved. Option C is wrong because patching critical systems monthly is a reasonable cadence for many environments and does not by itself indicate a critical gap. Option D is wrong because deploying patches within 30 days of release is a common and acceptable SLA for non-emergency patches, not a critical flaw.

Page 9

Page 10 of 13

Page 11