Courseiva

Systems Security Certified Practitioner SSCP (SSCP) — Questions 751–825

971 questions total · 13pages · All types, answers revealed

Page 10

Page 11 of 13

Page 12
751
MCQmedium

An organization is planning to deploy a remote access VPN for employees. The solution must support strong encryption, mutual authentication, and work through firewalls without requiring additional ports. Which technology is most suitable?

A.L2TP/IPsec
B.PPTP
C.IPsec tunnel mode
D.SSL/TLS VPN
AnswerD

SSL/TLS VPN tunnels over TCP 443, so it traverses existing firewall rules without opening extra ports, satisfying that constraint. It supports strong encryption and mutual authentication through client certificates, letting the organisation verify both user and server identities during the remote access session.

Why this answer

SSL/TLS VPNs (e.g., clientless or client-based SSL VPNs) use TLS over TCP port 443, which is almost universally allowed through firewalls, and they support strong encryption (AES) and mutual authentication via certificates or client certificates. Because they ride on standard HTTPS, no additional ports need to be opened, satisfying all stated requirements.

Exam trap

The trap is choosing IPsec-based options (L2TP/IPsec or IPsec tunnel mode) for 'works through firewalls without additional ports,' when only SSL/TLS VPN on TCP 443 reliably meets that requirement.

How to eliminate wrong answers

Option A is wrong because L2TP/IPsec uses UDP ports 500 and 4500 and IP protocol 50 (ESP), which often require firewall changes and can be blocked by NAT, failing the 'no additional ports' requirement. Option B is wrong because PPTP is obsolete and insecure, using weak MS-CHAPv2 authentication and RC4 encryption, and it uses TCP 1723 and GRE (protocol 47), which many firewalls block. Option C is wrong because IPsec tunnel mode also relies on ESP/IKE ports and protocols that frequently need explicit firewall rules and can struggle with NAT traversal, so it does not meet the 'work through firewalls without additional ports' criterion as cleanly as SSL/TLS VPN.

752
MCQeasy

A security analyst is reviewing network traffic and notices a large number of ICMP echo requests from a single source to multiple destinations within the organization's network. The analyst suspects a reconnaissance attempt. Which type of attack is most likely being performed?

A.Ping of death
B.Smurf attack
C.Ping sweep
D.ICMP flood
AnswerC

A ping sweep involves sending ICMP echo requests to multiple IP addresses to determine which hosts are active. This is a common reconnaissance technique used to map a network. The scenario describes ICMP echo requests from a single source to multiple destinations, which is characteristic of a ping sweep. Thus, it is the most likely attack.

Why this answer

A ping sweep is a reconnaissance technique that uses ICMP echo requests to identify live hosts on a network. The scenario describes a single source sending ICMP echo requests to multiple destinations, which matches the pattern of a ping sweep. Other ICMP-based attacks like Smurf, Ping of Death, and ICMP flood have different characteristics and objectives.

Exam trap

The trap here is confusing a ping sweep, which is for host discovery, with an ICMP flood, which is a denial-of-service attack.

753
MCQmedium

A security analyst receives an alert from the EDR system indicating that a workstation has been communicating with a known malicious IP address. The analyst confirms the alert and notes that the user is still logged in. Which immediate containment action should the analyst take FIRST?

A.Isolate the workstation using the EDR agent's network isolation capability
B.Create a full forensic image of the hard drive
C.Disable the user's Active Directory account
D.Block the malicious IP address at the firewall
AnswerA

EDR network isolation severs the workstation's connections while preserving the agent's management channel and volatile evidence, halting command-and-control traffic and potential lateral movement. This contains the confirmed compromise immediately, before the still-logged-in user or malware can cause further damage.

Why this answer

Network isolation via the EDR agent is the fastest, least disruptive containment action that stops the active command-and-control channel while preserving volatile memory and forensic artifacts on the host. It cuts the malicious traffic immediately without tipping off the attacker through account lockouts or firewall changes that might be noticed. This aligns with the containment phase of incident response, where speed and evidence preservation are both prioritized.

Exam trap

The trap is confusing 'containment' with 'eradication' or 'evidence collection' — candidates often pick forensic imaging or firewall blocking because those sound thorough, but the question asks for the FIRST immediate containment action.

How to eliminate wrong answers

Option B is wrong because creating a full forensic image is a preservation/collection step that takes significant time and does nothing to stop the ongoing malicious communication — containment must precede deep forensics. Option C is wrong because disabling the AD account does not stop the malware already running on the workstation from continuing to beacon out, and it may alert the attacker or disrupt the user's other sessions before evidence is gathered. Option D is wrong because blocking a single IP at the firewall is a network-perimeter action that only addresses one indicator; the malware could use DGA domains, other C2 IPs, or encrypted channels, and it leaves the compromised host free to move laterally.

754
MCQmedium

An organization's disaster recovery plan specifies an RPO of 4 hours and an RTO of 24 hours for a critical database. Which of the following best describes these metrics?

A.RPO means up to 4 hours of data loss; RTO means the database must be recovered within 24 hours.
B.RPO means recovery point objective; RTO means recovery time objective.
C.RPO means the database can be down for up to 4 hours; RTO means up to 24 hours of data loss.
D.RPO means the database must be recovered within 4 hours; RTO means up to 24 hours of data loss.
AnswerA

RPO defines the maximum tolerable data loss measured in time, so four hours means the recovery point may lose up to four hours of transactions. RTO defines the maximum acceptable downtime, so the database must be operational again within 24 hours of disruption.

Why this answer

RPO (Recovery Point Objective) defines the maximum acceptable data loss measured in time, meaning up to 4 hours of transactions could be lost. RTO (Recovery Time Objective) defines the maximum acceptable downtime, meaning the database must be fully operational within 24 hours after a disaster.

Exam trap

The trap here is confusing RPO with downtime and RTO with data loss, leading candidates to swap the definitions or misassign the time values.

How to eliminate wrong answers

Option B is wrong because it merely expands the acronyms without explaining the practical meaning of the metrics (e.g., it doesn't state that RPO is about data loss and RTO is about downtime). Option C is wrong because it reverses the definitions: RPO is about data loss, not downtime, and RTO is about downtime, not data loss. Option D is wrong because it swaps the values: RPO is 4 hours of data loss, not recovery time, and RTO is 24 hours of downtime, not data loss.

755
Multi-Selectmedium

A security analyst is configuring a SIEM to detect potential data exfiltration. Which TWO log sources are most critical for detecting large outbound data transfers?

Select 2 answers
A.Network flow logs (e.g., NetFlow)
B.DNS logs
C.Proxy logs
D.System event logs
E.Application error logs
AnswersA, C

Network flow logs record byte and packet counts per connection, exposing volumetric anomalies such as unusually large outbound transfers that endpoint or application logs would miss. This directly satisfies the SIEM's requirement to detect data exfiltration by revealing the volume and destination of traffic leaving the network, independent of payload content.

Why this answer

Network flow logs (Option A) are critical because NetFlow/IPFIX records capture byte and packet counts per flow, letting the SIEM baseline normal egress volumes and alert on anomalously large outbound transfers to external IPs. Proxy logs (Option C) are equally critical because they record HTTP/HTTPS requests with URLs, destination hosts, and often response/request sizes, exposing web-based exfiltration such as large uploads to cloud storage or file-sharing sites. Together these two sources give both volumetric (flow) and content-context (proxy) visibility into outbound data movement.

DNS logs (B) mainly reveal tunneling or beaconing via query patterns and payload sizes, not bulk data transfer volumes. System event logs (D) and application error logs (E) are host-local and generally lack the outbound network volume and destination detail needed to detect large data exfiltration.

Exam trap

A common pitfall is to think that DNS logs are sufficient for detecting exfiltration via DNS tunneling, but the question specifically asks for detecting 'large outbound data transfers,' which require volume-based analysis from network flow logs or proxy logs, not just query patterns.

756
Multi-Selecthard

A company is migrating to a cloud-based SaaS application and wants to implement federated identity. Users will authenticate using their existing corporate Active Directory credentials. Which THREE components are essential for a SAML-based federation? (Select THREE.)

Select 3 answers
A.Identity Provider (IdP)
B.Trust relationship between IdP and SP
C.Ticket Granting Ticket (TGT)
D.Attribute Authority (AA)
E.Service Provider (SP)
AnswersA, B, E

The IdP authenticates users against the corporate Active Directory and issues signed SAML assertions to the SaaS relying party, satisfying the requirement that existing credentials be reused. Without it, no trusted authority exists to vouch for user identity, so federation cannot occur.

Why this answer

In a SAML-based federation, the Identity Provider (IdP) is essential because it is the entity that authenticates users against the corporate Active Directory and issues signed SAML assertions containing authentication and attribute statements (Option A). The Service Provider (SP) is equally essential as the SaaS application that consumes those SAML assertions to grant access, making it the relying party in the federation (Option E). A trust relationship between the IdP and SP is also required, since the SP must trust the IdP's signing certificate and the two parties exchange metadata (entityID, ACS URL, SSO URL, X.509 certificate) to validate assertions and establish the federation (Option B).

Option C is incorrect because a Ticket Granting Ticket is a Kerberos construct issued by a Key Distribution Center, not a SAML federation component. Option D is incorrect because an Attribute Authority is a separate SAML role that issues attribute assertions and is not one of the three essential components for basic SAML federation between an IdP and SP.

Exam trap

SSCP often mixes Kerberos components (TGT, KDC) into SAML questions — candidates who see 'ticket' and assume it belongs to federation pick the TGT, forgetting SAML uses assertions, not tickets.

757
MCQeasy

A company's backup strategy includes weekly full backups and daily differential backups. A ransomware attack occurred on Wednesday, corrupting data. The last full backup was Sunday. Which backup set should be restored first?

A.Wednesday differential backup
B.Sunday full backup
C.Monday differential backup
D.Tuesday differential backup
AnswerB

Differential backups capture everything changed since the last full backup, so restoration must begin with that full backup as the base. Sunday's full backup is the correct starting point; Tuesday's differential is then applied on top to reach Wednesday's state.

Why this answer

The correct restoration order is to first restore the Sunday full backup, because differential backups contain all changes since the last full backup. Without the full backup as a base, the differential backups cannot be applied. After restoring the full backup, you would then apply the most recent differential backup (Wednesday) to bring the data to the point just before the attack.

Exam trap

The trap here is that candidates often confuse differential backups with incremental backups, mistakenly thinking they need to restore all differentials in order, or they try to restore the most recent differential without the full backup first.

How to eliminate wrong answers

Option A is wrong because the Wednesday differential backup cannot be restored first; it must be applied after the full backup to provide the incremental changes. Option C is wrong because the Monday differential backup is not the most recent differential backup, and restoring it alone would miss changes made on Tuesday and Wednesday. Option D is wrong because the Tuesday differential backup, while more recent than Monday, still requires the full backup first and is not the final differential needed to reach Wednesday's state.

758
Multi-Selecthard

A security auditor is evaluating a company's implementation of mandatory access control (MAC) using a commercial trusted operating system. The auditor needs to verify that the MAC implementation correctly enforces the no read up and no write down rules for confidentiality. Which TWO of the following are essential characteristics the auditor should confirm? (Choose two.)

Select 2 answers
A.Users can change the classification of objects they own.
B.Access decisions are based on the principle of least privilege.
C.Subjects with a lower clearance cannot read objects with a higher classification.
D.The system enforces a strict need-to-know policy for all users.
E.Subjects with a higher clearance cannot write to objects with a lower classification.
AnswersC, E

This is the no read up rule, a core principle of MAC for confidentiality. It ensures that a subject cannot access information above their clearance level, preventing unauthorized disclosure. The auditor must confirm this is enforced, as it is fundamental to MAC's confidentiality model and directly supports the no read up requirement.

Why this answer

The no read up rule prevents subjects from reading objects with higher classifications, and the no write down rule prevents subjects from writing to objects with lower classifications. These two rules are essential for enforcing confidentiality in MAC. The auditor must confirm that subjects with lower clearance cannot read higher-classified objects and that subjects with higher clearance cannot write to lower-classified objects.

Exam trap

The trap here is confusing general security principles like least privilege or need-to-know with the specific label-based rules that define MAC confidentiality, overlooking that only no read up and no write down are mandatory MAC characteristics.

759
MCQmedium

A security administrator is configuring a Linux server to enforce mandatory access control (MAC). Which of the following tools provides MAC on Linux?

A.PAM
B.iptables
C.chmod
D.SELinux
AnswerD

SELinux enforces mandatory access control through type enforcement, role-based access control and multi-level security, applying kernel-level policy labels that constrain every process and file regardless of user discretion. AppArmor and standard permissions do not provide the same comprehensive MAC model on Linux.

Why this answer

SELinux and AppArmor are Linux security modules that implement mandatory access control policies beyond traditional discretionary access control.

760
Multi-Selecthard

Which THREE of the following are valid steps in the change management process? (Select THREE)

Select 3 answers
A.Post-implementation review
B.Vulnerability scanning
C.Baseline configuration update
D.Impact assessment
E.Change request submission
AnswersA, D, E

A post-implementation review closes the change management lifecycle by verifying the change achieved its intended outcome and identifying any unanticipated effects. It is a recognised procedural step, distinct from implementation itself, and satisfies the stem's requirement for a valid change process stage.

Why this answer

Option E (Change request submission) is correct because the change management process formally begins when a Request for Change (RFC) is submitted and logged, often via a ticketing or ITSM system, so the change can be reviewed and authorized. Option D (Impact assessment) is correct because after the RFC is raised, the change advisory board or reviewers evaluate risk, scope, affected systems, and potential downtime to decide whether the change should be approved. Option A (Post-implementation review) is correct because after the change is deployed, the process includes verifying that it achieved its objective, did not cause unintended issues, and capturing lessons learned for future changes.

Option B (Vulnerability scanning) is not a change management step; it is a security assessment activity typically performed under vulnerability management, even though its findings may trigger an RFC. Option C (Baseline configuration update) is not a step in the change management process itself; updating the configuration baseline is a configuration management activity that occurs after an approved change is implemented.

Exam trap

The trap here is that candidates may confuse operational security activities like vulnerability scanning or configuration updates with formal change management process steps, which are specifically about the lifecycle of a change request from submission through review.

761
MCQmedium

During a security audit, it is discovered that a legacy system uses SNMPv1 for network monitoring. Which of the following is the primary security concern?

A.Weak hashing
B.Community strings transmitted in cleartext
C.No access control
D.Lack of encryption
AnswerB

SNMPv1 authenticates requests solely via community strings, which travel unencrypted across the wire. Any packet capture exposes them, granting read or read-write access to device MIBs. This cleartext exposure, absent in SNMPv3's authentication and encryption, is the primary concern for the legacy monitoring setup.

Why this answer

SNMPv1 transmits community strings (effectively passwords) in cleartext over the network. An attacker capturing network traffic can directly read the community string and gain unauthorized access to SNMP-managed devices. This lack of confidentiality is the primary security concern because it exposes the entire monitoring infrastructure to compromise.

Exam trap

The trap here is that candidates often confuse 'no access control' (Option C) with the lack of authentication, but SNMPv1 does have community strings as a form of access control; the real issue is that these strings are transmitted in cleartext, making them easily intercepted.

How to eliminate wrong answers

Option A is wrong because SNMPv1 does not use hashing for authentication; it relies on plaintext community strings, so 'weak hashing' is not a relevant concern. Option C is wrong because SNMPv1 does have a basic form of access control via read-only (RO) and read-write (RW) community strings, though it is rudimentary and easily bypassed once the community string is known. Option D is wrong because while SNMPv1 indeed lacks encryption, the question asks for the 'primary' security concern; the immediate exposure of community strings in cleartext is the most direct and exploitable vulnerability, making lack of encryption a secondary consequence.

762
Multi-Selecthard

A company is selecting a cryptographic algorithm for digital signatures. Which THREE of the following algorithms can be used for digital signatures? (Select THREE.)

Select 3 answers
A.SHA-256
B.DSA
C.AES
D.RSA
E.ECDSA
AnswersB, D, E

DSA is a FIPS-approved asymmetric algorithm designed solely for digital signatures, relying on the discrete logarithm problem over finite fields. It satisfies the stem's requirement directly, generating signatures through a per-message random value k rather than supporting encryption.

Why this answer

DSA (Option B) is a Digital Signature Algorithm designed specifically to generate and verify digital signatures using discrete logarithms, so it is correct. RSA (Option D) can produce digital signatures by signing a hash with the private key and verifying with the public key, making it a valid signature algorithm. ECDSA (Option E) is the Elliptic Curve Digital Signature Algorithm, which provides digital signatures based on elliptic-curve cryptography and is also correct.

SHA-256 (Option A) is only a hash function used to create message digests, not a signature algorithm by itself, and AES (Option C) is a symmetric block cipher for encryption, not for digital signatures.

Exam trap

SSCP often tests the confusion between hash functions (SHA-256), symmetric ciphers (AES), and asymmetric signature algorithms (DSA, RSA, ECDSA), catching candidates who select SHA-256 thinking it 'signs' data.

763
MCQmedium

A security administrator is reviewing audit logs and discovers that a user account with administrative privileges was used to access a file server outside of normal business hours. The administrator needs to determine whether this access was authorized. Which of the following should the administrator do FIRST?

A.Escalate the incident to law enforcement as a potential breach
B.Review the change management records and on-call schedule for that time period
C.Contact the user to ask whether they performed the access
D.Disable the administrative account immediately to prevent further access
AnswerB

Checking change management records and on-call schedules provides context to determine if the access was planned or expected. This is a non-intrusive first step that can quickly validate or refute the need for further investigation. It preserves evidence and avoids disrupting operations prematurely.

Why this answer

The first step in investigating suspicious access is to gather context from non-intrusive sources such as change management and on-call schedules. This helps determine if the access was authorized without disrupting operations or alerting a potential insider. Disabling accounts, contacting users, or escalating externally should come after initial verification.

Exam trap

The trap here is jumping to containment or notification before verifying whether the activity was legitimate; always gather context first.

764
MCQmedium

A security administrator is reviewing the organization's data retention policy. The policy states that customer financial records must be kept for seven years, but the IT team currently archives them indefinitely. Which action should the administrator take to align data handling with the policy while preserving records for legal discovery?

A.Delete all archived financial records immediately to reduce the organization's data footprint.
B.Configure the archival system to apply a retention period of seven years and automatically purge records after that period.
C.Move the archived records to a lower-cost storage tier and continue retaining them indefinitely.
D.Reclassify financial records as public so they are exempt from retention requirements.
AnswerB

Setting a seven-year retention with automatic purge directly enforces the documented policy and limits unnecessary data exposure. It satisfies legal hold requirements during the retention window while reducing storage and breach impact afterward. This is the corrective action that brings technical controls in line with the approved data retention policy.

Why this answer

The correct action is to enforce the documented seven-year retention with automatic purge. That aligns operational data handling with policy, reduces long-term breach impact, and still preserves records during the required legal window. Indefinite retention, immediate deletion, or reclassification all fail to meet the policy's specific retention requirement.

Exam trap

The trap here is assuming that reducing storage cost or reclassifying data satisfies a retention policy, when the policy actually requires a specific retention duration and purge.

765
MCQhard

In a federated identity scenario, a user authenticates to their home domain and accesses a resource in a partner domain. The partner domain trusts the authentication performed by the home domain. What is the home domain's role in this trust relationship?

A.Relying Party
B.Identity Provider (IdP)
C.Service Provider (SP)
D.Kerberos Distribution Center (KDC)
AnswerB

The home domain authenticates the user and issues the assertions the partner domain consumes, so it acts as the Identity Provider (IdP). The partner domain is the relying party or service provider that trusts those assertions.

Why this answer

In a federated identity trust, the home domain that authenticates the user and issues the security token is the Identity Provider (IdP). The partner domain that consumes that assertion and grants access is the Relying Party (or Service Provider). The IdP is trusted because it vouches for the user's identity.

Exam trap

The trap is the interchangeable-sounding terms Relying Party, Service Provider, and IdP — candidates must remember that the authenticating home domain is always the IdP, while the resource-owning partner domain is the RP/SP.

How to eliminate wrong answers

Option A is wrong because the Relying Party is the partner domain that accepts and relies on the token — the opposite side of the trust from the home domain. Option C is wrong because Service Provider is another name for the Relying Party in SAML/OIDC terminology, not the authenticating domain. Option D is wrong because a Kerberos Distribution Center is a component of Kerberos within a single realm that issues tickets; it is not the federated role played by the home domain in a cross-domain trust.

766
Multi-Selectmedium

Which TWO of the following are examples of biometric authentication? (Choose two.)

Select 2 answers
A.Smart card
B.Retina scan
C.PIN
D.Fingerprint
E.Password
AnswersB, D

Retina scan is a biometric trait.

Why this answer

Retina scan is a biometric authentication method because it uses unique physiological characteristics of the eye's retinal blood vessel pattern to verify identity. Biometric authentication relies on measurable biological traits, and the retina's pattern is highly distinctive and difficult to replicate, making it a strong form of authentication.

Exam trap

ISC2 often tests the distinction between authentication factors (something you know, have, or are) and tricks candidates into selecting smart cards or PINs as biometrics because they are commonly associated with security, but they are not based on biological traits.

767
MCQeasy

An organization's security team is reviewing the results of a recent risk assessment. Management decides to accept a particular risk because the cost of the control exceeds the potential loss, and the risk falls within the stated risk appetite. Which term best describes this decision?

A.Risk mitigation
B.Risk acceptance
C.Risk transference
D.Risk avoidance
AnswerB

Risk acceptance is the deliberate decision to retain a risk because the cost of mitigation outweighs the benefit and the exposure is within the organization's risk tolerance. Documenting the rationale, the approving authority, and a review date keeps the decision auditable and ensures it is revisited if conditions change.

Why this answer

When management knowingly retains an exposure because controls cost more than the expected loss and the risk fits within tolerance, the decision is risk acceptance. It must be formally documented with the approving authority and a scheduled review so that changes in threat, cost, or business context trigger reconsideration.

Exam trap

The trap here is confusing acceptance with mitigation, even though no control was implemented and the organization consciously chose to retain the exposure.

768
MCQeasy

A security administrator needs to ensure that only authorized devices can connect to the corporate wireless network. Which of the following should be implemented to meet this requirement?

A.WPA2-Enterprise with 802.1X
B.MAC address filtering
C.SSID broadcasting disabled
D.Pre-shared key (PSK) authentication
AnswerA

WPA2-Enterprise with 802.1X provides strong, certificate-based or credential-based authentication for each device or user before network access is granted. It ensures that only authorized devices with valid credentials can connect, and it supports dynamic key management. This meets the requirement for strict device authorization.

Why this answer

WPA2-Enterprise with 802.1X authenticates each device or user individually, typically against a RADIUS server, before granting network access. This ensures that only authorized devices can connect. MAC filtering, PSK, and SSID hiding are either weak or do not provide per-device authorization.

Exam trap

The trap here is assuming that hiding the SSID or using MAC filtering provides strong access control, when both are easily bypassed.

769
MCQeasy

Which transport layer protocol is used by DNS for its queries and responses, and why is it appropriate?

A.UDP, because it guarantees packet ordering.
B.TCP, because it provides error checking and retransmission.
C.TCP, because reliability is critical for DNS resolution.
D.UDP, because it is connectionless and fast, suitable for short exchanges.
AnswerD

DNS queries and responses use UDP port 53, whose connectionless datagram model avoids handshake overhead and suits the short request-response exchanges typical of name resolution. This satisfies the requirement for a fast transport matching DNS's small, self-contained message pattern.

Why this answer

DNS primarily uses UDP on port 53 because queries and responses are typically small, single-packet exchanges where the low overhead and lack of connection setup make UDP fast and efficient. TCP is used only for large responses (e.g., zone transfers or DNSSEC) or when truncation occurs.

Exam trap

SSCP often tests the misconception that DNS uses TCP for reliability; candidates pick TCP because they associate reliability with critical services, but DNS is designed around UDP's speed with application-level retry logic.

How to eliminate wrong answers

Option A is wrong because UDP does not guarantee packet ordering — it is connectionless and provides no ordering or delivery guarantees; DNS relies on application-level retries and transaction IDs. Option B is wrong because while TCP does provide error checking and retransmission, DNS does not use TCP for typical queries due to the overhead; TCP is reserved for specific cases like zone transfers (AXFR) and large responses. Option C is wrong because reliability is not the primary driver for DNS query transport; UDP's speed and low overhead are preferred, and reliability is handled at the application layer with retries.

770
Drag & Dropmedium

Drag and drop the steps for configuring a Windows Firewall rule to allow inbound RDP traffic into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Windows Firewall: create inbound rule for port 3389, allow connection, select profiles, name it.

771
MCQmedium

An organization has implemented a PAM solution for managing privileged accounts. Which feature allows administrators to request temporary elevated access for a specific task?

A.Session recording
B.Just-in-time provisioning
C.Password vaulting
D.Role-based access control
AnswerB

Just-in-time provisioning grants elevated privileges only for the duration of a specific task, then automatically revokes them. This directly satisfies the PAM requirement for temporary, task-scoped access, eliminating standing privileges that attackers could exploit. Microsoft Entra ID Privileged Identity Management implements this through time-bound role activation, requiring justification and approval before elevation.

Why this answer

Just-in-time (JIT) provisioning in a PAM solution grants elevated privileges only for the duration of a specific task and then automatically revokes them, which is exactly the 'temporary elevated access' described. It minimizes standing privileges and reduces the attack surface. Other PAM features like vaulting and session recording support security but do not provide on-demand, time-bound elevation.

Exam trap

SSCP often tests the confusion between PAM features that control access (vaulting, JIT) and those that monitor it (session recording), leading candidates to choose a monitoring feature when the question asks for access provisioning.

How to eliminate wrong answers

Option A is wrong because session recording is an auditing/monitoring feature that captures privileged sessions for review — it does not grant temporary elevated access. Option C is wrong because password vaulting stores and rotates privileged credentials, but it does not itself provide time-bound elevation for a task. Option D is wrong because role-based access control (RBAC) assigns permissions based on roles, which are typically standing permissions, not temporary task-scoped elevation.

772
MCQhard

A defense contractor runs an air-gapped laboratory where removable media are used to move engineering data between isolated enclaves. Policy requires that a workstation be usable only when a specific approved removable device is inserted, and that the workstation become unusable the instant that device is removed. Which access control approach best enforces this behavior?

A.Implement a hardware token interlock that permits operation only while the approved device is physically engaged
B.Require multifactor authentication with a smart card before any user may log on to the workstation
C.Deploy a role-based policy that grants laboratory staff access to the enclave during working hours
D.Apply discretionary access control so that file owners may share engineering data only with vetted colleagues
AnswerA

A hardware interlock is a physical control that couples system operation to the presence of a specific object, so the workstation runs only with the approved device inserted and stops the moment it is withdrawn. This directly satisfies both halves of the policy without relying on software that could be bypassed.

Why this answer

The policy couples system availability to the physical presence of one approved object, which is a property of a hardware interlock rather than of any logical permission scheme. Interlocks act at the level of the machine itself, so the workstation cannot operate without the device and cannot continue operating after the device is removed, regardless of who is logged on.

Exam trap

The trap here is reaching for a strong logical control such as multifactor authentication when the requirement is actually about physical presence of a specific object.

773
MCQeasy

Which type of IDS monitors network traffic at a specific network segment and analyzes packets for malicious patterns?

A.NIDS
B.HIDS
C.UBA
D.SIEM
AnswerA

A Network IDS (NIDS) passively inspects packets traversing a network segment, matching them against signatures to identify malicious patterns. This placement and packet-analysis capability is exactly what the stem describes, distinguishing it from host-based monitoring.

Why this answer

A Network Intrusion Detection System (NIDS) is specifically designed to monitor traffic on a network segment, capturing packets in real time and analyzing them for known attack signatures or anomalous patterns. Unlike host-based systems, NIDS operates at the network layer, inspecting headers and payloads to detect malicious activity such as port scans, DoS attacks, or exploit attempts.

Exam trap

In the SSCP exam, the distinction between network-based and host-based monitoring is important, and the trap here is that candidates confuse HIDS with NIDS because both involve 'intrusion detection,' but HIDS operates on the host while NIDS operates on the network segment.

How to eliminate wrong answers

Option B (HIDS) is wrong because a Host-based Intrusion Detection System monitors activities on a single host (e.g., system logs, file integrity, process behavior), not network traffic at a segment level. Option C (UBA) is wrong because User Behavior Analytics focuses on identifying deviations in user activity patterns, often using machine learning, rather than analyzing raw network packets for malicious patterns. Option D (SIEM) is wrong because a Security Information and Event Management system aggregates and correlates logs from multiple sources, but does not directly capture or analyze network packets at a segment level.

774
MCQmedium

Based on the exhibit, which type of attack is most likely being attempted?

A.Cross-site scripting (XSS)
B.SQL injection
C.Directory traversal
D.Buffer overflow
AnswerB

The parameter contains SQL syntax designed to drop a table, which is characteristic of a SQL injection attack.

Why this answer

The exhibit shows a URL parameter containing SQL injection syntax (DROP TABLE users;). The %22%3B%20 sequence decodes to "; " which is used to break out of a SQL query. The destination is an internal host (10.0.0.100), likely a web application server.

A status code of 500 indicates a server error, possibly due to the malicious input. Thus, SQL injection (Option D) is correct. The other options do not match the pattern.

775
MCQhard

An organization is implementing a federated identity system to allow employees to access a partner's cloud application using their corporate credentials. The solution must support single sign-on and use XML-based assertions. Which technology should be used?

A.Kerberos
B.SAML
C.OAuth 2.0
D.OpenID Connect
AnswerB

SAML exchanges XML-based assertions between identity and service providers, enabling browser-based single sign-on across security domains. It directly satisfies the stem's requirement for federated authentication using corporate credentials at a partner's cloud application, with the identity provider issuing signed assertions the partner's application validates and trusts.

Why this answer

SAML (Security Assertion Markup Language) is an XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider, enabling single sign-on. It is specifically designed for federated identity scenarios where users authenticate with their corporate credentials to access partner cloud applications. The requirement for XML-based assertions directly points to SAML.

Exam trap

The trap is confusing authentication with authorization: OAuth 2.0 is often mistakenly chosen for SSO, but it is an authorization framework, while SAML is the XML-based authentication standard for federated SSO.

How to eliminate wrong answers

Option A is wrong because Kerberos is a ticket-based authentication protocol used primarily within a Windows domain or trusted realm, not for cross-organizational federated SSO with XML assertions. Option C is wrong because OAuth 2.0 is an authorization framework for delegated access, not an authentication protocol, and it does not use XML assertions. Option D is wrong because OpenID Connect is an authentication layer built on OAuth 2.0 that uses JSON Web Tokens (JWT), not XML-based assertions.

776
MCQhard

An administrator notices that a certificate used for code signing is about to expire. The certificate is signed by a trusted root CA. What is the correct procedure to ensure continued trust?

A.Continue using the expired certificate until a new one is obtained
B.Extend the validity period of the existing certificate by modifying the certificate
C.Switch to a self-signed certificate
D.Request a new certificate from the same CA before expiration
AnswerD

Requesting a replacement certificate from the same trusted CA before expiry maintains an unbroken chain of trust, since the root remains trusted and the new certificate is issued under it. Allowing expiry would break code-signing validation for newly signed software.

Why this answer

The correct procedure is to request a new certificate from the same trusted root CA before the current certificate expires. This ensures that the new certificate is signed by the same trusted root, maintaining the chain of trust without interruption. Continuing to use an expired certificate would break trust validation, as clients and operating systems reject expired code-signing certificates to prevent execution of untrusted code.

Exam trap

The trap here is that candidates may think extending the validity period or using a self-signed certificate is acceptable, but ISC2 tests the understanding that only a certificate from the same trusted CA preserves the existing chain of trust without requiring manual trust configuration.

How to eliminate wrong answers

Option A is wrong because using an expired certificate violates trust models; code-signing certificates are validated for expiration, and expired certificates cause signature verification failures, leading to warnings or blocked execution. Option B is wrong because certificate validity periods cannot be extended by modifying the certificate; the validity is cryptographically bound by the CA's signature, and any alteration invalidates the signature. Option C is wrong because switching to a self-signed certificate breaks the chain of trust; self-signed certificates are not trusted by default and require manual installation on every client, which is impractical for code signing.

777
MCQhard

A financial institution uses a RADIUS server for centralized authentication of its VPN users. A security administrator notices that authentication requests from a new VPN concentrator are being rejected, while requests from other devices work fine. The RADIUS server logs show that the shared secret does not match. What is the most likely cause?

A.The RADIUS server's certificate has expired.
B.The user accounts are not configured with the correct password policy.
C.The VPN concentrator is not included in the RADIUS server's list of authorized clients.
D.The VPN concentrator is configured with the wrong shared secret.
AnswerD

RADIUS clients and servers authenticate each other using a shared secret. If the shared secret on the VPN concentrator does not match the one configured on the RADIUS server, authentication requests will be rejected. The logs indicating a shared secret mismatch point directly to this configuration error on the new device.

Why this answer

RADIUS uses a shared secret between the client (VPN concentrator) and the server to authenticate and encrypt certain attributes. When the shared secret does not match, the server rejects requests from that client. The logs explicitly indicate a shared secret mismatch, so the most likely cause is that the new VPN concentrator has been configured with an incorrect shared secret.

Other options would produce different symptoms or logs.

Exam trap

The trap here is assuming that any authentication failure is due to user credentials or certificates, when the specific log message points to a device-level shared secret mismatch.

778
Multi-Selecthard

Which THREE of the following are key objectives of data classification?

Select 3 answers
A.Identify and protect sensitive information
B.Reduce storage costs by identifying duplicate data
C.Establish a foundation for risk management decisions
D.Determine the encryption algorithm to use
E.Comply with legal and regulatory requirements
AnswersA, C, E

Classification labels data by sensitivity, so controls such as encryption, access restrictions and handling rules can be applied proportionately. This directly satisfies the objective of identifying which assets are sensitive and protecting them, rather than treating all data with identical, costly controls.

Why this answer

Data classification is the process of assigning data to categories (e.g., public, internal, confidential, restricted) based on sensitivity and value, so option A is correct because its primary purpose is to identify sensitive information and apply proportionate protection controls. Option C is correct because classification results feed directly into risk management: you cannot assess likelihood and impact, or select appropriate safeguards, without knowing which data is sensitive and how it must be handled. Option E is correct because many legal and regulatory frameworks (e.g., GDPR, HIPAA, PCI DSS) require organizations to know where regulated data resides and to protect it accordingly, making compliance a key driver of classification.

Option B is not a classification objective — deduplication and storage optimization are data management/storage efficiency techniques, not sensitivity-based categorization. Option D is not a classification objective either; selecting a specific encryption algorithm is a technical control decision made after classification, not the goal of classifying data.

Exam trap

ISC2 often tests the distinction between the objectives of data classification and the subsequent actions or technologies that classification enables, leading candidates to mistakenly select options like 'determine encryption algorithm' as a direct objective.

779
MCQmedium

A security awareness training program aims to reduce successful phishing attacks. Which metric is most appropriate for measuring the effectiveness of this training?

A.Percentage of employees who click simulated phishing links
B.Training completion rate
C.Number of reported phishing emails
D.Number of security incidents caused by phishing
AnswerA

Click rate on simulated phishing links directly measures whether employees apply the training, since clicking is the behaviour the programme targets. It satisfies the stem's effectiveness requirement by quantifying real susceptibility rather than completion or awareness, which do not prove reduced phishing success.

Why this answer

The percentage of employees who click simulated phishing links is the most appropriate metric because it directly measures the behavior the training aims to change—whether employees can recognize and avoid phishing attempts. A decrease in click rate over time indicates improved awareness and reduced susceptibility. This is a direct, outcome-based measure of training effectiveness, unlike completion rates which only show participation.

Exam trap

The trap here is confusing activity metrics (like completion rate) with outcome metrics (like click rate). Candidates often pick completion rate because it's easy to measure, but the exam expects you to choose the metric that directly reflects the training's goal: reducing successful phishing attacks.

How to eliminate wrong answers

Option B is wrong because training completion rate measures participation, not whether employees actually learned to avoid phishing; someone can complete training and still click a malicious link. Option C is wrong because the number of reported phishing emails can be influenced by many factors (e.g., increased attack volume, reporting culture) and does not directly measure whether employees avoid clicking; in fact, more reports could indicate better awareness but doesn't prove reduced susceptibility. Option D is wrong because the number of security incidents caused by phishing is a lagging indicator and may be affected by other controls (e.g., email filters, endpoint protection); it does not isolate the effect of training.

780
Multi-Selectmedium

A security analyst is investigating a phishing incident that led to credential theft. Which TWO actions are appropriate during the containment phase? (Select TWO)

Select 2 answers
A.Reset the compromised user's password
B.Update the incident response plan
C.Conduct a lessons learned meeting
D.Restore the user's machine from backup
E.Block the phishing domain at the email gateway
AnswersA, E

Resetting the password immediately invalidates the stolen credentials, cutting off the attacker's authenticated access before they can pivot or exfiltrate further. This directly satisfies the containment phase's goal of limiting damage while the phishing incident is still active.

Why this answer

Option A is correct because resetting the compromised user's password immediately invalidates the stolen credentials, preventing the attacker from continuing to use the phished account during containment. Option E is correct because blocking the phishing domain at the email gateway stops further phishing emails from that domain reaching other users, limiting the spread of the incident. Option B is not a containment action; updating the incident response plan is a post-incident improvement activity.

Option C is also post-incident, as lessons learned meetings occur after eradication and recovery to improve future response. Option D is a recovery action, since restoring from backup is used to return systems to normal operation after the threat is contained and removed.

Exam trap

In the SSCP exam, candidates often confuse the containment phase with recovery or other phases. A common mistake is selecting actions like restoring from backup (recovery) or conducting lessons learned (post-incident), instead of immediate containment steps such as password resets or blocking malicious infrastructure.

781
Multi-Selectmedium

A cloud security architect is designing a solution to protect workloads running in a public cloud. Which THREE of the following are key security controls that should be implemented?

Select 3 answers
A.Store encryption keys in the same cloud region as the data
B.Deploy a Cloud Security Posture Management (CSPM) tool
C.Disable multi-factor authentication for service accounts
D.Use a Cloud Workload Protection Platform (CWPP)
E.Implement IAM roles with least privilege
AnswersB, D, E

CSPM continuously assesses cloud configuration against benchmarks and compliance baselines, detecting misconfigured storage, network and logging settings. It satisfies the stem's design requirement by addressing the misconfiguration risk inherent to public cloud, where provider-managed infrastructure removes traditional perimeter controls.

Why this answer

Option B is correct because a Cloud Security Posture Management (CSPM) tool continuously monitors the cloud environment for misconfigurations, compliance violations, and policy drift, which is a foundational control for protecting public cloud workloads. Option D is correct because a Cloud Workload Protection Platform (CWPP) secures the actual workloads (VMs, containers, serverless functions) at runtime, providing vulnerability scanning, threat detection, and workload-level hardening. Option E is correct because implementing IAM roles with least privilege limits each identity to only the permissions required for its function, reducing the blast radius of compromised credentials and enforcing zero-trust access control.

Option A is not a key control because storing encryption keys in the same region as the data does not improve security and may actually reduce resilience; key management should follow a dedicated KMS/HSM strategy with appropriate separation and replication. Option C is not a key control because disabling multi-factor authentication for service accounts weakens security and violates best practices; MFA or strong credential management should be enforced, not removed.

Exam trap

The trap is that some options sound plausible but are either not security controls (A) or are insecure practices (C). Candidates might also overlook that the question asks for THREE, and E is correct but easy to miss if they focus only on the first two.

782
MCQmedium

A company wants to track all hardware assets including serial numbers and locations. What is the primary repository for this information?

A.CMDB
B.Patch management tool
C.Vulnerability database
D.SIEM
AnswerA

A CMDB provides the authoritative repository for hardware assets, recording serial numbers, locations and configuration items with their relationships. It directly satisfies the requirement to track all hardware assets, unlike an asset inventory limited to listing, because the CMDB maintains configuration item attributes and interdependencies across the IT estate.

Why this answer

A Configuration Management Database (CMDB) is the authoritative repository for recording configuration items (CIs) such as hardware assets, their serial numbers, locations, owners, relationships, and lifecycle states. It underpins ITIL/ITSM processes like change, incident, and asset management. Tracking hardware serial numbers and physical locations is a canonical CMDB use case.

Exam trap

SSCP often tests the confusion between a CMDB and a SIEM or vulnerability database — candidates must recognize that asset attributes like serial number and location belong to configuration/asset management, not security event or vulnerability tracking.

How to eliminate wrong answers

Option B is wrong because a patch management tool tracks patch status and software versions on endpoints, not comprehensive hardware asset attributes like serial numbers and physical locations. Option C is wrong because a vulnerability database (e.g., NVD) catalogs known CVEs and weaknesses, not an organization's own hardware inventory. Option D is wrong because a SIEM aggregates and correlates log and event data for security monitoring; it does not serve as the system of record for hardware assets.

783
MCQmedium

An organization wants to detect insider threats by identifying abnormal user behavior. Which technology is best suited for this purpose?

A.User Behavior Analytics (UBA)
B.Network-based IDS
C.Vulnerability scanner
D.Signature-based antivirus
AnswerA

UBA baselines each user's normal activity, then flags statistically significant deviations such as unusual access times, volumes or data transfers. This satisfies the requirement to identify abnormal user behaviour indicative of insider threat, which signature-based tools cannot detect.

Why this answer

User Behavior Analytics (UBA) is specifically designed to detect insider threats by establishing a baseline of normal user activity and then identifying anomalous deviations, such as unusual login times, abnormal data access patterns, or atypical file transfers. Unlike other security tools that rely on known signatures or network traffic patterns, UBA applies machine learning and statistical modeling to user-centric data (e.g., authentication logs, file system events, and endpoint activity) to uncover subtle, non-signature-based indicators of malicious insider behavior.

Exam trap

A common mistake is to choose Network-based IDS, but insider threats often involve legitimate credentials and non-malicious traffic, so a solution focused on user behavior (UBA) is required.

How to eliminate wrong answers

Option B is wrong because a Network-based IDS (Intrusion Detection System) monitors network traffic for known attack signatures or protocol anomalies, but it lacks the user-context and behavioral baseline needed to detect insider threats that do not generate malicious network packets (e.g., a user exfiltrating data via legitimate cloud storage). Option C is wrong because a vulnerability scanner identifies known software weaknesses (e.g., missing patches, misconfigurations) by comparing system states against a database of CVEs; it does not analyze user behavior or detect ongoing anomalous actions. Option D is wrong because signature-based antivirus relies on static file signatures and heuristics to detect known malware; it cannot identify abnormal user behavior such as a legitimate user accessing files outside their normal pattern or performing unauthorized privilege escalation.

784
Multi-Selecteasy

Which THREE of the following are standard phases of the incident response lifecycle?

Select 3 answers
A.Preparation
B.Containment, Eradication, and Recovery
C.Auditing
D.Budgeting
E.Detection and Analysis
AnswersA, B, E

Preparation is the first phase, involving planning and training.

Why this answer

Preparation is the foundational phase of the incident response lifecycle, as defined by NIST SP 800-61 Rev. 2. This phase involves establishing policies, creating incident response plans, forming a CSIRT, and provisioning tools (e.g., SIEM, forensic workstations) before any incident occurs. Without proper preparation, all subsequent phases are significantly less effective.

Exam trap

ISC2 often tests candidates by including plausible-sounding business or audit terms (like Auditing or Budgeting) as distractors, expecting test-takers to confuse supporting activities with formal lifecycle phases defined in NIST or SANS frameworks.

785
MCQeasy

A company is deploying a new wireless network and wants to ensure that only authorized devices can connect. The security team decides to use a method that requires a supplicant, authenticator, and authentication server. Which technology should be implemented?

A.WPA2-Enterprise
B.WEP with 802.1X
C.WPA2-Personal
D.MAC address filtering
AnswerA

WPA2-Enterprise implements IEEE 802.1X, which uses a supplicant on the client, an authenticator (the access point), and an authentication server (typically RADIUS). This allows for centralized authentication and per-user or per-device credentials, ensuring that only authorized devices can connect. It meets the requirement of using the three-party model and provides strong security for enterprise wireless networks.

Why this answer

WPA2-Enterprise uses IEEE 802.1X, which defines the supplicant (client), authenticator (access point), and authentication server (RADIUS). This architecture enables strong, centralized authentication, ensuring that only devices with valid credentials can join the network. The other options either lack the three-party model or rely on weak security mechanisms.

Exam trap

The trap here is equating any wireless security with the 802.1X framework, when in fact only WPA2-Enterprise (and WPA3-Enterprise) implements the supplicant-authenticator-authentication server model.

786
MCQhard

An organization uses a risk register to track identified risks. A risk owner reports that a mitigation control was implemented six months ago, but the residual risk rating has not been updated and no post-implementation review was performed. Which activity is MOST important for maintaining the integrity of the risk management process?

A.Transfer the risk to a third party through cyber insurance and remove the original mitigation control.
B.Escalate the risk to the board as an accepted risk without further analysis because the owner has already acted.
C.Close the risk entry because the mitigation control has been implemented and the risk is therefore eliminated.
D.Reassess the risk with the control in place, document the updated likelihood and impact, and adjust the residual risk rating accordingly.
AnswerD

Risk registers become unreliable when controls are recorded but their effect is never measured. Reassessing likelihood and impact with the control operating provides an evidence-based residual rating, confirms whether the treatment achieved its objective, and keeps decisions aligned with actual exposure. This is the core feedback loop of risk monitoring and analysis.

Why this answer

A risk register is only useful if it reflects current exposure. When a control is deployed, the risk must be reassessed to measure how much likelihood or impact it actually reduced, and the residual rating updated with evidence. This validation step closes the treatment loop and supports accurate reporting to management.

Exam trap

The trap here is treating implementation of a control as proof that the risk is resolved, skipping the reassessment that determines residual risk.

787
MCQeasy

A security team identifies a vulnerability in a web application that allows SQL injection. Which risk response strategy involves implementing input validation and parameterized queries to reduce the risk to an acceptable level?

A.Risk transfer
B.Risk mitigation
C.Risk acceptance
D.Risk avoidance
AnswerB

Input validation and parameterised queries remove the injection vector, so the SQL injection risk is reduced rather than transferred, avoided or accepted. Mitigation lowers likelihood or impact to a tolerable level, matching the stem's requirement to reduce risk to an acceptable level.

Why this answer

Risk mitigation involves applying controls to reduce the likelihood or impact of a risk to an acceptable level. Implementing input validation and parameterized queries directly addresses the SQL injection vulnerability by preventing malicious SQL from being executed, thereby reducing the risk without eliminating the application's functionality.

Exam trap

The SSCP exam often tests the distinction between risk mitigation (applying controls to reduce risk) and risk avoidance (eliminating the activity entirely), tricking candidates who think input validation removes the risk completely rather than reducing it to an acceptable level.

How to eliminate wrong answers

Option A is wrong because risk transfer shifts the financial burden of a loss to a third party (e.g., insurance), not the technical control of the vulnerability. Option C is wrong because risk acceptance means acknowledging the risk without taking action, which contradicts the active implementation of security controls. Option D is wrong because risk avoidance would require removing the vulnerable web application entirely or disabling the feature that allows user input, which is not the same as applying input validation and parameterized queries.

788
MCQeasy

A security administrator is reviewing the account lifecycle process for a large retail company. An employee in the accounting department has been promoted to a role in the same department that requires access to the payroll system, while the employee's previous duties no longer require access to the accounts payable system. Which action should the administrator take to ensure least privilege is maintained?

A.Modify the existing account to grant payroll access and remove the accounts payable access.
B.Disable the existing account and require the employee to request a new account through the help desk.
C.Create a new account for the payroll role and disable the old accounts payable account after 30 days.
D.Leave both sets of access in place so the employee can assist the accounting team during the transition.
AnswerA

Least privilege requires that an account hold only the access needed for current job duties. Since the employee remains with the company but changed roles, the existing identity should be retained and its entitlements adjusted by adding payroll access and removing accounts payable access. This keeps the account lifecycle accurate and prevents accumulation of unnecessary privileges.

Why this answer

Because the employee remains with the organization but changed job duties, the account should be modified to add the payroll entitlement and remove the accounts payable entitlement. This maintains least privilege, preserves the identity history, and avoids both account sprawl and lingering unnecessary access. The other choices either retain excessive rights, create redundant identities, or disrupt a current employee's access.

Exam trap

The trap here is assuming that a role change requires a new account or a full deprovisioning, when least privilege is achieved by adjusting entitlements on the existing identity.

789
MCQmedium

A security analyst is reviewing alerts and sees that a user's workstation has begun encrypting files with a new extension, and a ransom note has appeared on the desktop. The analyst confirms this is an active ransomware infection. According to NIST SP 800-61, which action should the analyst take FIRST during the containment phase?

A.Immediately disconnect the workstation from the network by unplugging the Ethernet cable or disabling Wi-Fi.
B.Shut down the workstation immediately to stop the encryption process.
C.Pay the ransom to obtain the decryption key and restore files quickly.
D.Run a full antivirus scan on the workstation to remove the ransomware.
AnswerA

Isolating the infected workstation from the network is the immediate priority in the containment phase to prevent the ransomware from spreading to shared drives and other systems. Disconnecting the network stops lateral movement and further encryption of network resources, while preserving the local state for later forensic analysis. This aligns with NIST SP 800-61 guidance to limit the scope and magnitude of the incident before proceeding with eradication and recovery.

Why this answer

During an active ransomware incident, the first containment action is to isolate the infected system from the network to prevent lateral spread and further encryption of shared resources. This aligns with NIST SP 800-61, which emphasizes limiting the scope of the incident before eradication and recovery. Disconnecting the network preserves volatile evidence while stopping the malware's communication and propagation.

Other actions like scanning, shutting down, or paying the ransom do not address immediate containment and may hinder forensic efforts.

Exam trap

The trap here is assuming that shutting down the machine or running antivirus is the fastest way to stop ransomware, when in fact network isolation must come first to prevent spread and preserve evidence.

790
Multi-Selectmedium

A security team is building a continuous monitoring program for a regulated environment. The compliance manager wants assurance that monitoring data is trustworthy and that deviations are detected promptly. Which THREE activities should be included in the monitoring program? (Choose three.)

Select 3 answers
A.Collecting and reviewing audit logs from critical systems on a defined schedule.
B.Reviewing the monitoring program's own controls and making improvements on a recurring cycle.
C.Archiving all monitoring data indefinitely without any review or analysis.
D.Establishing metrics and reporting thresholds that trigger escalation when exceeded.
E.Performing a full penetration test of every system on a weekly basis.
AnswersA, B, D

Scheduled collection and review of audit logs from critical systems is a core continuous monitoring activity because it provides evidence that controls are operating and reveals deviations such as failed logins, privilege changes, and configuration edits. Without a defined review cadence, logs accumulate unread and incidents go unnoticed. This activity directly supports both security detection and compliance evidence requirements.

Why this answer

Continuous monitoring depends on three reinforcing activities: scheduled collection and review of audit logs, defined metrics with escalation thresholds, and recurring evaluation of the program itself. Together they provide detection, measurable response criteria, and a feedback loop that keeps coverage current. Penetration testing is periodic validation rather than continuous monitoring, and indefinite archiving without analysis adds no detection capability.

Exam trap

The trap here is equating continuous monitoring with frequent one-time assessments such as penetration tests, or with simply storing data, rather than with ongoing review, measurement, and program improvement.

791
MCQmedium

An organization uses Kerberos for SSO. A user reports that after entering their password, they receive a 'ticket expired' error when trying to access a network share. The system administrator checks the Kerberos configuration. Which ticket is most likely expired?

A.Session key
B.Ticket-Granting Ticket (TGT)
C.Service ticket
D.Authentication Server (AS) reply
AnswerB

The Ticket-Granting Ticket is obtained at initial authentication and used to request service tickets. If it expires, subsequent access to the network share fails with a ticket expired error, matching the stem's symptom after password entry.

Why this answer

The Ticket-Granting Ticket (TGT) has a limited lifetime (typically 8-10 hours). When it expires, the user must re-authenticate to get a new TGT.

792
MCQeasy

Which of the following is the primary purpose of a risk register?

A.To record all security incidents after they occur
B.To track changes made to system configurations
C.To document and track identified risks and their treatment
D.To automatically detect vulnerabilities in the network
AnswerC

A risk register records each identified risk, its owner, score and chosen treatment, providing an auditable trail that supports tracking through to closure or acceptance. It is not a control catalogue or incident log; its purpose is documenting and monitoring risk treatment decisions over time.

Why this answer

The primary purpose of a risk register is to document and track identified risks along with their treatment plans, including risk owners, likelihood, impact, and mitigation status. This aligns with the Risk Identification, Monitoring and Analysis domain, where the risk register serves as a central repository for risk management activities throughout the system development life cycle.

Exam trap

The trap here is that candidates confuse the risk register with an incident log or vulnerability scanner output, but the risk register is specifically a forward-looking planning document for managing identified risks, not a reactive or automated detection tool.

How to eliminate wrong answers

Option A is wrong because a risk register is a proactive tool for documenting potential risks before they occur, not a reactive log for recording security incidents after they happen (incident response logs serve that purpose). Option B is wrong because tracking changes to system configurations is the function of a change management system or configuration management database (CMDB), not a risk register. Option D is wrong because automatic vulnerability detection is performed by vulnerability scanners (e.g., Nessus, OpenVAS) or SIEM tools, not by a risk register, which is a manual or semi-automated documentation and tracking artifact.

793
MCQmedium

A security analyst notices that a service account has been granted domain administrator privileges. Which principle of access control is being violated?

A.Need-to-know
B.Separation of duties
C.Least privilege
D.Accountability
AnswerC

Least privilege requires granting only the access needed to perform a role's duties. A service account holding domain administrator rights far exceeds its operational requirements, so the excessive privilege violates that principle, regardless of authentication or separation-of-duties controls.

Why this answer

Granting a service account domain administrator privileges violates the principle of least privilege, which states that accounts should have only the minimum permissions necessary to perform their required tasks. A service account typically needs limited, specific permissions, not full domain admin rights. This over-provisioning increases the attack surface and risk.

Exam trap

SSCP often tests the distinction between least privilege and need-to-know, causing candidates to choose need-to-know when the issue is excessive permissions rather than information access.

How to eliminate wrong answers

Option A is wrong because need-to-know is about limiting access to information based on job requirements, not about the level of privileges granted. Option B is wrong because separation of duties involves dividing tasks among multiple people to prevent fraud, which is not directly violated by granting excessive privileges to a single account. Option D is wrong because accountability refers to tracing actions to a specific individual, which is a logging/auditing concern, not the principle violated by excessive permissions.

794
MCQhard

An organization is implementing a password policy that requires passwords to be at least 12 characters, include uppercase, lowercase, digits, and special characters, and be changed every 90 days. Additionally, users cannot reuse any of the last 10 passwords. Which password policy element does the last requirement address?

A.Password expiry
B.Password length
C.Password history
D.Password complexity
AnswerC

Password history enforces the no-reuse constraint by storing hashes of prior passwords and rejecting any new one matching the last 10 entries. This directly satisfies the stem's requirement that users cannot reuse recent passwords, distinct from complexity, length, or expiry settings.

Why this answer

The requirement that users cannot reuse any of the last 10 passwords is specifically addressing password history, which prevents users from cycling back to previous passwords. This element enforces a memory of past passwords to avoid reuse.

Exam trap

The trap is confusing password history with password expiry or complexity; candidates might think 'cannot reuse' relates to expiry, but it's specifically about remembering past passwords.

How to eliminate wrong answers

Option A is wrong because password expiry refers to the maximum age of a password before it must be changed, such as the 90-day requirement. Option B is wrong because password length refers to the minimum number of characters, such as the 12-character requirement. Option D is wrong because password complexity refers to the mix of character types (uppercase, lowercase, digits, special characters).

795
MCQhard

A security analyst is investigating a potential attack on a network. The analyst observes a large number of ICMP echo request packets with spoofed source IP addresses being sent to a subnet's broadcast address. Many hosts on the subnet are replying, causing network congestion. Which type of attack is this?

A.Smurf attack
B.Ping of death
C.Fraggle attack
D.SYN flood
AnswerA

A Smurf attack involves sending ICMP echo requests to a broadcast address with a spoofed source IP (the victim's IP). All hosts on the subnet respond to the victim, amplifying the traffic and causing a denial of service. This matches the scenario exactly.

Why this answer

The Smurf attack uses ICMP echo requests sent to a broadcast address with a spoofed source IP. All hosts on the subnet reply to the spoofed victim, amplifying traffic and causing a denial of service. The scenario describes exactly this: ICMP echo requests to a broadcast address with spoofed source, causing many replies and congestion.

Exam trap

The trap here is mixing up Smurf and Fraggle attacks. Smurf uses ICMP, while Fraggle uses UDP. The scenario specifies ICMP, so Smurf is correct.

796
Multi-Selectmedium

A security auditor is reviewing the configuration of a remote access VPN. Which TWO features are considered best practices for securing the VPN connection?

Select 2 answers
A.Using IKEv2 with pre-shared keys only
B.Disabling encryption to reduce latency
C.Implementing multi-factor authentication (MFA)
D.Enabling split tunneling for all traffic to improve performance
E.Using TLS 1.3 with mandatory forward secrecy
AnswersC, E

Multi-factor authentication satisfies the auditor's requirement by adding a second verification factor beyond the password, defeating credential-stuffing and stolen-password attacks against the VPN gateway. Even if an attacker captures valid domain credentials, the missing second factor blocks authentication. Microsoft Entra ID Conditional Access can enforce MFA specifically for VPN sign-ins.

Why this answer

Option C is correct because implementing multi-factor authentication (MFA) ensures that even if a user's credentials are compromised, an additional verification factor (such as a TOTP code or hardware token) is required before the VPN tunnel is established, directly mitigating credential-based attacks. Option E is correct because TLS 1.3 with mandatory forward secrecy (using ephemeral key exchanges like ECDHE) ensures that session keys cannot be retroactively decrypted even if the server's long-term private key is later compromised, which is a recognized best practice for protecting VPN control and data channels. Option A is not a best practice because IKEv2 with pre-shared keys only lacks per-user authentication and scalability, and PSKs are vulnerable to offline dictionary attacks; certificate-based or EAP-based authentication is preferred.

Option B is incorrect because disabling encryption removes confidentiality and integrity protections, defeating the purpose of a VPN. Option D is incorrect because enabling split tunneling for all traffic can bypass corporate security controls (such as inspection and DLP) and expose the endpoint and internal network to threats, so it is not a security best practice.

Exam trap

The trap is selecting performance-oriented options (split tunneling, disabling encryption) as 'best practices'; the exam expects candidates to prioritize confidentiality and strong authentication over latency.

797
MCQmedium

A user claims to be 'jsmith' and provides a password. What is the term for the step where the system verifies that the password matches the one on file for 'jsmith'?

A.Authorization
B.Identification
C.Authentication
D.Accountability
AnswerC

Authentication is the process of verifying a claimed identity by checking the supplied credential against the stored one. Here, the system compares the password against the record for 'jsmith', confirming the user is who they claim to be. This directly satisfies the stem's requirement to verify the password matches the one on file.

Why this answer

Authentication is the process of verifying a claimed identity — here, validating that the password provided matches the stored credential for 'jsmith'. Identification is the act of claiming an identity (e.g., entering a username), while authentication proves it. The question explicitly describes verification of the password, which is authentication.

Exam trap

SSCP often tests the distinction between identification (claiming an identity) and authentication (proving it), and between authentication and authorization (what you can do), causing candidates to pick the wrong stage in the identity lifecycle.

How to eliminate wrong answers

Option A is wrong because authorization determines what an authenticated user is allowed to do (permissions, access rights), not whether the password is correct. Option B is wrong because identification is merely the claim of identity (e.g., typing 'jsmith'), which occurs before authentication and does not verify anything. Option D is wrong because accountability is the ability to trace actions to a specific user via logs and audit trails — it depends on authentication but is not the verification step itself.

798
Multi-Selectmedium

Which TWO of the following are characteristics of mandatory access control (MAC)?

Select 2 answers
A.The system enforces access decisions based on policies
B.Security labels are assigned to subjects and objects
C.Access decisions are based on the user’s discretion
D.It is commonly used in commercial environments
E.Users can grant access to other users
AnswersA, B

MAC decisions are enforced by the operating system against a central policy, not by object owners' discretion. The stem's policy-based enforcement is the defining characteristic: subjects cannot override or delegate access, distinguishing MAC from discretionary models.

Why this answer

Option A is correct because MAC is defined by policy-driven enforcement: the operating system or security kernel makes access decisions according to centrally administered rules (e.g., Bell-LaPadula or Biba models), not user choice. Option B is correct because MAC relies on security labels (sensitivity levels and categories) attached to both subjects and objects, and access is granted only when the subject's label dominates the object's label per the policy. Option C is incorrect because basing access on the user's discretion describes discretionary access control (DAC), where owners set permissions.

Option D is incorrect because MAC is most commonly associated with high-assurance government, military, and intelligence environments rather than typical commercial settings. Option E is incorrect because in MAC users cannot delegate or grant access to others; only the policy administrator can change labels and authorizations.

Exam trap

The trap here is that candidates often confuse MAC with DAC, mistakenly thinking that MAC allows users to set permissions or that it is common in commercial environments, when in fact MAC is policy-driven and used in high-security contexts.

799
MCQmedium

Refer to the exhibit. A security analyst reviews the firewall configuration for a Windows workstation on a private network. What is the MOST significant weakness?

A.Inbound connections are set to Block by default
B.Default outbound connections are set to Allow, potentially allowing malware to communicate out
C.The rule 'RDP (UDP-In)' is set to Block and enabled, which blocks legitimate RDP traffic
D.The rule 'File and Printer Sharing (Echo Req)' is disabled, preventing network discovery
AnswerB

Allowing all outbound traffic by default lets malware establish command-and-control channels and exfiltrate data without being blocked, since the firewall only inspects inbound connections. Restricting outbound to required destinations satisfies the least-permission constraint for egress.

Why this answer

The most significant weakness is that the firewall configuration allows all outbound connections by default. While blocking inbound traffic by default is a secure baseline, permitting unrestricted outbound traffic enables malware or unauthorized software to communicate with external command-and-control servers or exfiltrate data without restrictions. The other options are less impactful: default inbound block (A) is a security best practice; blocking RDP UDP-In traffic (C) is often intentional to prevent vulnerabilities; disabling File and Printer Sharing (D) actually reduces the attack surface.

Therefore, the default outbound allow (B) poses the greatest risk.

Exam trap

Trap: Candidates often focus on inbound rules or specific blocked ports, overlooking the broader risk of unrestricted outbound connections, which is a common weakness in default firewall configurations.

800
MCQhard

An organization uses role-based access control (RBAC). After a merger, a user account from the acquired company is migrated into the parent company's domain. The user is assigned to multiple roles, but is unable to access a critical application that requires a specific role. The administrator verified that the user's account is enabled and the application server is reachable. What is the MOST likely cause?

A.The user's group memberships are conflicting with the required role.
B.The user's account was not assigned the required role.
C.There is a firewall rule blocking traffic from the user's IP range.
D.The application's session timeout is set too low.
AnswerB

RBAC grants access solely through role membership, not account state or connectivity. Since the account is enabled and the server reachable, the missing required role assignment is the only remaining cause of the access denial.

Why this answer

In RBAC, access is granted based on the roles explicitly assigned to a user account. Since the administrator confirmed the account is enabled and the application server is reachable, the most likely cause is that the required role was not assigned to the migrated user. Without that role assignment, the user lacks the necessary permissions to access the critical application, regardless of other roles held.

Exam trap

The trap here is that candidates may assume group membership conflicts (Option A) cause access denial in RBAC, but RBAC roles are independent and additive—conflicts do not occur; the real issue is the missing role assignment.

How to eliminate wrong answers

Option A is wrong because RBAC does not have conflicting group memberships; roles are additive and do not conflict with each other—if the required role were assigned, access would be granted. Option C is wrong because the administrator verified the application server is reachable, which implies network connectivity is not blocked; a firewall rule would prevent reachability, not just application access. Option D is wrong because a low session timeout would cause the user to be logged out after inactivity, not prevent initial access to the application.

801
MCQhard

An organization implements a policy that the same individual cannot both create a purchase order and approve it in the financial system. Which security principle does this control primarily enforce?

A.Job rotation
B.Least privilege
C.Need-to-know
D.Separation of duties
AnswerD

Separation of duties splits a sensitive transaction across different people so no single individual controls it end to end. Preventing the same person from creating and approving a purchase order enforces exactly this, directly satisfying the stem's described policy control.

Why this answer

Separation of duties (SoD) is the security principle that prevents a single individual from performing conflicting tasks, such as creating and approving a purchase order. By splitting these responsibilities, the organization reduces the risk of fraud, errors, and unauthorized transactions, ensuring that no single person has unchecked control over a critical financial process.

Exam trap

The trap here is that candidates confuse separation of duties with least privilege, but least privilege only limits permissions to the minimum needed, whereas separation of duties specifically prevents a single user from executing two conflicting functions that could enable fraud or error.

How to eliminate wrong answers

Option A is wrong because job rotation is a practice where employees periodically switch roles to cross-train and reduce monotony, not a control that enforces dual-authority over a single transaction. Option B is wrong because least privilege limits users to only the permissions necessary for their job, but it does not inherently prevent the same person from both creating and approving a purchase order if both actions fall within their role. Option C is wrong because need-to-know restricts access to information based on job necessity, not the segregation of conflicting duties within a process.

802
MCQmedium

A vulnerability scan identifies a critical flaw in a web server. The server is currently in production and cannot be patched immediately due to compatibility issues. The risk response chosen is to implement a web application firewall (WAF) rule to block exploitation attempts. This is an example of which risk response?

A.Risk acceptance
B.Risk avoidance
C.Risk transfer
D.Risk mitigation
AnswerD

Deploying a WAF rule reduces the likelihood or impact of exploitation while the underlying flaw remains unpatched, so the risk is lowered rather than transferred, avoided or accepted. This directly satisfies the stem's constraint that patching is blocked by production compatibility issues.

Why this answer

Implementing a WAF rule to block exploitation attempts reduces the likelihood or impact of the vulnerability without removing the flaw itself. This is a classic risk mitigation technique, as it applies a compensating control to lower residual risk while the server remains unpatched. Risk mitigation involves taking action to reduce risk to an acceptable level, which is exactly what deploying a WAF signature achieves.

Exam trap

ISC2 often tests the distinction between risk mitigation and risk avoidance, where candidates mistakenly think that blocking exploitation attempts 'avoids' the risk, but avoidance requires eliminating the vulnerability entirely (e.g., removing the server), not just reducing its exploitability.

How to eliminate wrong answers

Option A is wrong because risk acceptance means acknowledging the risk and taking no action to reduce it, whereas a WAF rule is an active control. Option B is wrong because risk avoidance would require removing the vulnerable server from production or disabling the affected service entirely, not just blocking exploit attempts. Option C is wrong because risk transfer involves shifting the financial impact of a loss to a third party (e.g., insurance or outsourcing), not implementing a technical control like a WAF.

803
Multi-Selectmedium

An organization has suffered a ransomware attack that encrypted files on several file servers. The incident response team is planning recovery. Which TWO actions should be performed to verify that the restored systems are clean before returning them to production? (Select TWO)

Select 2 answers
A.Restore the systems from the most recent backup
B.Change all user passwords associated with the systems
C.Run a full antivirus and anti-malware scan on the restored systems
D.Apply all security patches to the operating system
E.Monitor the systems for any signs of reinfection or anomalous behavior for a period of time
AnswersC, E

Scanning restored systems with current antivirus and anti-malware signatures detects any residual malware, backdoors or dormant payloads the ransomware may have left behind. This directly satisfies the stem's requirement to verify systems are clean before returning them to production.

Why this answer

Option C is correct because running a full antivirus and anti-malware scan on the restored systems is a direct verification step that checks the restored data and OS for any residual malware, ransomware payloads, or infected files before the systems are trusted again. Option E is correct because monitoring the restored systems for reinfection or anomalous behavior over a period of time provides ongoing validation that no dormant persistence mechanisms, scheduled tasks, or command-and-control callbacks survived the recovery process. Option A is not a verification action; restoring from the most recent backup is a recovery step, and that backup itself may contain the ransomware or an earlier compromise.

Option B does not verify system cleanliness; changing user passwords is a containment/credential-hygiene measure and does nothing to detect malware on the restored hosts. Option D is also not a verification step; applying OS security patches remediates known vulnerabilities but does not confirm that the restored systems are free of the ransomware or other malware.

Exam trap

The trap here is that candidates often assume restoring from a clean backup (Option A) is sufficient to guarantee a clean system, but the SSCP exam emphasizes that backups must be verified as malware-free and that additional validation steps (scanning and monitoring) are required before returning systems to production.

804
MCQeasy

Which of the following is the PRIMARY purpose of implementing a clean desk policy?

A.To lower office cleaning costs
B.To comply with fire safety regulations
C.To reduce the risk of data breaches
D.To improve employee productivity
AnswerC

Unattended documents, unlocked screens and exposed media let anyone with physical access copy or photograph sensitive data. A clean desk policy removes that opportunistic exposure, directly lowering the likelihood of a data breach rather than merely improving tidiness or audit compliance.

Why this answer

A clean desk policy is a physical security control designed to prevent unauthorized access to sensitive information by ensuring that documents, devices, and media are securely stored when not in use. By reducing the visibility of confidential data, it directly mitigates the risk of data breaches from shoulder surfing, theft, or accidental exposure. This aligns with the principle of least exposure and supports compliance with data protection frameworks like GDPR or HIPAA.

Exam trap

The trap here is that candidates confuse a clean desk policy with general workplace organization or fire safety, overlooking its core role as a physical security control to protect confidential data from unauthorized access.

How to eliminate wrong answers

Option A is wrong because a clean desk policy does not target cleaning costs; it is a security measure, not a housekeeping budget control. Option B is wrong because while a clean desk may indirectly reduce fire hazards by clearing clutter, fire safety regulations are primarily addressed by fire codes, extinguisher placement, and egress paths, not by a policy focused on information security. Option D is wrong because although a tidy workspace can boost morale, the primary purpose of a clean desk policy is security, not productivity improvement.

805
MCQmedium

A security analyst reviews the exhibit. The internal IP 10.0.0.1 is a web server, and 203.0.113.5 is an external IP. What is the most likely issue?

A.The web server may be exfiltrating data to an external host
B.The external IP is scanning the web server for vulnerabilities
C.The web server is experiencing a DDoS attack from the external IP
D.An internal user is browsing a malicious website
AnswerA

Internal RFC 1918 address 10.0.0.1 initiating outbound sessions to public 203.0.113.5 indicates a web server communicating with an external host, consistent with command-and-control or data exfiltration traffic crossing the perimeter. The private-to-public direction satisfies the stem's internal/external constraint, making exfiltration the most likely issue.

Why this answer

The exhibit shows a high volume of outbound traffic from internal IP 10.0.0.1 (the web server) to external IP 203.0.113.5 on port 443 (HTTPS). This pattern is consistent with data exfiltration, where a compromised web server sends sensitive data to an external command-and-control (C2) server. The traffic is initiated by the internal server, not inbound, which rules out scanning or DDoS attacks.

Exam trap

The trap here is that candidates confuse the direction of traffic—assuming any external IP communicating with a web server must be an attacker scanning or attacking, rather than recognizing that the server itself may be the compromised source of outbound data.

How to eliminate wrong answers

Option B is wrong because vulnerability scanning typically involves inbound probes (e.g., SYN scans) from the external IP to the web server, not sustained outbound data flows. Option C is wrong because a DDoS attack would show a flood of inbound traffic from many sources, not a single external IP sending or receiving a steady outbound stream. Option D is wrong because an internal user browsing a malicious website would generate outbound traffic from a client workstation, not from a web server IP like 10.0.0.1.

806
MCQeasy

A company has 200 employees using a Windows Active Directory environment. The security administrator receives multiple alerts that user accounts are being locked out every 15 minutes. The help desk confirms that users who report the issue are able to log in successfully after unlocking their accounts, but they get locked out again shortly after. The administrator checks the domain controller security logs and sees many failed logon attempts with a specific service account name 'svc_backup' from multiple workstations. The svc_backup account is used for a backup application that runs scheduled tasks. What should the administrator do to resolve the issue?

A.Disable the svc_backup account until the backup vendor releases a patch
B.Change the password for svc_backup and update the backup application with the new password
C.Create a new service account with a different name and grant it the same permissions
D.Increase the account lockout threshold to prevent lockouts
AnswerB

The svc_backup account's stored password no longer matches the domain, so the backup application's scheduled tasks repeatedly authenticate with stale credentials, triggering lockouts. Updating the password and reconfiguring the application restores successful authentication and stops the failed logon attempts.

Why this answer

Changing the password for svc_backup and updating the backup application with the new password is correct because the symptom pattern — repeated lockouts every 15 minutes from multiple workstations with failed logons for a single service account — is the classic signature of a stale cached credential. The backup application (or a scheduled task) is still presenting the old password, and each retry trips the domain account lockout threshold. Updating the credential in the application (and any dependent scheduled tasks/services) stops the failed attempts at the source.

Exam trap

SSCP often tests whether candidates chase the symptom (lockouts) rather than the root cause (stale cached credential), so the trap is selecting a mitigation that weakens policy or disables the account instead of fixing the credential.

How to eliminate wrong answers

Option A is wrong because disabling the account halts backups entirely, causing a data-protection gap, and it does not address the root cause — the stale credential will still be presented once the account is re-enabled. Option C is wrong because creating a new service account with the same permissions simply reproduces the same problem unless the credential is correctly synchronized with the application, and it adds unnecessary identity sprawl. Option D is wrong because raising the lockout threshold weakens security (making brute-force attacks easier) and only masks the symptom — the failed logons would continue, just without locking the account.

807
Multi-Selecthard

A security administrator is reviewing a network diagram and identifies several controls intended to reduce the attack surface of a demilitarized zone (DMZ). Which TWO controls best limit the impact of a compromised DMZ host on the internal network? (Choose two.)

Select 2 answers
A.Enable promiscuous mode on the DMZ switch ports so that monitoring tools can capture all traffic.
B.Deploy the DMZ on the same VLAN as internal servers to simplify administration and monitoring.
C.Enforce strict firewall rules that permit only required outbound flows from the DMZ to specific internal hosts and ports.
D.Use a separate network segment with a firewall between the DMZ and the internal network, and require authentication for any DMZ-to-internal connection.
E.Allow all outbound traffic from the DMZ to any destination so that services can reach update servers without interference.
AnswersC, D

Egress filtering from the DMZ prevents a compromised host from freely reaching internal systems, so an attacker cannot pivot broadly. By allowing only the specific internal destinations and ports that the service legitimately needs, the administrator contains the blast radius. This is a core principle of DMZ design and directly limits lateral movement.

Why this answer

Limiting the impact of a compromised DMZ host depends on restricting what that host can reach. Strict egress rules from the DMZ and a separate firewall with authentication for DMZ-to-internal connections both enforce least privilege at the boundary. Sharing a VLAN with internal servers or allowing unrestricted egress removes containment, and promiscuous mode on production ports increases exposure rather than reducing it.

Exam trap

The trap here is treating monitoring or administrative convenience features, such as promiscuous mode or a shared VLAN, as security controls when they actually widen the attack surface.

808
MCQmedium

A healthcare organization's incident response team has just contained a ransomware outbreak that encrypted several file servers. Before restoring from backups, the incident response manager wants to ensure that the team can determine exactly how the attacker initially gained access and what data was exfiltrated. The organization does not have a dedicated forensic imaging solution, but the servers are still powered on and running. Which of the following actions BEST supports the investigation while preserving evidence?

A.Run a full antivirus scan on each server and quarantine any detected malware, then review the scan reports.
B.Immediately power off the servers to prevent further encryption, then remove the hard drives for later analysis.
C.Capture a memory image and relevant logs from the running servers, then isolate them from the network before restoration.
D.Restore the servers from the most recent backup immediately, then review backup logs to identify the initial compromise.
AnswerC

Capturing volatile data like memory and logs while the systems are still running preserves critical evidence about the attacker's tools, credentials, and network connections. Isolating the servers prevents further damage without destroying evidence. This approach aligns with incident response best practices by balancing containment and forensic preservation, enabling the team to determine initial access and exfiltration methods before restoring from backups.

Why this answer

The best action is to capture volatile evidence such as memory and logs from the running servers before isolating them. This preserves critical artifacts that reveal the attacker's methods and data exfiltration while preventing further damage. Restoring from backup or powering off the servers would destroy evidence, and antivirus scanning could alter the compromised state, undermining the investigation's goals.

Exam trap

The trap here is assuming that containment always requires immediately powering off or restoring systems, which destroys volatile evidence needed to determine the root cause and scope of the incident.

809
Multi-Selectmedium

An organization is designing network segmentation to protect sensitive data. Which TWO of the following are effective methods for implementing network segmentation?

Select 2 answers
A.Honeypots
B.NAT
C.Firewalls
D.Port security
E.VLANs
AnswersC, E

Firewalls enforce segmentation by inspecting traffic and permitting or denying flows between network zones according to rule sets, so sensitive-data segments stay isolated from untrusted areas. They satisfy the stem's requirement for an effective segmentation method by providing policy-based control at zone boundaries.

Why this answer

Firewalls (C) are a core segmentation control because they enforce policy between zones—filtering traffic by IP address, port, and protocol (e.g., allowing only TCP 443 from a DMZ to an internal subnet)—thereby restricting lateral movement toward sensitive data. VLANs (E) segment a switched network at Layer 2 by logically isolating broadcast domains, so hosts in different VLANs cannot communicate directly without a Layer 3 device, which is a standard way to separate sensitive systems from general user traffic. Honeypots (A) are deception/detection decoys, not segmentation mechanisms, since they attract and log attackers rather than partition traffic.

NAT (B) translates addresses (e.g., private RFC 1918 to public) for connectivity and concealment, but it does not by itself enforce segmentation between internal zones. Port security (D) limits which MAC addresses may use a switch port to prevent unauthorized devices or MAC flooding, but it does not create separate network segments or control inter-zone traffic.

Exam trap

The trap is selecting port security or NAT as segmentation methods — port security is port-level access control, and NAT is address translation, neither of which segments networks or enforces inter-segment policy.

810
Drag & Dropmedium

Drag and drop the steps for a typical TLS 1.3 handshake into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

TLS 1.3 reduces round trips: ClientHello, ServerHello, EncryptedExtensions, Finished from server, Finished from client.

811
Multi-Selectmedium

Which TWO of the following are essential components of a secure configuration baseline for a new server deployment?

Select 2 answers
A.Disable all unnecessary services and ports
B.Apply the latest security patches to the operating system
C.Enable only error logging, not audit logging
D.Assign the same strong password to all local accounts
E.Use default passwords for all service accounts
AnswersA, B

Disabling unnecessary services and ports reduces the attack surface by removing exploitable daemons and listening sockets from the new server. This satisfies the stem's requirement for an essential secure configuration baseline component, since unused services are a primary initial-access vector.

Why this answer

Option A is correct because a secure configuration baseline must minimize the attack surface by disabling all unnecessary services and closing unused ports, following the principle of least functionality. Option B is correct because applying the latest security patches to the operating system remediates known vulnerabilities before the server is exposed to production traffic. Option C is incorrect because a secure baseline requires comprehensive audit logging, not just error logging, to support detection and forensic analysis.

Option D is incorrect because assigning the same strong password to all local accounts violates the principle of unique credentials and enables lateral movement if one account is compromised. Option E is incorrect because default passwords for service accounts are publicly known and must be changed or replaced with strong, unique credentials.

812
MCQeasy

Which of the following is the correct order of the access control process?

A.Identification, authentication, authorization, accountability
B.Identification, authorization, authentication, accountability
C.Authorization, authentication, identification, accountability
D.Authentication, identification, authorization, accountability
AnswerA

Access control proceeds by first claiming an identity, then proving it, then granting rights, then logging activity. Accountability depends on the prior identification and authentication steps, so this sequence reflects the actual dependency chain rather than any reordering of the four stages.

Why this answer

The access control process begins with identification, where a subject claims an identity (e.g., username). Next is authentication, verifying that identity (e.g., password). Then authorization determines what resources the authenticated subject can access.

Finally, accountability involves logging and auditing actions to hold the subject responsible. This sequence is fundamental in security models.

Exam trap

The trap is mixing up the order of authentication and authorization; candidates might think authorization comes before authentication, but you cannot authorize an unauthenticated identity.

How to eliminate wrong answers

Option B is wrong because authorization cannot occur before authentication; you must verify identity before granting access. Option C is wrong because authorization and authentication are reversed; identification must come first. Option D is wrong because authentication cannot precede identification; you need to claim an identity before verifying it.

813
MCQmedium

A company is deploying a VPN that uses IPsec in tunnel mode. The security engineer must choose a key exchange method that provides perfect forward secrecy (PFS) so that compromise of a long-term key does not expose past session keys. Which configuration should the engineer select?

A.Use static keying with manually configured security associations and AES-256.
B.Use IKEv2 with a Diffie-Hellman group for the IKE SA and a separate Diffie-Hellman group for the CHILD_SA.
C.Use IKEv2 with RSA signatures for authentication and no additional Diffie-Hellman exchange after the initial IKE SA.
D.Use IKEv1 in main mode with pre-shared keys and no DH group for the quick mode.
AnswerB

Perfect forward secrecy is achieved when each session key is derived from a fresh Diffie-Hellman exchange rather than from a long-term key. In IKEv2, using a DH group for the IKE SA and a distinct DH group for the CHILD_SA ensures that compromise of the IKE SA key does not compromise the IPsec session keys. This provides the required PFS.

Why this answer

Perfect forward secrecy requires that each IPsec session key be derived from a fresh, ephemeral Diffie-Hellman exchange. In IKEv2, configuring separate DH groups for the IKE SA and the CHILD_SA ensures that even if the IKE SA key is compromised, past and future child session keys remain protected. Static keys and configurations without a child DH exchange do not provide this property.

Exam trap

The trap here is assuming that using strong authentication or a strong cipher automatically provides perfect forward secrecy, when PFS specifically requires an ephemeral Diffie-Hellman exchange for each session.

814
MCQmedium

A healthcare organization must enforce access control based on a combination of the user's assigned department, the classification of the data being accessed, and the time of day. Users in the cardiology department may view patient records only during their scheduled shift, and only if the record belongs to a patient currently admitted to cardiology. Which access control model BEST supports these requirements?

A.Role-Based Access Control (RBAC)
B.Attribute-Based Access Control (ABAC)
C.Discretionary Access Control (DAC)
D.Mandatory Access Control (MAC)
AnswerB

ABAC evaluates attributes of the subject, object, action, and environment, which maps directly to department, data classification, time of day, and patient admission status. Policies written as boolean rules can require all conditions to be true before granting access, delivering the fine-grained, context-aware decisions this scenario demands. This makes ABAC the appropriate model for combining multiple dynamic factors into one authorization decision.

Why this answer

Attribute-Based Access Control is designed for policy decisions that combine multiple characteristics of the user, the resource, and the environment. Department, data classification, shift time, and a patient's current admission status are all attributes that can be evaluated in a single rule, so access is granted only when every condition is satisfied. The other models rely on ownership, static labels, or roles that cannot express these dynamic, contextual constraints together.

Exam trap

The trap here is assuming that role membership alone is sufficient for context-sensitive access, when in fact temporal and data-context conditions require attribute-based evaluation.

815
MCQhard

An organization's risk register shows a high risk for phishing attacks. Which controls are considered detective controls for this risk?

A.Security awareness training.
B.Email filtering.
C.User reporting mechanism.
D.Multi-factor authentication.
AnswerC

A user reporting mechanism detects phishing attempts when recipients flag suspicious emails, enabling the security team to investigate and respond. It satisfies the scenario's need for a detective control by identifying incidents that bypass preventive filters, rather than blocking them outright. Reporting provides the visibility required to confirm an active phishing campaign.

Why this answer

A user reporting mechanism is a detective control because it enables users to identify and report suspected phishing emails after they have been received, allowing the security team to investigate and respond. Unlike preventive controls that block attacks, detective controls discover incidents that have already occurred, such as a user recognizing a malicious link or attachment in their inbox.

Exam trap

ISC2 often tests the distinction between preventive and detective controls, and the trap here is that candidates confuse 'user reporting' as a reactive or corrective control rather than recognizing it as a detective control that identifies an ongoing or past incident.

How to eliminate wrong answers

Option A is wrong because security awareness training is a preventive/deterrent control that educates users to avoid falling for phishing, not a control that detects attacks after they occur. Option B is wrong because email filtering is a preventive control that blocks phishing emails before they reach the user's inbox, not a detective measure that identifies incidents post-delivery. Option D is wrong because multi-factor authentication is a preventive control that protects accounts even if credentials are compromised, not a detective control that identifies phishing attempts or compromises.

816
MCQhard

A security engineer is hardening a data center network against VLAN hopping attacks. The core switches currently use 802.1Q trunking on all inter-switch links, and unused access ports are left in the default VLAN. Which configuration change best mitigates VLAN hopping while preserving legitimate trunk operation?

A.Disable Dynamic Trunking Protocol (DTP) on all access ports and place unused ports in an unused VLAN.
B.Change all access ports to trunk ports and enable Dynamic Trunking Protocol (DTP) negotiation.
C.Enable BPDU Guard and Root Guard on all trunk ports to block VLAN hopping frames.
D.Configure all inter-switch links as access ports in VLAN 1 to simplify the topology.
AnswerA

Disabling DTP prevents an attacker from negotiating a trunk on an access port, and moving unused ports out of the default VLAN removes a common double-tagging target. This preserves legitimate trunks on trusted links while closing the two main VLAN hopping vectors: switch spoofing and double tagging against the native VLAN.

Why this answer

VLAN hopping typically relies on DTP negotiation on an access port or on double tagging through the native VLAN. Disabling DTP on access ports stops an attacker from forming a trunk, and moving unused ports to an unused VLAN removes an easy double-tagging target. Legitimate trunks remain functional on trusted inter-switch links, so segmentation is preserved while the attack surface is reduced.

Exam trap

The trap here is assuming that Spanning Tree protection features such as BPDU Guard or Root Guard also prevent VLAN hopping, when they actually address a different attack class.

817
MCQeasy

A network technician needs to ensure that only authorized DHCP servers can assign IP addresses on the network. Which switch feature should be enabled?

A.DHCP snooping
B.Dynamic ARP Inspection
C.Port security
D.BPDU guard
AnswerA

DHCP snooping classifies switch ports as trusted or untrusted, permitting DHCP server replies only via trusted ports. Rogue or unauthorised DHCP servers on untrusted ports are blocked, satisfying the requirement that only authorised servers assign addresses.

Why this answer

DHCP snooping is a security feature that filters untrusted DHCP messages and builds a DHCP snooping binding database by monitoring DHCP traffic on untrusted ports. By enabling DHCP snooping on the switch, only DHCP servers connected to trusted ports can assign IP addresses, preventing rogue DHCP server attacks.

Exam trap

ISC2 often tests DHCP snooping by confusing it with Dynamic ARP Inspection, but the key distinction is that DHCP snooping directly controls DHCP server messages, while DAI relies on the snooping database to validate ARP traffic.

How to eliminate wrong answers

Option B (Dynamic ARP Inspection) is wrong because it validates ARP packets using the DHCP snooping binding table to prevent ARP spoofing, not to control which DHCP servers can assign IP addresses. Option C (Port security) is wrong because it limits the number of MAC addresses allowed on a switch port to prevent MAC flooding, not to authorize DHCP servers. Option D (BPDU guard) is wrong because it protects spanning tree protocol by disabling ports that receive BPDUs, which is unrelated to DHCP server authorization.

818
MCQhard

Refer to the exhibit. A systems administrator configures this Group Policy setting. What is the direct consequence?

A.Members of Backup Operators cannot connect to the server using Remote Desktop.
B.Members of Backup Operators are prohibited from local console logon.
C.Members of Backup Operators can connect via Remote Desktop.
D.Members of Backup Operators are prevented from using any remote access method.
AnswerA

The Group Policy setting "Deny log on through Remote Desktop Services" explicitly removes the Remote Desktop logon right from the named accounts or groups. Adding Backup Operators to this policy therefore blocks those members from establishing RDP sessions, directly satisfying the exhibit's configured restriction.

Why this answer

The 'Deny log on through Remote Desktop Services' policy explicitly prevents members of Backup Operators from using Remote Desktop. Therefore, they cannot connect via RDP, making Option A correct. Option B is incorrect because the policy only affects Remote Desktop, not local console logon.

Option C is incorrect because the policy denies, not allows. Option D is incorrect because it does not affect other remote access methods like SSH unless specifically configured.

819
MCQmedium

Which access control model allows the owner of a resource to determine who can access it and what permissions they have?

A.Mandatory Access Control (MAC)
B.Discretionary Access Control (DAC)
C.Attribute-Based Access Control (ABAC)
D.Role-Based Access Control (RBAC)
AnswerB

DAC grants the resource owner discretion over access decisions, so they assign permissions directly to other subjects. This owner-controlled permission assignment is precisely the mechanism the stem requires, distinguishing DAC from mandatory and role-based models where policy or roles dictate access.

Why this answer

Discretionary Access Control (DAC) gives resource owners discretion to grant or deny access to others.

820
MCQeasy

A security analyst is reviewing authentication logs and notices that a user account was used to log in from two different geographic locations within a five-minute window. The organization uses a centralized RADIUS server for authentication. Which of the following should the analyst investigate FIRST to determine if this is a legitimate concurrent session or a compromise?

A.Examine the firewall rules governing RADIUS traffic.
B.Check the user's group membership in Active Directory.
C.Review the user's password complexity policy.
D.Check the RADIUS server's accounting logs for session start and stop records.
AnswerD

RADIUS accounting logs record session start and stop times, as well as the network access server and assigned IP address. Reviewing these logs first can reveal whether two simultaneous sessions were actually established and from which devices. This directly addresses whether the logins are concurrent and helps distinguish a legitimate session from credential theft.

Why this answer

RADIUS accounting logs provide session start and stop records, including the network access server and assigned IP address. These details allow the analyst to verify whether two sessions were truly concurrent and from which locations. Other options relate to policy or authorization and do not provide session-specific evidence needed to investigate the suspicious logins.

Exam trap

The trap here is focusing on password or group policy instead of session accounting data, which is the only source that can confirm concurrent logins.

821
MCQmedium

A system administrator is configuring a file encryption solution for a shared network drive. The solution must allow multiple users to read the files without sharing a single symmetric key. Which approach should be used?

A.Use a different symmetric key for each user and re-encrypt the file for each user
B.Encrypt the file with each user's public key directly
C.Encrypt the file with a symmetric key, then encrypt that key with each authorized user's public key
D.Encrypt the file with a single symmetric key and share that key securely with all users
AnswerC

Hybrid encryption solves the multi-user key distribution constraint: the file's symmetric key is wrapped individually with each authorised user's public key, so any of them can unwrap it with their private key. No shared symmetric secret is required, preserving confidentiality and access control.

Why this answer

Describes hybrid encryption, which is the correct approach for this scenario. The file is encrypted with a random symmetric key (session key) for efficiency, and that symmetric key is then encrypted with each authorized user's public key. This allows multiple users to decrypt the symmetric key with their private key and then decrypt the file, without sharing a single symmetric key.

Exam trap

The trap here is that candidates may choose Option B (direct public key encryption) because they understand asymmetric encryption but overlook the performance and practical limitations of encrypting large files with public key algorithms, which are designed for small data like keys.

How to eliminate wrong answers

Option A is wrong because re-encrypting the entire file for each user with a different symmetric key is computationally expensive and does not scale; it also requires managing multiple encrypted copies. Option B is wrong because directly encrypting the file with each user's public key would require encrypting the entire file multiple times, which is inefficient for large files and does not leverage symmetric key performance. Option D is wrong because sharing a single symmetric key with all users violates the requirement of not sharing a single symmetric key and introduces a single point of compromise.

822
MCQmedium

A security analyst at a financial firm is reviewing the risk register and notes that the firm has purchased a cyber insurance policy to cover losses from a data breach. In risk management terms, which of the following best describes this action?

A.Risk transference
B.Risk mitigation
C.Risk avoidance
D.Risk acceptance
AnswerA

Risk transference shifts the financial impact of a risk to a third party, typically through insurance or contractual agreements. By purchasing cyber insurance, the firm transfers the monetary loss from a breach to the insurer while still retaining the operational and reputational risk. This matches the scenario precisely, as the firm is not reducing the likelihood but is offsetting the financial burden.

Why this answer

Risk transference is the correct classification because cyber insurance shifts the financial consequences of a data breach to an external insurer. The organization still owns the risk operationally, but the monetary impact is contractually borne by another party. This is a standard risk treatment option alongside avoidance, mitigation, and acceptance, and it is commonly used for low-frequency, high-impact events such as major data breaches.

Exam trap

The trap here is assuming that buying insurance reduces the likelihood or impact of a breach rather than simply transferring the financial loss.

823
MCQmedium

A company implements mandatory access control (MAC) on its classified document system. A user with a security clearance of Secret attempts to read a document labeled Top Secret. What happens?

A.The user is prompted to request a temporary upgrade
B.The access is denied by the system
C.The document is downgraded to Secret for the user
D.The user can read the document because they have a valid clearance
AnswerB

Under mandatory access control, the system compares the document's classification label with the user's clearance and enforces the no-read-up rule. Secret clearance cannot read Top Secret, so the reference monitor denies access regardless of the user's need or intent.

Why this answer

In a mandatory access control (MAC) system, access decisions are based on comparing the user's security clearance (Secret) with the document's classification label (Top Secret). Since the clearance level is lower than the document's classification, the system automatically denies the read operation. This is a fundamental property of MAC, where the system enforces the Bell-LaPadula model's simple security property (no read up).

Exam trap

The trap here is that candidates confuse MAC with discretionary access control (DAC), where a user might be able to request temporary access or have permissions changed by the owner, but in MAC, all access decisions are system-enforced and cannot be overridden by users.

How to eliminate wrong answers

Option A is wrong because MAC does not support user-initiated temporary upgrades; clearance changes require administrative action and are not prompted by the system. Option C is wrong because MAC never automatically downgrades a document's classification label to match a user's clearance; labels are immutable and set by the security administrator. Option D is wrong because having a valid clearance is insufficient; the clearance must equal or exceed the document's classification level for read access.

824
MCQhard

A security professional is designing a key management system and needs to ensure that keys are generated using a truly random source. Which of the following is the most appropriate method for generating cryptographic keys?

A.Hardware random number generator
B.Cryptographically secure PRNG seeded with a static password
C.Pseudorandom number generator (PRNG) seeded with current timestamp
D.User-memorized passphrase
AnswerA

A hardware random number generator derives entropy from physical phenomena, producing non-deterministic output. Software generators are deterministic algorithms, so only a hardware source satisfies the requirement for a truly random seed for cryptographic key generation.

Why this answer

A hardware random number generator (HRNG) uses a physical entropy source (e.g., thermal noise, quantum effects) to produce truly random numbers, making it the most appropriate for generating cryptographic keys. Cryptographic keys require high entropy and unpredictability; HRNGs provide true randomness, unlike deterministic PRNGs.

Exam trap

SSCP often tests the difference between true random and pseudorandom sources — candidates pick a PRNG seeded with a timestamp or password because it sounds random, but cryptographic keys require a truly random source like a hardware RNG.

How to eliminate wrong answers

Option B is wrong because a cryptographically secure PRNG seeded with a static password is deterministic and the static password is a weak, low-entropy seed, making keys predictable. Option C is wrong because a PRNG seeded with the current timestamp is predictable (timestamps are guessable) and not cryptographically secure. Option D is wrong because a user-memorized passphrase is low-entropy and subject to dictionary attacks; it is not a random source.

825
Multi-Selectmedium

Which TWO of the following are primary purposes of a risk register?

Select 2 answers
A.Track the status of risk treatment plans
B.Document identified risks and their characteristics
C.Record network traffic logs
D.Store vulnerability scan results
E.Provide a checklist for compliance audits
AnswersA, B

Beyond initial documentation, the register is maintained to track each risk treatment plan's progress, status and residual risk. This ongoing tracking satisfies the stem's requirement, ensuring treatments are actioned and monitored rather than merely listed.

Why this answer

A risk register is a living document used to track the status of risk treatment plans, including whether controls have been implemented, are in progress, or are overdue. This ensures that risk owners are accountable and that residual risk is managed over time. Option B is correct because the primary function of a risk register is to document identified risks along with their characteristics, such as probability, impact, risk score, and owner.

These two functions are core to the risk management process as defined by frameworks like NIST SP 800-37 and ISO 31000.

Exam trap

The trap here is that candidates confuse the risk register with operational security tools like vulnerability scanners or log management systems, leading them to select options that describe technical data storage rather than the risk management documentation and tracking functions.

Page 10

Page 11 of 13

Page 12