Courseiva

Systems Security Certified Practitioner SSCP (SSCP) — Questions 826–900

971 questions total · 13pages · All types, answers revealed

Page 11

Page 12 of 13

Page 13
826
MCQeasy

An organization wants to allow secure remote access for employees. Which protocol is most appropriate for a site-to-site VPN?

A.PPTP
B.SSL/TLS
C.IPsec
D.SSH
E.L2TP
AnswerC

IPsec operates at the network layer, authenticating and encrypting every packet between gateways. This provides the confidentiality and integrity a site-to-site VPN requires across untrusted networks, unlike TLS, which secures individual application sessions rather than gateway-to-gateway tunnels.

Why this answer

IPsec is the correct choice for a site-to-site VPN because it operates at the network layer (Layer 3), providing encryption and authentication for all IP traffic between two entire networks. It supports both tunnel and transport modes, and uses protocols like ESP (Encapsulating Security Payload) and AH (Authentication Header) to ensure confidentiality, integrity, and origin authentication, making it the standard for permanent site-to-site connections.

Exam trap

The trap here is that candidates often confuse SSL/TLS with site-to-site VPNs because of its common use in remote access VPNs (e.g., AnyConnect), but SSL/TLS is a transport-layer protocol designed for client-to-server connections, not for routing entire network segments.

How to eliminate wrong answers

Option A (PPTP) is wrong because it uses outdated MPPE encryption and relies on PPP authentication, which has known security vulnerabilities (e.g., MS-CHAPv2 cracking) and is not suitable for secure site-to-site VPNs. Option B (SSL/TLS) is wrong because it operates at the transport layer (Layer 4) and is designed for client-to-site remote access VPNs (e.g., OpenVPN or AnyConnect), not for routing traffic between two entire networks. Option D (SSH) is wrong because it is a protocol for secure remote command-line access and port forwarding (tunneling individual TCP connections), not for encapsulating entire IP networks.

Option E (L2TP) is wrong because it is a tunneling protocol that provides no encryption by itself (RFC 2661); it is typically paired with IPsec (L2TP/IPsec) for security, but alone it is not appropriate for a secure site-to-site VPN.

827
Multi-Selecthard

A security analyst is reviewing a web application for OWASP Top 10 vulnerabilities. Which THREE of the following are examples of injection flaws?

Select 3 answers
A.SQL injection
B.LDAP injection
C.Broken authentication
D.OS command injection
E.Cross-Site Scripting (XSS)
AnswersA, B, D

SQL injection inserts malicious SQL statements through unsanitised input fields, tricking the database interpreter into executing attacker-controlled queries. It is a canonical injection flaw because untrusted data crosses into an interpreter without proper separation, matching the OWASP Top 10 category.

Why this answer

SQL injection (A) is a classic injection flaw where untrusted input is concatenated into SQL statements, allowing an attacker to alter query logic and manipulate the database. LDAP injection (B) is also an injection flaw because unsanitized input inserted into LDAP filters or queries can modify directory lookups and bypass authentication or expose directory data. OS command injection (D) occurs when user input is passed to a shell or system call, letting an attacker execute arbitrary operating-system commands on the server.

Broken authentication (C) is a separate OWASP category involving weaknesses in session management, credential handling, or authentication logic, not an injection flaw. Cross-Site Scripting (E) is typically classified under injection-like client-side flaws or its own category, but in the OWASP Top 10 it is not grouped as an injection flaw in the same sense as SQL, LDAP, or OS command injection.

Exam trap

SSCP often tests whether candidates lump XSS into the injection category — XSS is injection-adjacent but OWASP lists it separately, so selecting it as a 'server-side injection' example is the classic wrong answer.

828
MCQmedium

A company deploys a guest Wi-Fi network that must be isolated from the internal network. The network team uses VLANs and a firewall. Which configuration best ensures isolation?

A.Configure the same SSID for both guest and internal networks but use different passwords.
B.Create a separate VLAN for guest traffic with a firewall rule blocking access to internal subnets.
C.Use WPA2 encryption with a pre-shared key and disable SSID broadcast.
D.Assign guest devices to the same subnet as internal devices but enforce MAC filtering.
AnswerB

A dedicated guest VLAN segments traffic at layer 2, and the firewall rule blocking access to internal subnets enforces isolation at layer 3. Together they satisfy the requirement that guest traffic cannot reach internal network resources.

Why this answer

Creating a separate VLAN for guest traffic logically segments the network at Layer 2, and adding a firewall rule that explicitly blocks access to internal subnets enforces isolation at Layer 3/4. This ensures guest devices cannot reach internal resources, even if they are on the same physical infrastructure.

Exam trap

The trap here is that candidates often confuse security features like encryption (WPA2) or hiding the SSID with network isolation, failing to recognize that VLANs and firewall rules are required for true Layer 2/3 separation.

How to eliminate wrong answers

Option A is wrong because using the same SSID for both guest and internal networks does not provide any logical separation; devices would still be on the same broadcast domain unless VLANs are used, and different passwords alone do not prevent traffic from crossing between networks. Option C is wrong because disabling SSID broadcast (hidden SSID) is a weak security measure that does not isolate traffic; it only hides the network name, and WPA2 with a PSK does not prevent guest devices from accessing internal subnets if they are on the same VLAN. Option D is wrong because assigning guest devices to the same subnet as internal devices eliminates any Layer 3 separation, and MAC filtering is an access control mechanism that can be easily spoofed and does not block traffic between devices on the same subnet.

829
MCQmedium

A security administrator is reviewing the organization's security awareness training program. The administrator wants to measure whether employees can recognize and report phishing emails. Which metric BEST measures the effectiveness of the training?

A.Number of employees who completed the training module
B.Percentage of simulated phishing emails that were reported by employees
C.Number of phishing emails blocked by the email gateway
D.Percentage of employees who clicked on simulated phishing emails
AnswerB

The reporting rate directly measures whether employees recognized simulated phishing emails and took the correct action to report them. This metric reflects both recognition and the desired behavior. It is the most direct indicator of the training's effectiveness in achieving its goal.

Why this answer

The percentage of simulated phishing emails reported by employees directly measures both recognition and the desired reporting behavior. It reflects whether training has successfully taught employees to identify and act on phishing attempts. Other metrics measure participation, susceptibility, or technical blocking, which do not fully capture the training's effectiveness.

Exam trap

The trap here is choosing click rate or completion rate, which measure susceptibility or participation, instead of the reporting rate that directly reflects recognition and response.

830
MCQeasy

Which backup type copies all data that has changed since the last full backup, regardless of any incremental backups?

A.Synthetic full backup
B.Full backup
C.Differential backup
D.Incremental backup
AnswerC

A differential backup captures every change made since the last full backup, ignoring any incremental backups taken in between. This directly satisfies the stem's constraint of copying all data changed since the last full backup regardless of incrementals, because each differential accumulates changes cumulatively rather than resetting after each incremental run.

Why this answer

A differential backup copies all data that has changed since the last full backup, regardless of any intermediate incremental backups. This means each differential backup grows in size as it accumulates all changes made after the last full backup, making it distinct from incremental backups which only capture changes since the last backup of any type.

Exam trap

The trap here is that candidates often confuse differential backups with incremental backups, but the key differentiator is the reference point: differential backs up all changes since the last full backup, while incremental backs up changes since the last backup of any type.

How to eliminate wrong answers

Option A is wrong because a synthetic full backup is a logical reconstruction of a full backup from previous full and incremental backups, not a backup type that copies changed data since the last full backup. Option B is wrong because a full backup copies all data, not just the data that has changed since the last full backup. Option D is wrong because an incremental backup copies only data that has changed since the last backup (which could be full, differential, or incremental), not specifically since the last full backup.

831
MCQhard

A security administrator is implementing a mandatory vacation policy for employees in sensitive roles. The administrator needs to ensure that the policy supports the detection of fraudulent activities. Which control should be implemented alongside mandatory vacations to maximize its effectiveness?

A.Security awareness training
B.Acceptable use policy
C.Job rotation
D.Background checks
AnswerC

Job rotation requires other employees to perform the duties of a role, which increases the chance of detecting fraud or errors that a single individual might conceal. Combined with mandatory vacations, it ensures that another person gains visibility into the role's transactions. This dual control strengthens detection and deterrence.

Why this answer

Job rotation ensures that multiple employees perform the same duties, increasing the likelihood that fraudulent transactions or irregularities are noticed. When paired with mandatory vacations, it removes the single-person dependency that allows fraud to remain hidden. This combination is a classic segregation of duties and detective control pairing.

Exam trap

The trap here is selecting a preventive or educational control like background checks or training, when the scenario requires a detective control that provides ongoing oversight to uncover fraud.

832
MCQhard

A company deploys a VPN gateway that uses Diffie-Hellman key exchange to establish session keys. A security auditor warns that the gateway is vulnerable to a man-in-the-middle attack during key agreement. Which of the following should the administrator implement to mitigate this risk?

A.Increase the Diffie-Hellman group to 8192-bit MODP
B.Configure the gateway to use static Diffie-Hellman keys
C.Deploy certificates and use authenticated Diffie-Hellman
D.Enable perfect forward secrecy on the VPN gateway
AnswerC

Authenticated Diffie-Hellman binds the exchange to verified identities using digital certificates, preventing an attacker from substituting keys. By validating each peer's certificate, the VPN gateway ensures it shares a key only with the legitimate party, directly mitigating the man-in-the-middle risk described by the auditor.

Why this answer

The vulnerability exists because unauthenticated Diffie-Hellman allows an attacker to impersonate each party. Using certificates to authenticate the exchange ensures that each side verifies the other's identity before deriving session keys. Larger groups, perfect forward secrecy, or static keys do not by themselves prevent impersonation, so authenticated Diffie-Hellman is the required mitigation.

Exam trap

The trap here is assuming that increasing key size or enabling perfect forward secrecy provides authentication, when these properties are independent of identity verification.

833
MCQhard

A security analyst is configuring a SIEM to detect data exfiltration. Which of the following correlation rules would best identify potential data exfiltration via DNS tunneling?

A.Correlate high outbound DNS query volume with requests to newly registered or suspicious domains
B.Correlate multiple failed logins from a single IP
C.Alert on any single failed login attempt
D.Alert when a user accesses a file share after hours
AnswerA

DNS tunnelling encodes stolen data within query names, producing abnormally high outbound query volumes directed at attacker-controlled domains. Correlating volume spikes with newly registered or suspicious domains satisfies the stem's detection goal by combining two weak indicators into a stronger signal, catching exfiltration that single-event rules would miss.

Why this answer

DNS tunneling encodes data in DNS queries and responses, often generating a high volume of outbound queries to domains that are newly registered or otherwise suspicious. Correlating these two indicators—unusual query volume and suspicious domain characteristics—directly targets the behavior of DNS tunneling, making it the most effective rule for detecting this exfiltration technique.

Exam trap

The trap here is that candidates often confuse general anomaly detection (like failed logins or after-hours access) with the specific network-layer indicators of DNS tunneling, failing to recognize that DNS tunneling is characterized by unusual DNS query patterns to suspicious domains, not by authentication or file access events.

How to eliminate wrong answers

Option B is wrong because multiple failed logins from a single IP indicate a brute-force or credential-stuffing attack, not data exfiltration via DNS tunneling. Option C is wrong because alerting on any single failed login attempt would generate excessive false positives and does not correlate with DNS tunneling behavior. Option D is wrong because after-hours file access may indicate insider threat or policy violation but is unrelated to the network-level anomaly of DNS tunneling.

834
MCQeasy

Which of the following is a secure alternative to RC4 for stream ciphers?

A.MD5
B.AES in ECB mode
C.ChaCha20
D.3DES
AnswerC

ChaCha20 is a modern stream cipher offering strong resistance to cryptanalysis, unlike RC4 whose keystream biases render it insecure. It satisfies the stem's demand for a secure stream cipher alternative, and is standardised for use in TLS.

Why this answer

ChaCha20 is a modern, high-speed stream cipher designed by Daniel J. Bernstein as a secure alternative to RC4, which has known vulnerabilities such as biases in its keystream and susceptibility to attacks like the Fluhrer-Mantin-Shamir attack. ChaCha20 is standardized in RFC 8439 and is widely used in TLS 1.3 and SSH, offering strong security and performance without the weaknesses of RC4.

Exam trap

A common mistake in this exam is confusing block cipher modes like ECB or hash functions like MD5 with stream ciphers. The correct answer must be a dedicated stream cipher that operates similarly to RC4, such as ChaCha20.

How to eliminate wrong answers

Option A is wrong because MD5 is a cryptographic hash function, not a stream cipher, and it is broken for collision resistance. Option B is wrong because AES in ECB mode is a block cipher mode that encrypts each block independently, making it deterministic and insecure for patterns, not a stream cipher; it also lacks the keystream generation property of RC4. Option D is wrong because 3DES is a block cipher (not a stream cipher) and is deprecated due to its small 56-bit effective key size and vulnerability to meet-in-the-middle attacks.

835
MCQhard

A large data center uses a three-tier architecture with core, aggregation, and access switches. The security team detects anomalous traffic patterns: every night at 2:00 AM, a single server (IP 10.10.10.50) sends large ICMP Echo requests to multiple external IPs, followed by a flood of TCP SYN packets from those external IPs back to the server. The server is a critical database server that should not initiate outbound connections. The team suspects the server is compromised. The network team wants to contain the threat without taking the server offline immediately. Which action should they take first?

A.Apply an access control list (ACL) on the switch port to block outbound ICMP and non-essential TCP traffic from the server.
B.Add a firewall rule to block all traffic to and from the server's IP.
C.Move the server to a quarantine VLAN with no route to the internet.
D.Shut down the switch port to disconnect the server immediately.
AnswerA

An ACL on the switch port blocks the server's outbound ICMP and non-essential TCP, severing command-and-control and exfiltration paths while the host stays online. This contains the compromise immediately, satisfying the requirement to avoid taking the critical database server offline.

Why this answer

Applying an ACL on the switch port to block outbound ICMP and non-essential TCP traffic from the server immediately stops the anomalous traffic (ICMP Echo requests and TCP SYN flood responses) without taking the critical database server offline. This containment approach preserves server availability for legitimate database operations while preventing further malicious outbound activity, aligning with the goal of containing the threat without immediate downtime.

Exam trap

The trap here is that candidates often choose a more drastic action like shutting down the port or blocking all traffic, failing to recognize that a granular ACL on the switch port can surgically stop the malicious traffic while keeping the server online for its primary role.

How to eliminate wrong answers

Option B is wrong because adding a firewall rule to block all traffic to and from the server's IP would completely isolate the server, taking it offline and violating the requirement to not take the server offline immediately. Option C is wrong because moving the server to a quarantine VLAN with no route to the internet would require reconfiguring the network and potentially disrupting connectivity, which is more invasive and time-consuming than a simple ACL on the switch port; it also does not address the immediate need to stop the ongoing traffic. Option D is wrong because shutting down the switch port disconnects the server entirely, taking it offline and failing the condition to contain the threat without immediate downtime.

836
Multi-Selectmedium

An organization has detected a ransomware infection on a critical file server. The incident response team has been activated. Which TWO actions should be performed FIRST during the initial response phase?

Select 2 answers
A.Determine the type of ransomware variant
B.Immediately disconnect the file server from the network
C.Reimage the file server using a known good backup
D.Identify all affected systems and scope of infection
E.Notify law enforcement authorities
AnswersB, D

Correct: Immediate containment prevents further encryption or lateral movement.

Why this answer

Immediately disconnecting the file server from the network is a critical containment action that stops the ransomware from encrypting additional files on the server and prevents lateral movement to other systems. This aligns with the first priority in incident response: containment before eradication or recovery. Disconnecting at the switch port or disabling the network interface card (NIC) is preferred over a graceful shutdown to avoid triggering any persistence mechanisms.

Exam trap

ISC2 often tests the misconception that identifying the ransomware variant (Option A) is the first step, but in the SSCP framework, containment (disconnection) and scoping (identifying affected systems) are the immediate priorities during the initial response phase.

837
MCQmedium

A security administrator is configuring a new wireless network that must use a protocol providing strong encryption and mutual authentication. The organization requires that the solution support AES-CCMP and be based on the IEEE 802.11i standard. Which protocol should the administrator implement?

A.WPA-Personal
B.WPA2-Enterprise
C.WEP
D.WPA3-Personal
AnswerB

WPA2-Enterprise implements the IEEE 802.11i standard and mandates AES-CCMP for encryption. It supports mutual authentication through 802.1X and EAP methods, allowing the client and server to authenticate each other. This meets the requirements for strong encryption and mutual authentication in a wireless network.

Why this answer

WPA2-Enterprise is based on IEEE 802.11i and uses AES-CCMP for encryption. It supports mutual authentication through 802.1X and EAP, making it suitable for enterprise wireless networks. The other options either lack mutual authentication (WPA-Personal, WPA3-Personal) or are insecure and outdated (WEP).

Exam trap

The trap here is assuming that any WPA2 or WPA3 variant provides mutual authentication, when only enterprise modes with 802.1X do.

838
Multi-Selectmedium

A security team is hardening a centralized authentication service and wants to reduce the risk of credential replay and lateral movement if a password is compromised. Which TWO of the following controls directly support this goal? (Choose two.)

Select 2 answers
A.Enforce a maximum password age of 60 days
B.Implement just-in-time privileged access with short-lived credentials
C.Increase the minimum password length to 16 characters
D.Publish a quarterly security awareness newsletter
E.Require multi-factor authentication for all interactive logins
AnswersB, E

Just-in-time privileged access issues credentials only when needed and for a brief window, so a captured credential quickly becomes useless and cannot be replayed later. This shrinks the attack surface for lateral movement because standing privileges do not persist across the environment. It directly supports the goal of reducing replay risk and containing a compromised password.

Why this answer

Reducing replay and lateral movement risk requires controls that make a stolen password insufficient on its own and that limit how long any credential remains usable. Multi-factor authentication forces an additional factor beyond the password, and just-in-time privileged access with short-lived credentials ensures captured secrets expire quickly. Together they directly counter replay and constrain an attacker's ability to move through the environment.

Exam trap

The trap here is treating password length or rotation as defenses against replay, when those controls only affect guessing and cracking difficulty, not the reuse of an already-valid credential.

839
Multi-Selecthard

A security administrator is conducting a risk assessment for a new cloud-based application. The administrator needs to identify TWO factors that are most important when determining the appropriate security controls for the application. (Choose two.)

Select 2 answers
A.The regulatory requirements applicable to the data
B.The physical location of the cloud provider's data center
C.The programming language used to develop the application
D.The sensitivity of the data processed by the application
E.The number of users who will access the application
AnswersA, D

Regulations such as GDPR, HIPAA, or PCI DSS mandate specific controls for certain data types. Compliance obligations directly dictate encryption, auditing, retention, and access requirements. Ignoring them can result in legal penalties, so they are a critical factor in choosing controls for the application.

Why this answer

Data sensitivity and regulatory requirements are the two most important factors because they define the impact of a breach and the mandatory controls. Sensitivity drives risk-based decisions, while regulations impose specific obligations. User count, programming language, and data center location are secondary and do not directly determine the appropriate security controls.

Exam trap

The trap here is selecting user count or location as primary factors; they are relevant but not as fundamental as data sensitivity and compliance obligations.

840
MCQeasy

A developer is building a mobile banking application and wants to ensure that if an attacker gains physical access to a rooted or jailbroken device, the application's sensitive data stored locally cannot be easily read. The developer decides to use the secure storage provided by the mobile operating system. Which of the following BEST describes the protection offered by this secure storage?

A.Data is encrypted with a hardware-backed key stored in a secure element or trusted execution environment.
B.Data is encrypted with a key derived from the user's login password, which is never stored on the device.
C.Data is stored in a hidden directory that is inaccessible to other applications due to sandbox permissions.
D.Data is obfuscated using a proprietary algorithm that changes with each application release to prevent reverse engineering.
AnswerA

Mobile OS secure storage, such as iOS Keychain or Android Keystore, uses hardware-backed keys in a secure element or trusted execution environment. The key material is protected from software attacks, and even on a rooted or jailbroken device, extracting the key is significantly harder. This matches the protection the developer seeks for locally stored sensitive data.

Why this answer

Mobile operating systems provide secure storage such as iOS Keychain and Android Keystore, which encrypt data with hardware-backed keys stored in a secure element or trusted execution environment. This protects sensitive data even on rooted or jailbroken devices because the key cannot be easily extracted. Password-derived keys, obfuscation, and sandbox permissions do not provide equivalent protection against a privileged attacker.

Exam trap

The trap here is treating application sandboxing as sufficient protection, when a rooted or jailbroken device allows an attacker to bypass sandbox restrictions.

841
MCQmedium

A company needs to ensure that when an employee leaves the organization, their accounts are disabled promptly to prevent unauthorized access. Which approach is MOST effective for timely account deactivation?

A.Conduct quarterly access reviews to identify and disable unused accounts.
B.Require managers to report departures via a ticketing system.
C.Implement a self-service password reset system to empower users.
D.Automatically synchronize with the HR system to disable accounts upon termination.
AnswerD

Automated HR-system synchronisation disables accounts as part of the termination workflow itself, removing reliance on manual notification. This closes the window between departure and deactivation, satisfying the promptness constraint that manual or periodic review processes cannot guarantee.

Why this answer

Automatically synchronizing with the HR system ensures that account deactivation occurs immediately upon termination, eliminating human delay or error. This approach leverages identity lifecycle management (ILM) to enforce the principle of least privilege and prevent unauthorized access through orphaned accounts.

Exam trap

The trap here is that candidates may choose option B because it seems proactive, but they overlook the inherent delay and unreliability of manual reporting compared to automated synchronization, which is the only option guaranteeing timely deactivation.

How to eliminate wrong answers

Option A is wrong because quarterly reviews are too infrequent to meet the requirement for timely deactivation, leaving accounts active for up to 90 days after departure. Option B is wrong because relying on managers to report departures via a ticketing system introduces manual latency and the risk of forgotten or delayed reports, which fails to guarantee prompt deactivation. Option C is wrong because a self-service password reset system does not disable accounts; it only allows users to reset their own passwords, which is irrelevant to deactivating a terminated employee's account.

842
Multi-Selecteasy

Which TWO of the following are examples of vulnerability sources? (Choose TWO.)

Select 1 answer
A.Environmental disaster
B.CVE entries
C.Intentional human attack
D.Hardware failure
E.Configuration weaknesses
AnswersE

Configuration weaknesses count as vulnerability sources because they are flaws introduced by insecure settings, defaults or hardening gaps rather than by software defects. They satisfy the stem's requirement for a source category, sitting alongside poor coding, design flaws and missing patches as an origin of exploitable weakness.

Why this answer

The SSCP exam distinguishes threat sources from vulnerability sources. A vulnerability source is the origin or category from which a weakness arises, such as configuration weaknesses or software flaws. CVE entries are a standardized reference/dictionary of publicly disclosed vulnerabilities, not a source category of vulnerabilities themselves.

Environmental disaster, intentional human attack, and hardware failure are threat sources or threat events, not vulnerability sources. Therefore the only valid vulnerability source among the options is Configuration weaknesses (E).

Exam trap

The SSCP exam tests the distinction between threat sources (e.g., natural disasters, human attacks, hardware failures) and vulnerability sources (e.g., software flaws, configuration weaknesses, architectural weaknesses). Candidates often incorrectly select threat events as vulnerability sources; note that CVE is a vulnerability reference/dictionary, not a vulnerability source category.

843
MCQmedium

A security operations center is deploying a network-based intrusion detection system. The team wants to detect attacks that span multiple packets and sessions, such as a slow port scan followed by exploitation attempts. Which detection method should the team prioritize to correlate these related events?

A.Stateful protocol analysis that tracks session state and compares activity against expected protocol behavior over time.
B.Signature matching against a database of known malicious byte patterns in individual packets.
C.Anomaly detection based solely on bandwidth utilization thresholds for each monitored network segment.
D.Statistical profiling of user login times to identify credential misuse across authentication servers.
AnswerA

Stateful protocol analysis maintains awareness of ongoing sessions and protocol state, allowing the IDS to recognize multi-packet and multi-session patterns such as a gradual scan preceding an exploit. It correlates events across time rather than judging each packet in isolation, which is essential for the described attack chain.

Why this answer

Detecting attacks that unfold across many packets and sessions requires the IDS to retain and reason about session state. Stateful protocol analysis tracks conversations against expected protocol behavior, enabling recognition of slow scans, evasive fragmentation, and follow-on exploitation that isolated packet inspection would miss. This makes it the appropriate priority for the described scenario.

Exam trap

The trap here is equating intrusion detection with signature matching alone, overlooking that multi-session attacks require stateful correlation.

844
MCQhard

In a federated identity environment using SAML, what is the role of the Identity Provider (IdP) when a user requests access to a service provider (SP)?

A.The IdP hosts the application and enforces access control policies
B.The IdP validates the user's OTP token
C.The IdP generates a Kerberos ticket for the user
D.The IdP authenticates the user and issues a SAML assertion to the SP
AnswerD

In SAML federation the IdP owns authentication, verifying the user's credentials and then issuing a signed assertion describing the authenticated subject. The SP trusts that assertion to grant access, so the IdP never authorises resources itself.

Why this answer

The IdP authenticates the user and issues a SAML assertion containing identity attributes and authorization claims. The SP trusts this assertion to grant access without re-authenticating the user.

845
Multi-Selecthard

A security administrator is implementing application whitelisting on a fleet of Linux servers that run a fixed set of approved binaries. The administrator wants to ensure only authorized executables can run, while still allowing legitimate administrative scripts. Which TWO of the following approaches BEST support this goal? (Choose two.)

Select 2 answers
A.Enable a host-based intrusion detection system that alerts on execution of unknown binaries.
B.Mount the application directories as read-only and restrict write access to root only.
C.Use an integrity measurement and attestation mechanism that records hashes of approved binaries and blocks execution of unlisted files.
D.Deploy mandatory access control policy that confines each service to a profile permitting only its required executables.
E.Configure a cron job that periodically compares running processes against a known-good list and kills anomalies.
AnswersC, D

Integrity measurement with attestation verifies that only binaries matching approved hashes execute, which directly enforces whitelisting. It also provides evidence that the system has not been tampered with. This approach supports the requirement to allow approved binaries while blocking unauthorized executables, and it can be integrated with boot-time verification for stronger assurance.

Why this answer

Effective application whitelisting on Linux relies on preventive controls that stop unapproved executables before they run. Integrity measurement with attestation and mandatory access control profiles both enforce an allowlist at execution time, while still permitting approved administrative scripts when properly configured. Detection and hardening measures are useful complements but do not by themselves guarantee that only authorized binaries execute.

Exam trap

The trap here is selecting detective or hardening measures that reduce risk but do not actually block execution of unauthorized binaries, which is what whitelisting requires.

846
MCQmedium

A security administrator is reviewing Linux audit logs to detect unauthorized file access. Which Linux component is primarily responsible for generating these security audit logs?

A.systemd-journald
B.SELinux
C.PAM
D.auditd
AnswerD

The auditd daemon is the Linux userspace component that writes kernel-generated audit events to /var/log/audit/audit.log, capturing file access, syscalls and authentication activity. It is the subsystem specifically responsible for producing the security audit records the administrator reviews.

Why this answer

auditd is the userspace component of the Linux Audit system that writes audit records to disk.

847
MCQmedium

A security team is conducting a qualitative risk assessment for a new cloud application. They want to prioritize risks based on likelihood and impact. Which method should they use to combine these factors?

A.Risk matrix (heat map)
B.SWOT analysis
C.Annualized loss expectancy (ALE)
D.Business Impact Analysis (BIA)
AnswerA

A risk matrix plots likelihood against impact on a grid, producing a heat map that ranks risks into qualitative bands for prioritisation. It combines both factors without requiring monetary values, which suits the qualitative cloud assessment. Other methods, such as SLE calculations, demand quantitative data the team lacks.

Why this answer

A risk matrix (heat map) is the correct method because it combines qualitative assessments of likelihood and impact into a single visual grid, allowing the team to prioritize risks by their position in the matrix. This approach is standard for qualitative risk assessments where numerical data is unavailable, as it maps ordinal ratings (e.g., low, medium, high) to a color-coded priority level.

Exam trap

The trap here is that candidates often confuse qualitative risk assessment with quantitative methods like ALE, assuming any combination of likelihood and impact requires numerical calculation, but the question explicitly states 'qualitative', which directly points to a risk matrix.

How to eliminate wrong answers

Option B is wrong because SWOT analysis (Strengths, Weaknesses, Opportunities, Threats) is a strategic planning tool used to identify internal and external factors, not a method for combining likelihood and impact to prioritize risks. Option C is wrong because Annualized Loss Expectancy (ALE) is a quantitative metric (SLE × ARO) that requires numerical values for asset value and frequency, making it unsuitable for a purely qualitative assessment. Option D is wrong because Business Impact Analysis (BIA) focuses on identifying critical business functions and recovery priorities, not on combining likelihood and impact for risk prioritization.

848
MCQmedium

During a change management process, the Change Advisory Board (CAB) has approved a change to update a critical database server. After implementation, a rollback is necessary due to unforeseen performance issues. What should the change manager do next?

A.Execute the rollback plan and schedule a post-implementation review
B.Leave the server in its current state and escalate to the CAB for a decision
C.Patch the server with the latest updates to resolve the performance issue
D.Submit a new change request for the rollback and await CAB approval
AnswerA

The rollback plan is the pre-approved reversal path, so executing it restores the database to its last known-good state and limits disruption. Scheduling a post-implementation review then captures why performance issues arose, feeding lessons back into future change assessments.

Why this answer

The change was already approved by the CAB, and the rollback plan is a pre-approved contingency within the original change request. Executing the rollback immediately restores service stability, and scheduling a post-implementation review (PIR) captures lessons learned and ensures compliance with the change management policy. This aligns with ITIL best practices, where rollback is part of the implementation plan and does not require a new change request.

Exam trap

The trap here is that candidates mistakenly think any rollback requires a new change request, but the rollback plan is already part of the approved change, so immediate execution is permitted without further CAB approval.

How to eliminate wrong answers

Option B is wrong because leaving the server in a degraded state violates the principle of restoring service as quickly as possible, and escalating to the CAB for a decision introduces unnecessary delay when a pre-approved rollback plan exists. Option C is wrong because patching the server with latest updates is an unapproved change that bypasses the change management process and could introduce further instability or security issues. Option D is wrong because submitting a new change request for the rollback is redundant and inefficient; the rollback plan was already approved as part of the original change, so immediate execution is authorized without additional CAB approval.

849
Multi-Selecthard

An organization is designing an access control policy for a new system. Which THREE of the following are fundamental principles that should be incorporated? (Choose THREE.)

Select 3 answers
A.Fail-open
B.Least privilege
C.Need-to-know
D.Separation of duties
E.Defense in depth
AnswersB, C, D

Least privilege grants each user only the minimum access rights required to perform their role, reducing the blast radius of compromised accounts or insider misuse. It is fundamental because the access control policy must limit permissions by default rather than granting broad standing access.

Why this answer

Option B (Least privilege) is correct because users and processes should be granted only the minimum access rights necessary to perform their assigned tasks, reducing the attack surface and limiting damage from compromised accounts. Option C (Need-to-know) is correct because access to specific information should be restricted to individuals who require it to fulfill their job responsibilities, which is a foundational access control principle closely tied to least privilege. Option D (Separation of duties) is correct because splitting critical tasks among multiple users prevents any single person from having enough control to commit fraud or cause significant harm without detection, a core principle in access control policy design.

Option A (Fail-open) is not a fundamental access control principle; fail-open means a system defaults to allowing access when it fails, which is generally a security weakness rather than a policy principle. Option E (Defense in depth) is a valid security architecture concept involving layered controls, but it is not one of the three fundamental access control principles being asked for here.

Exam trap

SSCP often tests whether candidates can distinguish fundamental access control principles (least privilege, need-to-know, separation of duties) from broader security strategies (defense in depth) or insecure failure modes (fail-open).

850
MCQhard

A company implements a new policy requiring all privileged access requests to be approved by a manager. However, after deployment, analysts report that they cannot perform emergency changes outside business hours. What is the best solution?

A.Extend manager on-call hours to cover all times.
B.Implement a break-glass procedure for emergency access.
C.Remove the approval requirement for privileged access.
D.Require analysts to call a manager for approval each time.
AnswerB

A break-glass procedure grants pre-authorised emergency access, bypassing the manager approval workflow when urgent changes are needed outside business hours. It satisfies the availability constraint while preserving accountability through logging and post-incident review, ensuring privileged access remains auditable without blocking critical fixes during unstaffed periods.

Why this answer

A break-glass procedure provides a predefined, auditable method for granting emergency privileged access without requiring real-time manager approval. This balances security with operational continuity, allowing analysts to perform critical changes outside business hours while maintaining accountability through post-event review and logging.

Exam trap

The trap here is that candidates may choose option A (extending on-call hours) thinking it solves the availability issue, but they fail to recognize that it does not address the fundamental need for immediate, unattended access during emergencies, which is the core purpose of a break-glass procedure.

How to eliminate wrong answers

Option A is wrong because extending manager on-call hours does not eliminate the approval bottleneck; it only shifts the coverage window, potentially leading to delays or burnout without a guaranteed response. Option C is wrong because removing the approval requirement for privileged access eliminates necessary oversight, violating the principle of least privilege and increasing the risk of unauthorized changes. Option D is wrong because requiring analysts to call a manager for approval each time outside business hours creates a single point of failure and introduces unacceptable delays for emergency changes, undermining operational resilience.

851
MCQeasy

A small company uses a single firewall at the network perimeter. The security team receives alerts from an IDS but cannot correlate them with firewall logs because logs are stored on separate servers with different timestamps. The CEO wants to reduce false positives and improve incident response. What should the security team do first?

A.Increase the IDS sensitivity to catch more threats.
B.Replace the IDS with a next-generation firewall.
C.Implement a SIEM to aggregate and correlate logs from multiple sources.
D.Manually align timestamps on each server daily.
AnswerC

A SIEM aggregates and normalises logs from the firewall and IDS into one platform, applying consistent timestamps so events can be correlated across sources. This directly addresses the separate servers and mismatched timestamps named in the stem, enabling the correlation needed to reduce false positives and speed incident response.

Why this answer

A SIEM (Security Information and Event Management) system aggregates logs from multiple sources, normalizes timestamps, and correlates events to reduce false positives and improve incident response. This directly addresses the core problem of disparate log sources with unsynchronized timestamps, enabling effective correlation between IDS alerts and firewall logs without replacing existing infrastructure.

Exam trap

The trap here is that candidates may think a next-generation firewall (NGFW) replaces the need for log correlation, but NGFWs still generate logs that require aggregation and correlation with other sources to reduce false positives and enable effective incident response.

How to eliminate wrong answers

Option A is wrong because increasing IDS sensitivity would generate more alerts, exacerbating the false positive problem and making correlation harder without fixing the timestamp mismatch. Option B is wrong because replacing the IDS with a next-generation firewall (NGFW) does not solve the log correlation issue; NGFWs still generate logs that need to be correlated with other sources, and the underlying timestamp synchronization problem remains. Option D is wrong because manually aligning timestamps daily is impractical, error-prone, and does not scale; it also fails to provide automated correlation or reduce false positives in real time.

852
MCQhard

A security analyst discovers that an internal host is sending traffic to an external IP address known to be a command-and-control server. The analyst wants to block only that specific traffic without affecting other traffic. Which firewall rule should be implemented?

A.Deny all traffic from the internal host.
B.Deny all traffic to the external IP.
C.Deny traffic on the specific port used.
D.Deny traffic from the internal host to the external IP.
AnswerD

A rule matching both source internal host and destination external IP denies only that specific flow, leaving all other traffic unaffected. This satisfies the constraint of blocking solely the command-and-control communication, whereas broader subnet or port blocks would disrupt unrelated legitimate traffic.

Why this answer

It creates a specific deny rule that matches only the source IP of the internal host and the destination IP of the command-and-control server, blocking that exact traffic flow while allowing all other traffic to and from both hosts. This is the most precise and least disruptive approach, adhering to the principle of least privilege in firewall rule design.

Exam trap

The trap here is that candidates often choose a broad deny rule (like denying all traffic to the external IP) because they focus on the malicious destination, forgetting that such a rule would block all traffic to that IP from any source, potentially impacting other hosts or services.

How to eliminate wrong answers

Option A is wrong because denying all traffic from the internal host would block all outbound communications from that host, including legitimate traffic to other destinations, causing unnecessary disruption. Option B is wrong because denying all traffic to the external IP would block all inbound and outbound traffic to that IP from any host, potentially affecting other internal hosts that may need to communicate with that IP for legitimate reasons (though unlikely in this scenario, it is overly broad). Option C is wrong because denying traffic on the specific port used would block all traffic on that port to any destination, not just the command-and-control server, which could disrupt other services using the same port.

853
MCQmedium

An organization uses a SIEM to alert when a server's configuration changes from its hardened baseline. This is an example of:

A.Deviation detection
B.Patch management
C.Vulnerability scanning
D.Asset management
AnswerA

Deviation detection compares current system state against a defined baseline and raises alerts on any divergence, which is precisely what the SIEM performs when a server's configuration drifts from its hardened state. It satisfies the stem's constraint of detecting configuration changes rather than preventing them or scanning for known malware signatures.

Why this answer

SIEM alerts on configuration changes from baseline are a form of deviation detection, which is part of configuration management.

854
Multi-Selectmedium

Which TWO of the following are key components of a security awareness program?

Select 2 answers
A.User training on password policies
B.Regular phishing simulations
C.Incident response drills
D.Quarterly vulnerability scans
E.Annual penetration testing
AnswersA, B

Training users on password policies establishes the baseline knowledge required to create strong credentials and recognise related attacks. This satisfies the stem's requirement for a key component because awareness programmes must first teach expected secure behaviour before simulations or other reinforcement activities can meaningfully assess it.

Why this answer

Option A (User training on password policies) is correct because a security awareness program must educate users on creating strong passwords, recognizing password-related threats, and following organizational password rules, which directly reduces credential-based risks. Option B (Regular phishing simulations) is correct because simulated phishing campaigns test and reinforce user vigilance against social engineering, providing measurable feedback that strengthens the human element of security. Option C (Incident response drills) is not a core awareness component; it tests the security team's technical and procedural response to incidents rather than end-user awareness.

Option D (Quarterly vulnerability scans) is a technical control that identifies system weaknesses and does not train or educate users. Option E (Annual penetration testing) is an offensive security assessment of systems and applications, not an awareness activity for the general workforce.

Exam trap

The trap here is confusing technical security assessments (like vulnerability scans and penetration tests) with user-focused awareness activities; candidates may select options that are part of broader security programs but not core to awareness.

855
MCQmedium

An organization decides to implement CIS Benchmarks on all Windows servers. They choose Level 1 settings. What does Level 1 represent?

A.Maximum security with high operational impact
B.Equivalent to DISA STIGs
C.Only applicable to critical systems
D.Basic security hygiene with minimal impact
AnswerD

CIS Level 1 profiles apply settings intended as essential, low-risk hardening that can be deployed broadly with minimal disruption to functionality or performance. This matches the organisation's aim of implementing benchmarks across all Windows servers without breaking operational services.

Why this answer

CIS Benchmarks define Level 1 as a set of configuration settings intended to provide basic security hygiene with minimal impact on business operations. These settings are designed to be easily implemented without causing significant performance degradation or service disruption, making them suitable for most systems. Level 1 focuses on essential security controls that address common vulnerabilities while maintaining system usability.

Exam trap

The trap here is that candidates often confuse Level 1 with 'maximum security' or assume it is only for critical systems, when in fact Level 1 is the baseline recommended for all systems to achieve a practical security posture without disrupting operations.

How to eliminate wrong answers

Option A is wrong because Level 1 is not about maximum security; maximum security with high operational impact is characteristic of Level 2 settings, which may disable features or enforce stricter policies that can affect performance. Option B is wrong because CIS Benchmarks and DISA STIGs are separate frameworks; while they may overlap in some controls, STIGs are typically more restrictive and aligned with U.S. Department of Defense requirements, not equivalent to CIS Level 1.

Option C is wrong because Level 1 is explicitly designed for general-purpose systems, not only critical systems; critical systems often require Level 2 or additional custom hardening.

856
MCQmedium

A security administrator is implementing a solution to detect unauthorized changes to critical system files on a server. Which of the following technologies is BEST suited for this purpose?

A.Security information and event management (SIEM)
B.Intrusion detection system (IDS)
C.File integrity monitoring (FIM)
D.Data loss prevention (DLP)
AnswerC

File integrity monitoring (FIM) tools compute cryptographic hashes of critical files and alert when changes occur. This directly detects unauthorized modifications. FIM is designed for this purpose, providing real-time or scheduled checks. It is the best fit for detecting changes to system files.

Why this answer

File integrity monitoring is specifically designed to detect unauthorized changes to files by comparing current hashes to known good baselines. It provides alerts when critical system files are modified, making it the best choice for this requirement.

Exam trap

The trap here is confusing general monitoring tools like SIEM or IDS with specialized file integrity monitoring.

857
MCQmedium

An organization uses a PKI with a root CA that issues certificates to intermediate CAs, which then issue end-entity certificates. A client receives an end-entity certificate signed by an intermediate CA. During validation, which certificates are required to build the chain of trust?

A.Only the root CA certificate
B.End-entity certificate, intermediate CA certificate, and root CA certificate
C.Only the end-entity certificate and the root CA certificate
D.Only the end-entity certificate and the intermediate CA certificate
AnswerB

Validation requires the full chain from the end-entity certificate up through the issuing intermediate CA to the trusted root CA, because each signature must be verified against its issuer's public key until a trust anchor is reached.

Why this answer

In a PKI hierarchy, the chain of trust requires each certificate in the path to be validated up to a trusted root. The client must have the end-entity certificate, the intermediate CA certificate (to verify the end-entity's signature), and the root CA certificate (to verify the intermediate CA's signature). Without the intermediate CA certificate, the client cannot cryptographically link the end-entity to the root, breaking the chain.

Exam trap

The trap here is that candidates often assume the root CA directly signs all certificates, forgetting that intermediate CAs are used in practice, so they incorrectly select Option C or D, missing the need for the full chain.

How to eliminate wrong answers

Option A is wrong because the root CA certificate alone cannot verify the end-entity certificate's signature, which was issued by the intermediate CA, not the root. Option C is wrong because omitting the intermediate CA certificate leaves a gap in the chain; the client cannot validate the intermediate CA's signature on the end-entity certificate. Option D is wrong because without the root CA certificate, the client cannot verify the intermediate CA certificate's signature, so the chain of trust cannot be anchored to a trusted root.

858
Multi-Selecthard

A security administrator is implementing a formal data retention and destruction program for a financial services firm. The firm stores customer records, transaction logs, and email archives on a variety of media, including solid-state drives, magnetic tapes, and cloud object storage. Which TWO practices should the administrator include to ensure data is destroyed in a manner that is both effective and auditable? (Choose two.)

Select 2 answers
A.Define retention periods by data category and apply destruction only after the retention period expires and any legal hold is released.
B.Delegate all destruction activities to the cloud service provider and rely on the provider's standard terms of service for assurance.
C.Use the same overwriting utility on all media types to simplify the destruction procedure and reduce training requirements.
D.Maintain a certificate of destruction that records the media type, serial number, method used, date, and the personnel who performed the destruction.
E.Store all media in a locked room after the retention period expires until the media can be reused for other purposes.
AnswersA, D

Retention periods must be tied to legal, regulatory, and business requirements for each data category, and destruction should occur only after those periods end and any litigation hold is lifted. Destroying data too early can violate regulations or spoliation rules, while retaining it too long increases breach exposure. This practice ensures destruction is lawful, consistent, and defensible during audits or legal proceedings.

Why this answer

An effective destruction program pairs documented retention rules with verifiable destruction evidence. Retention periods must reflect legal and business requirements, with destruction delayed until holds are released. Certificates of destruction provide the audit trail that proves media was destroyed properly.

Using one overwrite tool for all media, delegating without assurance, or merely storing expired media fails to deliver either effective destruction or the documentation auditors require.

Exam trap

The trap here is assuming a single overwriting method works on every media type and that a cloud provider's default terms are sufficient evidence of destruction.

859
Multi-Selectmedium

An organization uses Linux servers and wants to implement mandatory access control (MAC) to enhance security. Which TWO technologies can be used? (Select TWO.)

Select 2 answers
A.SELinux
B.iptables
C.AppArmor
D.auditd
E.PAM (Pluggable Authentication Modules)
AnswersA, C

SELinux enforces mandatory access control through kernel-level type enforcement and security contexts, applying policy defined by the administrator rather than the resource owner. This satisfies the Linux MAC requirement because even root processes are confined by the loaded policy.

Why this answer

SELinux (A) is correct because it is a Linux kernel security module that enforces mandatory access control by applying type enforcement, role-based access control, and multi-level security policies that confine processes and users regardless of their discretionary permissions. AppArmor (C) is also correct because it implements MAC through per-program profiles that restrict an application's file, network, and capability access using path-based rules loaded into the kernel. iptables (B) is incorrect because it is a packet-filtering firewall tool for network traffic, not a MAC framework for constraining process privileges. auditd (D) is incorrect because it is the Linux auditing daemon that logs security-relevant events, providing accountability rather than access enforcement. PAM (E) is incorrect because it is an authentication framework that handles login and credential checks, not a mandatory access control mechanism.

Exam trap

SSCP often tests the distinction between MAC frameworks (SELinux, AppArmor) and adjacent security tools (iptables for firewalling, auditd for auditing, PAM for authentication) — candidates pick familiar tools without confirming they enforce MAC.

860
MCQmedium

During a forensic investigation, an examiner creates a bit-for-bit copy of a hard drive using a write blocker. What is the purpose of using a write blocker?

A.To prevent modification of the original evidence
B.To encrypt the data during transfer
C.To speed up the imaging process
D.To verify the hash of the original drive
AnswerA

A write blocker intercepts write commands at the hardware or driver level, allowing the examiner to read the drive while blocking any modification. This preserves the original evidence's integrity so the bit-for-bit copy remains forensically sound and admissible.

Why this answer

A write blocker is a hardware or software device that intercepts and blocks any write commands from the forensic workstation to the source drive, ensuring that the original evidence remains unaltered during acquisition. This is critical for maintaining the integrity and admissibility of digital evidence in legal proceedings, as any modification could compromise the chain of custody and forensic soundness.

Exam trap

ISC2 often tests the misconception that write blockers are used for encryption or speed optimization, but the core purpose is strictly write prevention to preserve evidence integrity.

How to eliminate wrong answers

Option B is wrong because write blockers do not encrypt data; encryption is a separate process typically handled by forensic tools or software after acquisition, and a write blocker's sole function is to prevent writes. Option C is wrong because write blockers do not speed up imaging; in fact, they may introduce a slight overhead due to command filtering, and imaging speed is primarily determined by the drive interface and the imaging tool. Option D is wrong because verifying the hash of the original drive is a post-imaging step performed by the examiner using hashing algorithms like SHA-256 or MD5, not a function of the write blocker itself.

861
MCQmedium

A system administrator receives a report that a critical server is running low on disk space. After investigation, it is determined that the log files are not being rotated properly. Which of the following is the BEST solution to prevent this issue in the future?

A.Configure log rotation based on size and age.
B.Increase the maximum log file size.
C.Redirect logs to a different partition.
D.Enable compression on the log folder.
AnswerA

Configuring rotation by size and age caps log growth before the volume fills, directly addressing the unrotated logs that caused low disk space. This prevents recurrence by bounding retention, unlike one-off deletion or manual monitoring, which do not enforce ongoing log lifecycle management.

Why this answer

Configuring log rotation based on both size and age is the best solution because it directly addresses the root cause — logs growing unbounded — by automatically archiving, compressing, or deleting old logs once they hit a size threshold or age limit. Tools like logrotate on Linux support directives such as 'size 100M', 'daily', 'rotate 7', and 'compress', giving deterministic control over disk consumption. This is a preventive, repeatable control rather than a one-time workaround.

Exam trap

SSCP often tests whether candidates choose a root-cause fix (rotation) versus a symptomatic workaround (bigger files, different partition, compression) — the trap is picking 'increase size' or 'redirect' because they sound like quick fixes, when only rotation prevents recurrence.

How to eliminate wrong answers

Option B is wrong because increasing the maximum log file size makes the problem worse — it allows logs to consume even more disk before any action is taken, delaying the failure rather than preventing it. Option C is wrong because redirecting logs to a different partition only moves the problem; that partition will eventually fill too, and it doesn't address the lack of rotation. Option D is wrong because enabling compression on the log folder reduces the size of existing files but does not stop new logs from accumulating unbounded — without rotation, compression alone cannot keep pace with continuous log growth.

862
MCQmedium

A security team discovers that an employee's credentials were used to access the HR database from an unrecognized IP address in a foreign country. The employee is currently in the office. Which risk identification technique is most directly responsible for detecting this anomaly?

A.User and entity behavior analytics (UEBA)
B.Manual log review
C.Vulnerability scanning
D.Threat intelligence feeds
AnswerA

UEBA baselines each user's normal activity, such as typical login locations and times, then flags statistically anomalous events. The foreign login from an IP the employee never uses, while the employee sits in the office, is exactly the behavioural deviation UEBA detects.

Why this answer

UEBA is the correct answer because it uses machine learning and statistical models to establish a baseline of normal user behavior (e.g., typical login times, geolocations, and access patterns). When the employee's credentials are used from a foreign IP address while the employee is physically in the office, UEBA detects this as an anomalous deviation from the baseline, triggering an alert. This technique is specifically designed for real-time anomaly detection in user and entity activities, making it the most direct method for identifying this type of credential misuse.

Exam trap

The trap here is that candidates may confuse threat intelligence feeds (Option D) with anomaly detection, assuming that an unrecognized foreign IP would be flagged by a threat feed, but UEBA is the only technique that directly detects behavioral anomalies without relying on known-bad indicators.

How to eliminate wrong answers

Option B (Manual log review) is wrong because it is a reactive, labor-intensive process that relies on human analysts to sift through logs after an incident, making it inefficient for real-time anomaly detection; it would not directly detect the anomaly without prior suspicion or automated correlation. Option C (Vulnerability scanning) is wrong because it focuses on identifying known security weaknesses in systems (e.g., unpatched software, misconfigurations) rather than monitoring user behavior or detecting anomalous access patterns. Option D (Threat intelligence feeds) is wrong because they provide information about known malicious IPs, domains, or indicators of compromise (IOCs) from external sources, but they do not establish a baseline of normal user behavior; an unrecognized IP from a foreign country may not be in any threat feed, so the anomaly would be missed without behavioral analysis.

863
MCQmedium

An analyst detects suspicious outbound traffic from a server to a known command-and-control IP address. According to NIST SP 800-61, which phase of the incident response lifecycle does this activity fall under?

A.Post-Incident Activity
B.Preparation
C.Containment, Eradication, and Recovery
D.Detection and Analysis
AnswerD

Detecting suspicious outbound traffic to a known command-and-control IP is the identification of a potential security event, which NIST SP 800-61 places squarely within Detection and Analysis. This phase covers monitoring, triage and validating whether activity constitutes a genuine incident before containment begins.

Why this answer

The detection of suspicious outbound traffic to a known command-and-control IP address is a clear indicator of a potential security incident. According to NIST SP 800-61, this activity falls under the 'Detection and Analysis' phase, which involves identifying and validating that an incident has occurred through monitoring, alerting, and analysis of security events.

Exam trap

ISC2 SSCP often tests the distinction between 'Detection and Analysis' and 'Containment, Eradication, and Recovery' by presenting a detection event and expecting candidates to recognize that containment actions are separate and occur later in the lifecycle.

How to eliminate wrong answers

Option A is wrong because 'Post-Incident Activity' occurs after the incident has been contained and eradicated, focusing on lessons learned and reporting, not on initial detection. Option B is wrong because 'Preparation' involves establishing policies, tools, and training before an incident occurs, not detecting active malicious traffic. Option C is wrong because 'Containment, Eradication, and Recovery' are actions taken after detection to stop the spread, remove the threat, and restore systems, not the initial identification of suspicious traffic.

864
MCQeasy

Which metric is used to measure the potential loss from a single occurrence of a risk?

A.Exposure Factor (EF)
B.Annualized Loss Expectancy (ALE)
C.Annualized Rate of Occurrence (ARO)
D.Single Loss Expectancy (SLE)
AnswerD

Single Loss Expectancy quantifies the monetary loss from one risk occurrence, directly satisfying the stem's requirement for a single-event metric. It is calculated as asset value multiplied by exposure factor, giving the expected cost per incident before annual frequency is applied. Annualised Loss Expectancy, by contrast, aggregates multiple occurrences across a year.

Why this answer

The Single Loss Expectancy (SLE) is the metric used to measure the potential loss from a single occurrence of a risk. It is calculated as Asset Value (AV) multiplied by the Exposure Factor (EF), providing a dollar value for one incident. This directly answers the question of loss per single event.

Exam trap

ISC2 often tests the distinction between SLE and ALE, trapping candidates who confuse a single-event loss with an annualized figure, especially when the question explicitly asks for 'single occurrence' but the answer options include ALE as a distractor.

How to eliminate wrong answers

Option A is wrong because Exposure Factor (EF) is a percentage representing the proportion of asset value lost per incident, not a direct monetary loss measure. Option B is wrong because Annualized Loss Expectancy (ALE) measures the expected loss per year, calculated as SLE × ARO, not per single occurrence. Option C is wrong because Annualized Rate of Occurrence (ARO) is a frequency metric (events per year), not a loss measurement.

865
MCQhard

A security administrator is prioritizing patches for a vulnerability with a CVSS score of 9.8 that is being actively exploited in the wild. The affected server has a low criticality classification. What should the administrator do?

A.Apply the patch immediately without change management
B.Ignore the patch because the server is low criticality
C.Wait for the next scheduled patch cycle
D.Prioritize patching via the change management process
AnswerD

Active exploitation plus a CVSS of 9.8 outweighs the server's low criticality, so the patch must be expedited. Routing it through change management satisfies the stem by ensuring the urgent fix is deployed under controlled, documented approval rather than bypassing governance entirely.

Why this answer

Even though the server is low criticality, a CVSS score of 9.8 with active exploitation represents an urgent risk that must be addressed. The administrator should prioritize patching through the change management process to ensure proper approval, testing, and documentation while still expediting the fix.

Exam trap

SSCP often tests the misconception that low asset criticality justifies ignoring critical vulnerabilities—candidates may pick 'ignore' or 'wait' without considering active exploitation and lateral movement risk.

How to eliminate wrong answers

Option A is wrong because bypassing change management entirely creates audit, compliance, and operational risks; emergency changes still require some form of change control. Option B is wrong because ignoring the patch is negligent—active exploitation means the risk is real regardless of server criticality, and the server could be a pivot point. Option C is wrong because waiting for the next scheduled patch cycle leaves the organization exposed to an actively exploited vulnerability, which is unacceptable.

866
Multi-Selecteasy

Which TWO metrics are commonly tracked to measure the effectiveness of the incident response process? (Select TWO)

Select 2 answers
A.MTTD (Mean Time to Detect)
B.SLA (Service Level Agreement) compliance percentage
C.MTBF (Mean Time Between Failures)
D.MTTR (Mean Time to Respond)
E.Number of firewall rules
AnswersA, D

MTTD measures the elapsed time from incident occurrence to detection, quantifying how quickly monitoring and alerting identify threats. Tracking it exposes gaps in detection capability and is a core effectiveness metric alongside containment and recovery times.

Why this answer

MTTD (Mean Time to Detect) is correct because it directly measures how quickly an organization identifies an incident after it occurs, which is a core indicator of incident response effectiveness in the detection phase. MTTR (Mean Time to Respond) is correct because it measures how quickly the team responds to and contains or resolves an incident, reflecting the efficiency of the response process. Together, MTTD and MTTR are standard incident response metrics used to benchmark and improve detection and response capabilities.

SLA compliance percentage is not specific to incident response effectiveness, as SLAs cover many service areas beyond security incidents. MTBF (Mean Time Between Failures) measures reliability of systems or components, not incident response performance. The number of firewall rules is a configuration or hygiene metric and does not measure how well incidents are detected or handled.

Exam trap

ISC2 often tests the distinction between operational metrics (MTTD, MTTR) and reliability metrics (MTBF) or configuration counts, so candidates mistakenly select MTBF or firewall rules because they sound technical but are irrelevant to incident response effectiveness.

867
Multi-Selectmedium

A security administrator is reviewing how mobile devices connect to corporate email and file shares. The organization wants to protect data if a device is lost and to prevent data leakage between personal and work applications. Which TWO controls should the administrator implement? (Choose two.)

Select 2 answers
A.Enable full device backup to the user's personal cloud account
B.Enroll devices in a mobile device management solution with remote wipe
C.Configure containerization that separates corporate apps and data from personal apps
D.Allow sideloading of applications from unknown sources
E.Disable device encryption to improve application performance
AnswersB, C

MDM enrollment lets the organization enforce policy, monitor compliance, and trigger a remote wipe if a device is lost, directly addressing the data protection requirement. It also provides the management channel needed to push other controls such as passcode and encryption policies to enrolled devices.

Why this answer

MDM with remote wipe protects data when a device is lost, and containerization isolates corporate apps and data from personal ones to stop leakage across the boundary. Together they address both parts of the requirement without forcing users to carry separate devices.

Exam trap

The trap here is selecting convenience features such as personal cloud backup or sideloading, which feel helpful but actually expand data exposure and defeat the stated goals.

868
Multi-Selectmedium

During the preparation phase of incident response, which TWO components are essential for an effective incident response plan? (Select TWO)

Select 2 answers
A.A list of approved vendors for hardware replacement
B.A list of all employee passwords
C.A communication plan with contact information for key stakeholders
D.Network topology diagrams
E.Detailed recovery procedures for each critical system
AnswersC, E

A communication plan with stakeholder contact details satisfies the coordination constraint during preparation, ensuring the right people are reachable the moment an incident is declared. Without predefined escalation paths and contacts, response stalls while responders hunt for decision-makers, delaying containment and violating the plan's requirement for clear internal and external notification procedures.

Why this answer

Option C is correct because an incident response plan must include a communication plan with up-to-date contact information for key stakeholders (e.g., incident handlers, management, legal, PR, and law enforcement) so that notifications and escalations occur quickly and in the proper order during an incident. Option E is correct because detailed recovery procedures for each critical system provide the documented, tested steps (such as restoration order, RTO/RPO targets, and system-specific rebuild or failover instructions) needed to return operations to normal after containment and eradication. Option A is not essential to the plan itself, since vendor lists support logistics but are not a core IR plan component.

Option B is incorrect and a security risk, as storing all employee passwords violates least privilege and credential-management best practices. Option D, while useful for scoping and containment, is supporting documentation rather than one of the two essential components emphasized here.

Exam trap

The trap here is that candidates may confuse operational logistics (like vendor lists or network diagrams) with the core structural components of an incident response plan, which must prioritize communication and recovery to enable a coordinated and effective response.

869
Multi-Selecthard

Which THREE are appropriate controls to prevent unauthorized access to a data center? (Choose three.)

Select 3 answers
A.Biometric scanner
B.Firewall
C.Mantrap
D.Security guards
E.Encryption
AnswersA, C, D

Biometric scanner authenticates individuals for physical access.

Why this answer

A biometric scanner is a physical access control that authenticates individuals based on unique physiological characteristics (e.g., fingerprints, iris patterns). It directly prevents unauthorized entry by verifying identity at the data center perimeter, making it an appropriate control for physical security.

Exam trap

ISC2 often tests the distinction between physical access controls (e.g., biometrics, mantrap, guards) and logical/technical controls (e.g., firewall, encryption), leading candidates to mistakenly select network or data protection mechanisms for a physical security question.

870
MCQeasy

During the preparation phase of the incident response lifecycle, which of the following is the MOST important component to establish?

A.Communication plan
B.Incident response plan
C.Incident response team
D.Forensic analysis tools
AnswerB

The incident response plan defines roles, escalation paths, communication channels and procedures before an incident occurs, so responders act consistently rather than improvising. This satisfies the stem's requirement for the most important preparation-phase component, underpinning every later lifecycle phase.

Why this answer

The incident response plan is the foundational document that outlines the entire process, including roles, procedures, and escalation paths. Without a formal, approved plan, other components like the communication plan, team, or tools lack the necessary structure and authority to function effectively during an incident.

Exam trap

ISC2 SSCP often tests the misconception that the incident response team is the most important component, but without a formal plan, the team lacks defined roles, authority, and procedures to act effectively.

How to eliminate wrong answers

Option A is wrong because a communication plan is a subset of the incident response plan; it cannot be established effectively without the overarching plan defining who communicates what and when. Option C is wrong because the incident response team is a resource that is assembled and trained based on the plan's requirements, not the primary component to establish first. Option D is wrong because forensic analysis tools are tactical resources selected after the plan defines the investigation procedures and legal requirements, not the most important preparatory component.

871
MCQmedium

A web application processes user-supplied data in SQL queries. Which practice best prevents SQL injection?

A.Parameterized queries
B.Escaping all user input
C.Using stored procedures exclusively
D.Input length validation
AnswerA

Parameterised queries separate SQL code from user-supplied values by sending them as bound parameters, so input is never interpreted as executable SQL syntax. This neutralises injection regardless of the characters supplied, satisfying the requirement to prevent SQL injection in the application's queries.

Why this answer

Parameterized queries (also known as prepared statements) separate SQL logic from user data by using placeholders (e.g., `?` in MySQLi or `:name` in PDO). The database engine treats the user input strictly as data, never as executable SQL code, which inherently prevents SQL injection regardless of the input content.

Exam trap

Candidates often believe stored procedures are inherently safe against SQL injection. However, stored procedures only prevent injection if they do not construct dynamic SQL within the procedure body using concatenated user input. Parameterized queries (or prepared statements) are the definitive protection because they separate SQL logic from data entirely.

How to eliminate wrong answers

Option B is wrong because escaping all user input is error-prone and context-dependent; for example, escaping for MySQL with `mysql_real_escape_string()` can still be bypassed if the character set is mismatched (e.g., GBK encoding leading to multibyte injection). Option C is wrong because stored procedures alone do not prevent SQL injection if dynamic SQL is constructed within the procedure using concatenated user input (e.g., `EXEC('SELECT * FROM Users WHERE id = ' + @input)`). Option D is wrong because input length validation only restricts the size of input, not its malicious content; a short SQL injection payload like `' OR 1=1 --` can easily pass length checks.

872
MCQmedium

An IT administrator needs to deprovision a user who has been terminated. Which of the following actions should be performed first to ensure security?

A.Remove the user from all groups
B.Delete the user account
C.Disable the user account
D.Change the user's password
AnswerC

Disabling the account immediately blocks authentication and access while preserving the object and its group memberships for audit and possible rehire. This satisfies the security-first constraint, since deletion would remove evidence and any dependent access before revocation is verified.

Why this answer

Immediately disabling the account prevents any further access. Evidence preservation can be done afterward, and deletion should be delayed until necessary.

873
MCQmedium

A security team is conducting a penetration test. In which phase would they attempt to exploit vulnerabilities found during scanning?

A.Maintaining access.
B.Scanning.
C.Reconnaissance.
D.Gaining access.
AnswerD

Gaining access is the penetration-testing phase where identified vulnerabilities are actively exploited to obtain entry, satisfying the stem's requirement to exploit scanning findings. Scanning only discovers and enumerates weaknesses; exploitation occurs here, after reconnaissance and scanning, and before maintaining access or covering tracks.

Why this answer

The gaining access phase is where the penetration tester actively exploits vulnerabilities discovered during scanning to obtain unauthorized entry into the system. This phase involves using tools like Metasploit or custom exploits to leverage specific weaknesses, such as unpatched software or misconfigured services, to achieve initial foothold. It directly follows the scanning phase and precedes maintaining access, making D the correct choice.

Exam trap

The trap here is confusing the scanning phase with the gaining access phase, as candidates often think vulnerability scanning includes exploitation, but scanning only identifies potential weaknesses without actively compromising the system.

How to eliminate wrong answers

Option A is wrong because maintaining access occurs after gaining access, focusing on persistence mechanisms like backdoors or rootkits, not the initial exploitation of vulnerabilities. Option B is wrong because scanning is the phase where vulnerabilities are identified through port scans (e.g., Nmap) and service enumeration, but exploitation is not performed here. Option C is wrong because reconnaissance is the initial information-gathering phase (e.g., OSINT, DNS lookups) that precedes scanning and does not involve active exploitation of vulnerabilities.

874
MCQhard

During a security audit, it is discovered that network devices are using Telnet for management. Which of the following is the most secure replacement to ensure encrypted remote access?

A.SNMPv3 with authentication and encryption
B.SSH with public key authentication
C.HTTPS with self-signed certificate
D.SSH with password authentication
AnswerB

Public key authentication is more secure and supports encryption.

Why this answer

SSH (Secure Shell) provides encrypted remote access and authentication, replacing the insecure Telnet protocol. Public key authentication adds a second factor (the private key) and is resistant to brute-force password attacks, making it the most secure option for managing network devices.

Exam trap

The trap here is that candidates often confuse SNMPv3's encryption capabilities with remote shell access, or they assume that any encrypted protocol (like HTTPS) is a direct replacement for Telnet, ignoring that SSH is the standard for secure command-line management.

How to eliminate wrong answers

Option A is wrong because SNMPv3 is designed for network management monitoring and trap notifications, not for interactive remote shell access or device configuration. Option C is wrong because HTTPS with a self-signed certificate encrypts the session but does not provide a trusted identity verification and is typically used for web-based management interfaces, not for command-line remote access. Option D is wrong because SSH with password authentication still relies on a shared secret that can be guessed, intercepted via keylogging, or compromised in transit if weak ciphers are used, whereas public key authentication eliminates password transmission.

875
Multi-Selectmedium

A security analyst is reviewing the organization's incident response plan and wants to ensure it includes the necessary elements for the preparation phase according to NIST SP 800-61. Which of the following should be included in the preparation phase? (Choose two.)

Select 2 answers
A.Eradicating malware from infected systems.
B.Recovering data from backups.
C.Developing an incident response policy that defines roles and responsibilities.
D.Establishing a communication plan with internal and external stakeholders.
E.Conducting a lessons learned meeting after an incident.
AnswersC, D

An incident response policy is a foundational element of the preparation phase. It establishes the authority, scope, and responsibilities for incident response, ensuring that all stakeholders understand their roles. NIST SP 800-61 specifically lists the creation of an incident response policy as a key preparation activity, as it provides the framework for the entire incident response lifecycle.

Why this answer

The preparation phase of the NIST SP 800-61 incident response lifecycle includes activities that establish the capability to respond to incidents. This includes creating an incident response policy that defines roles and responsibilities, and establishing a communication plan with stakeholders. These elements ensure the organization is ready to detect, analyze, and respond to incidents effectively.

Exam trap

The trap here is confusing activities from other phases, such as lessons learned, eradication, or recovery, with preparation phase elements.

876
Multi-Selectmedium

An incident response team is preparing to collect evidence from a compromised Linux web server. The team lead wants to ensure that the evidence will be admissible in a potential legal proceeding. Which TWO actions should the team take to maintain the integrity of the evidence? (Choose two.)

Select 2 answers
A.Document the chain of custody for each evidence item.
B.Analyze the original evidence directly to avoid any copy-related discrepancies.
C.Compute and record cryptographic hashes of the evidence before and after analysis.
D.Allow all team members to access the evidence freely for efficiency.
E.Store evidence on the compromised server to maintain original context.
AnswersA, C

A chain of custody documents who handled the evidence, when, and for what purpose, which is essential for admissibility. Without it, opposing counsel can challenge whether the evidence was tampered with or altered. In this scenario, documenting custody for each item collected from the Linux server establishes an unbroken record that supports the evidence's integrity in legal proceedings.

Why this answer

Maintaining evidence integrity requires documenting the chain of custody and using cryptographic hashes to verify that data has not changed. These practices ensure that evidence collected from the compromised Linux server can withstand legal scrutiny. Analyzing originals, storing evidence on the compromised system, or allowing unrestricted access all undermine integrity and admissibility.

Exam trap

The trap here is assuming that analyzing the original evidence is more accurate, when in fact it risks altering the evidence and breaking the chain of custody.

877
MCQhard

During a code review, a developer identifies that a web application directly concatenates user input into SQL queries without sanitization. This vulnerability is classified under which OWASP Top 10 category?

A.Cross-Site Scripting (XSS)
B.Security Misconfiguration
C.Broken Access Control
D.Injection
AnswerD

Concatenating unsanitised input into SQL queries lets attackers alter query structure, so the flaw is Injection. This directly satisfies the stem's constraint: user input reaches an interpreter without sanitisation. Injection covers SQL, NoSQL, OS command and ORM injection, making it the precise OWASP Top 10 category here.

Why this answer

Directly concatenating unsanitized user input into SQL queries is the textbook definition of SQL injection, which falls under the OWASP Top 10 'Injection' category (A03:2021). Injection covers SQL, NoSQL, OS command, and LDAP injection where untrusted data is interpreted as code or commands. The fix is parameterized queries or prepared statements, not input filtering alone.

Exam trap

The trap here is that candidates see 'web application' and 'user input' and jump to XSS, but the key discriminator is that the input reaches a SQL query, which is Injection, not Cross-Site Scripting.

How to eliminate wrong answers

Option A is wrong because XSS involves injecting client-side script into web pages viewed by other users, not manipulating backend SQL queries. Option B is wrong because Security Misconfiguration refers to insecure default settings, verbose errors, or unnecessary features enabled, not unsanitized query construction. Option C is wrong because Broken Access Control concerns users acting outside their intended permissions, not the injection of malicious SQL through input fields.

878
Multi-Selectmedium

A security analyst is reviewing the incident response plan and wants to ensure the containment strategy is effective for a recent malware outbreak. The analyst must choose containment measures that align with NIST SP 800-61. Which TWO actions are appropriate containment strategies? (Choose two.)

Select 2 answers
A.Restoring the infected systems from a known good backup
B.Immediately deleting all files created in the last 24 hours on the infected systems
C.Applying a temporary firewall rule to block command-and-control traffic
D.Conducting a lessons learned meeting with the incident response team
E.Disconnecting the infected systems from the network
AnswersC, E

Blocking command-and-control traffic via firewall rules is a containment technique that cuts off attacker communication without necessarily disconnecting all systems. NIST SP 800-61 supports using network controls to contain incidents. This approach can be more surgical than full isolation, allowing business operations to continue while preventing further malicious activity. It is a valid containment strategy.

Why this answer

Containment strategies in NIST SP 800-61 focus on limiting the scope and impact of an incident. Disconnecting infected systems and blocking command-and-control traffic both prevent further spread or attacker communication. Deleting files, restoring backups, and holding lessons learned meetings are eradication, recovery, or post-incident activities, not containment.

The two correct actions directly stop the incident from expanding while analysis continues.

Exam trap

The trap here is confusing eradication and recovery actions with containment, when containment specifically aims to stop the spread without necessarily removing the threat.

879
MCQhard

A security engineer is implementing a cryptographic system that requires both confidentiality and integrity. The engineer decides to use AES-256 in Galois/Counter Mode (GCM). Which of the following statements about GCM is true?

A.GCM provides authentication but not confidentiality.
B.GCM is vulnerable to padding oracle attacks.
C.GCM can only be used with block sizes of 128 bits.
D.GCM requires a unique nonce for each encryption operation under the same key.
AnswerD

GCM is a nonce-based authenticated encryption mode. Reusing a nonce with the same key is catastrophic: it allows an attacker to recover the authentication key and potentially forge messages. Therefore, it is critical that each encryption operation uses a unique nonce. This is a fundamental requirement for the security of GCM.

Why this answer

GCM is an authenticated encryption mode that provides confidentiality and integrity. It requires a unique nonce for each encryption under the same key; nonce reuse compromises the authentication key and allows forgery. GCM does not use padding, so it is not susceptible to padding oracle attacks.

It is designed for 128-bit block ciphers like AES.

Exam trap

The trap here is assuming that GCM, like CBC, is vulnerable to padding oracle attacks or that it does not provide confidentiality.

880
MCQmedium

You work for a financial services firm that must comply with GDPR and PCI DSS. The company uses a cloud-based CRM to store customer data. The security team recently discovered that the CRM vendor had a data breach that exposed the company's customer records. An investigation shows that the breach occurred because the vendor did not have multi-factor authentication (MFA) enabled for administrative accounts. The contract with the vendor states that the vendor is responsible for security of their platform. However, your company had not conducted a risk assessment of the vendor before signing the contract. Management wants to improve risk identification for third-party relationships. Which of the following is the BEST long-term solution?

A.Implement a third-party risk management program with periodic security assessments and contractual security requirements
B.Demand that the vendor reimburse the company for breach costs
C.Cancel the contract with the vendor and move to a private cloud solution
D.Require all vendors to provide SOC 2 reports
AnswerA

A third-party risk management programme institutionalises pre-contract risk assessments, ongoing periodic security reviews and enforceable contractual security clauses, directly remedying the missing vendor assessment. This provides sustained identification and mitigation of supplier risk across GDPR and PCI DSS obligations.

Why this answer

A third-party risk management (TPRM) program with periodic security assessments and contractual security requirements directly addresses the root cause: the lack of pre-contract risk identification and ongoing vendor oversight. By embedding MFA requirements into contracts and performing regular assessments (e.g., reviewing SOC 2 reports, conducting penetration tests), the company can proactively enforce security controls like MFA for administrative accounts, preventing future breaches. This is a sustainable, long-term solution that aligns with GDPR and PCI DSS due diligence obligations.

Exam trap

The trap here is that candidates may choose Option D (SOC 2 reports) as a quick fix, mistakenly believing a single compliance report guarantees security, when in fact SOC 2 is a point-in-time audit that does not enforce ongoing contractual obligations or address specific risks like MFA configuration.

How to eliminate wrong answers

Option B is wrong because demanding reimbursement is a reactive, financial remedy that does not prevent future breaches; it fails to address the systemic lack of risk identification and vendor oversight. Option C is wrong because canceling the contract and moving to a private cloud solution is an extreme, short-term reaction that ignores the need for a scalable, ongoing vendor risk management process; it also may not be feasible or cost-effective for all third-party relationships. Option D is wrong because requiring SOC 2 reports alone is insufficient; while SOC 2 provides a snapshot of controls, it does not ensure continuous compliance or contractual enforcement of specific security measures like MFA, and it does not replace the need for periodic assessments tailored to the company's risk appetite.

881
Multi-Selectmedium

Which TWO of the following are characteristics of a Smurf attack? (Select TWO)

Select 2 answers
A.Requires fragmented packets
B.Uses ICMP echo requests
C.Exploits TCP SYN handshake
D.Targets DNS resolvers
E.Amplifies traffic by using broadcast addresses
AnswersB, E

The attacker sends ICMP echo requests with a spoofed source address to a network's broadcast address, so every host replies to the victim. This ICMP echo mechanism is the defining traffic characteristic of a Smurf attack.

Why this answer

Smurf attacks send ICMP echo requests to a broadcast address with a spoofed source IP, causing all hosts to reply to the victim, leading to amplification.

882
MCQmedium

Which of the following tools would best help a security team detect misconfigurations in a cloud environment, such as open storage buckets or overly permissive IAM roles?

A.Cloud Security Posture Management (CSPM)
B.Web Application Firewall (WAF)
C.Cloud Workload Protection Platform (CWPP)
D.Event Viewer
AnswerA

CSPM tools continuously scan cloud configurations against benchmarks and policies, surfacing open storage buckets and overly permissive IAM roles. This agentless posture assessment targets exactly the misconfiguration class described, unlike runtime workload protection or vulnerability scanners.

Why this answer

Cloud Security Posture Management (CSPM) tools are specifically designed to continuously monitor cloud environments for misconfigurations, compliance violations, and security risks such as open storage buckets and overly permissive IAM roles. They compare the actual configuration against best practices and benchmarks (e.g., CIS, NIST) and alert on deviations. This directly addresses the need to detect misconfigurations.

Exam trap

The trap is confusing CSPM with CWPP or WAF; candidates may think any cloud security tool detects misconfigurations, but only CSPM is purpose-built for posture management.

How to eliminate wrong answers

Option B is wrong because a Web Application Firewall protects web applications from HTTP-based attacks like SQL injection and XSS, but it does not assess cloud infrastructure configurations. Option C is wrong because a Cloud Workload Protection Platform focuses on securing workloads (VMs, containers, serverless) at runtime, including vulnerability management and threat detection, but not on cloud service configuration posture. Option D is wrong because Event Viewer is a Windows logging tool for local system events, not a cloud configuration scanner.

883
MCQhard

A DevOps team implements a CI/CD pipeline for a web application. Which security control is BEST to ensure that only properly reviewed code reaches production?

A.Run static application security testing (SAST) in the pipeline
B.Require a manual approval gate before deployment
C.Run automated unit tests and integration tests
D.Implement code signing for all artifacts
AnswerB

A manual approval gate inserts human review between build and deployment, ensuring unreviewed code cannot reach production. This satisfies the stem's requirement that only properly reviewed code is deployed, which automated scanning alone cannot guarantee.

Why this answer

Requiring a manual approval gate ensures a human has reviewed the code before deployment, which is the best way to ensure only properly reviewed code reaches production. Option A is wrong because SAST (static application security testing) is automated and may miss logic flaws or business logic issues that require human review. Option C is wrong because automated unit and integration tests verify functionality but do not constitute a code review; they can pass even if the code has logic errors or security issues not covered by tests.

Option D is wrong because code signing ensures the integrity and authenticity of artifacts but does not involve reviewing the code content for correctness or security.

884
MCQmedium

A company wants to enforce network access control (NAC) for both wired and wireless devices. Which protocol is used for this purpose?

A.802.1X
B.SNMP (Simple Network Management Protocol)
C.EAP (Extensible Authentication Protocol)
D.PAP (Password Authentication Protocol)
AnswerA

802.1X provides port-based network access control, authenticating devices via EAP before granting Layer 2 connectivity. It applies uniformly to wired switch ports and wireless associations, satisfying the requirement to enforce NAC across both media through a single authentication framework.

Why this answer

802.1X is the IEEE standard for port-based network access control (NAC) that authenticates devices before granting access to both wired and wireless networks. It operates at the data link layer and uses an authentication server (e.g., RADIUS) to validate credentials, ensuring only authorized devices connect to the network.

Exam trap

The trap here is confusing EAP (a framework) with 802.1X (the protocol that enforces NAC), leading candidates to pick EAP because it is directly involved in authentication, but it does not control network access itself.

How to eliminate wrong answers

Option B (SNMP) is wrong because it is a management protocol for monitoring and configuring network devices, not for enforcing access control or authentication. Option C (EAP) is wrong because it is an authentication framework used within 802.1X, not a standalone NAC protocol; it provides the transport for authentication methods but does not enforce port-based access control. Option D (PAP) is wrong because it is a simple, unencrypted password authentication protocol used in PPP, not designed for network access control in modern wired/wireless environments.

885
MCQeasy

After a major security incident, an organization's incident response team conducts a lessons learned meeting. The team identifies that the communication plan was unclear, leading to delays in notifying stakeholders. Which of the following should be the PRIMARY outcome of this meeting?

A.A set of actionable recommendations to update the incident response plan and improve future response efforts.
B.A decision to terminate the employees who failed to follow the communication plan.
C.An immediate upgrade of all security tools to prevent similar communication failures.
D.A formal report documenting the incident timeline and the names of individuals responsible for the delays.
AnswerA

The primary purpose of a lessons learned meeting is to identify what went well and what needs improvement, then produce actionable recommendations to enhance the incident response plan. This includes clarifying communication procedures, roles, and escalation paths. The outcome should be a documented set of changes that can be implemented and tested. This directly addresses the identified communication delays and helps prevent recurrence.

Why this answer

The primary outcome of a lessons learned meeting is a set of actionable recommendations to improve the incident response plan, including communication procedures. This ensures that identified weaknesses are addressed systematically. Documenting blame, terminating employees, or immediately upgrading tools do not directly resolve the process gaps and may not prevent future communication delays.

Exam trap

The trap here is focusing on punitive measures or tool purchases instead of process improvements, which are the true goal of a lessons learned meeting.

886
MCQhard

A company's security policy requires that all servers be hardened according to CIS Level 1 benchmarks. During an audit, it is discovered that a server has password complexity settings that exceed Level 1 requirements. Which of the following is the most appropriate action?

A.Report the non-compliance to management for remediation
B.Implement Level 2 benchmarks to be consistent
C.Immediately revert to Level 1 settings to ensure compliance
D.Document the deviation and accept the stronger configuration
AnswerD

Exceeding CIS Level 1 password complexity strengthens rather than weakens security, so the server still meets the benchmark's intent. The auditor should record the stronger setting as a documented deviation instead of forcing a downgrade to match the baseline exactly.

Why this answer

Exceeding CIS Level 1 password complexity requirements represents a stronger security posture, not a violation. CIS benchmarks define Level 1 as a minimum baseline of essential security controls, and deviations that improve security are acceptable as long as they are documented and formally accepted by management. The key principle is that compliance is measured against the minimum baseline, and stronger configurations are permitted with proper risk acceptance.

Exam trap

The trap here is that candidates mistakenly treat any deviation from a baseline as non-compliance, failing to recognize that exceeding the minimum requirements is acceptable and should be documented rather than reverted or escalated.

How to eliminate wrong answers

Option A is wrong because reporting non-compliance implies a violation, but exceeding Level 1 requirements is not a compliance failure—it is a stronger configuration that should be documented, not escalated as a finding. Option B is wrong because implementing Level 2 benchmarks is unnecessary and could introduce operational overhead or compatibility issues; the policy explicitly requires Level 1, and Level 2 is a separate, more restrictive set of controls not mandated here. Option C is wrong because immediately reverting to Level 1 settings would weaken security without justification, violating the principle of least privilege and potentially exposing the system to password-based attacks.

887
Multi-Selectmedium

Which TWO of the following are common techniques used in quantitative risk analysis?

Select 2 answers
A.Exposure Factor (EF)
B.Asset Value (AV)
C.Risk rating (High/Medium/Low)
D.Probability and impact matrix
E.Delphi technique
AnswersA, B

Exposure Factor quantifies the percentage of an asset's value lost in a single incident, feeding directly into SLE and ALE calculations. It is a numeric input, distinguishing quantitative analysis from qualitative techniques such as Delphi or scenario ranking.

Why this answer

Options A and B are correct because quantitative risk analysis relies on numeric monetary values: the Exposure Factor (EF) is the percentage of an asset's value that would be lost in a given incident, and the Asset Value (AV) is the monetary worth of the asset, both of which feed the Single Loss Expectancy (SLE = AV × EF) and Annualized Loss Expectancy (ALE = SLE × ARO) calculations. These are core measurable inputs that make the analysis truly quantitative. Options C, D, and E do not belong: a High/Medium/Low risk rating is qualitative, the probability and impact matrix is a qualitative technique that maps likelihood against consequence, and the Delphi technique is a qualitative expert-consensus method for estimating risk.

Exam trap

The SSCP exam often tests the distinction between qualitative and quantitative methods by listing qualitative tools (like risk ratings, probability-impact matrices, and Delphi) as distractors, expecting candidates to recognize that only metrics like EF, AV, SLE, and ALE are truly quantitative.

888
MCQhard

A security analyst is reviewing a proposed cryptographic design for a new messaging application. The design uses AES-256 in Galois/Counter Mode (GCM) for confidentiality and integrity, but the analyst notices that the same nonce is generated for multiple messages under the same key. What is the MOST likely security consequence of this flaw?

A.The integrity protection is broken, allowing an attacker to forge authentication tags and inject messages.
B.The performance of the encryption degrades because the nonce is used to seed the counter, causing counter collisions.
C.The confidentiality of the messages is lost because the keystream is reused, allowing XOR-based plaintext recovery.
D.The encryption key is immediately exposed, requiring rekeying of all sessions.
AnswerA

In GCM, nonce reuse under the same key is catastrophic because it allows an attacker to recover the authentication subkey H and forge valid tags. This breaks integrity and authenticity, enabling injection of arbitrary messages without detection. While confidentiality is also compromised, the primary and most severe consequence is the loss of integrity, which undermines the entire security guarantee of the messaging application.

Why this answer

In AES-GCM, the nonce must be unique for each encryption under a given key. Reusing a nonce allows an attacker to recover the GHASH subkey H and forge authentication tags, completely breaking integrity and authenticity. Although confidentiality is also weakened because the keystream repeats, the most critical consequence is the ability to inject undetected messages, which invalidates the application's trust model.

Exam trap

The trap here is focusing only on confidentiality loss from keystream reuse and overlooking that nonce reuse in GCM destroys integrity by enabling tag forgery.

889
MCQhard

A security analyst reviews logs and finds that an attacker exploited a vulnerability in a web application to read arbitrary files from the server. The application runs on Apache with mod_php. Which of the following is the MOST likely vulnerability?

A.XML External Entity (XXE) vulnerability.
B.Remote File Inclusion (RFI) vulnerability.
C.Server-Side Request Forgery (SSRF) vulnerability.
D.Local File Inclusion (LFI) vulnerability in a PHP include statement.
AnswerD

PHP include statements that accept user-supplied paths without validation let an attacker traverse the filesystem and read arbitrary files. Because the application runs mod_php, a Local File Inclusion flaw in an include call is the most likely mechanism enabling the observed arbitrary file reads.

Why this answer

The scenario describes reading arbitrary files from the server, which is the hallmark of a Local File Inclusion (LFI) vulnerability. In a PHP application using include statements, an attacker can manipulate a file path parameter (e.g., `?page=../../etc/passwd`) to include and read local files, exploiting the server's filesystem access. Apache with mod_php is particularly susceptible to LFI when user input is not sanitized before being passed to functions like `include()` or `require()`.

Exam trap

The trap here is that candidates confuse LFI with RFI because both involve file inclusion, but the key distinction is that LFI reads local files from the server, while RFI requires remote file inclusion, which is less common and often blocked by default PHP settings.

How to eliminate wrong answers

Option A is wrong because XML External Entity (XXE) exploits XML parsers to read files or perform SSRF, but the scenario does not mention XML processing or a parser; it focuses on a PHP include statement, making XXE an unlikely vector. Option B is wrong because Remote File Inclusion (RFI) involves including remote files from external servers (e.g., via HTTP), which requires `allow_url_include` to be enabled—a rare configuration—and the question specifies reading arbitrary files from the server, not remote hosts. Option C is wrong because Server-Side Request Forgery (SSRF) forces the server to make requests to internal or external resources, but it does not directly read arbitrary files via PHP include; it is more about accessing internal services or performing port scans.

890
MCQmedium

An organization uses Kerberos for single sign-on. When a user logs in, they receive a Ticket Granting Ticket (TGT). What is the primary purpose of the TGT?

A.To encrypt all network traffic
B.To obtain service tickets for accessing resources
C.To provide a digital signature for emails
D.To authenticate the user to the network
AnswerB

The TGT is issued by the Authentication Service after initial credential validation and is presented to the Ticket Granting Service to request service tickets. It proves the user's identity without re-entering credentials, enabling single sign-on for subsequent resource access.

Why this answer

The TGT is obtained from the Authentication Server (AS) and is used to request service tickets from the Ticket Granting Server (TGS) without re-entering credentials, enabling SSO.

891
MCQmedium

An administrator wants to ensure that a Linux web server only allows the www-data user to run specific commands with elevated privileges. Which configuration file should be modified?

A./etc/sudoers
B./etc/pam.d/
C./etc/chmod.conf
D./etc/selinux/config
AnswerA

The /etc/sudoers file defines which users may run which commands with elevated privileges, so a rule granting www-data only specific commands enforces least privilege. Editing it via visudo validates syntax and prevents locking out administrative access.

Why this answer

The /etc/sudoers file defines which users or groups may run which commands with elevated privileges via sudo. To allow www-data to run specific commands as root, you add entries there (typically using visudo). This enforces least privilege by limiting the commands the web user can execute with sudo.

Exam trap

SSCP often tests file-path knowledge; candidates confuse authentication configuration (PAM) with authorization for command execution (sudoers), or pick SELinux config thinking it controls privileges.

How to eliminate wrong answers

Option B is wrong because /etc/pam.d/ contains PAM configuration files for authentication, authorization, and session modules, not command-level sudo permissions. Option C is wrong because /etc/chmod.conf does not exist as a standard Linux configuration file; chmod is a command, not a config file. Option D is wrong because /etc/selinux/config controls SELinux mode (enforcing, permissive, disabled), not sudo command permissions.

892
MCQmedium

A Windows system administrator needs to enforce a security policy that prevents users from installing unauthorized software. Which feature should be configured via Group Policy?

A.Windows Defender Firewall
B.User Account Control (UAC)
C.AppLocker
D.BitLocker Drive Encryption
AnswerC

AppLocker applies allow or deny rules based on publisher, path, or file hash, blocking execution of unauthorised installers and applications. Configured through Group Policy, it directly enforces the software restriction the administrator needs, unlike firewall or audit settings.

Why this answer

AppLocker is a Windows application control feature configured via Group Policy that lets administrators allow or deny which applications and files users can run, directly preventing installation and execution of unauthorized software. It uses rules based on publisher, path, or file hash. This is the correct tool for enforcing an application allowlist/denylist through GPO.

Exam trap

SSCP often tests endpoint security controls, and candidates confuse UAC (elevation prompts) with AppLocker (application execution control), picking UAC when the requirement is preventing unauthorized software installation.

How to eliminate wrong answers

Option A is wrong because Windows Defender Firewall controls network traffic (ports, protocols, IPs), not which applications users can install or run. Option B is wrong because User Account Control prompts for elevation but does not block installation of unauthorized software if the user has admin rights or if the installer runs without elevation. Option D is wrong because BitLocker encrypts disk volumes to protect data at rest, not to control application execution.

893
MCQmedium

Refer to the exhibit. During a security review, an analyst finds these firewall rules. Which recommendation should be made to reduce risk?

A.Restrict the source for rule 10 to specific administrative IPs
B.Enable logging on rule 15 as well
C.Require VPN access for all internal traffic
D.Remove rule 15 entirely
AnswerA

Restricting rule 10's source to specific administrative IPs enforces least privilege on the management interface, which the exhibit shows exposed to any source. This directly satisfies the review's goal of reducing attack surface by limiting who can reach administrative services, rather than relying on broad network-level filtering alone.

Why this answer

Rule 10 allows SSH (TCP/22) from any source (0.0.0.0/0) to the internal server, which exposes the management interface to the entire internet. Restricting the source to specific administrative IPs reduces the attack surface by limiting who can initiate SSH connections, mitigating brute-force and unauthorized access risks. This aligns with the principle of least privilege and is a fundamental access control recommendation.

Exam trap

The trap here is that candidates may focus on logging (option B) or overly broad solutions (option C) instead of directly addressing the most critical risk—unrestricted inbound SSH access—which is the classic 'permit any any' mistake in firewall rules.

How to eliminate wrong answers

Option B is wrong because enabling logging on rule 15 (which likely permits all outbound traffic) does not reduce risk; it only improves visibility, but the rule itself remains overly permissive and could allow malicious outbound traffic. Option C is wrong because requiring VPN for all internal traffic is excessive and unnecessary; VPN is typically used for remote access, not for internal LAN traffic, and would add latency and complexity without addressing the specific exposure of rule 10. Option D is wrong because removing rule 15 entirely might break legitimate outbound connectivity (e.g., DNS, updates) and is not the most direct fix for the inbound SSH exposure; a more targeted approach is to restrict the source of rule 10.

894
MCQmedium

Which of the following best describes the concept of accountability in access controls?

A.Users must present multiple factors to gain access
B.Users must be uniquely identified and their actions logged
C.The system must verify the user's identity before granting access
D.The resource owner can delegate access to others
AnswerB

Accountability requires that each user be uniquely identified so actions can be traced back to a specific individual, with those actions recorded in logs. Shared or generic accounts break this, since activity cannot be attributed to one person.

Why this answer

Accountability in access control means that every action can be traced back to a uniquely identified individual, which requires both unique identification (no shared accounts) and logging of activity. This is what allows an organization to hold a specific person responsible for what was done with their credentials. It is distinct from authentication (proving identity) and authorization (what you're allowed to do).

Exam trap

SSCP often tests the distinction between authentication, authorization, and accountability — candidates frequently pick the authentication option (C) because it sounds like the 'security' answer, but accountability specifically requires unique identification plus logging, not just identity verification.

How to eliminate wrong answers

Option A is wrong because requiring multiple factors describes multi-factor authentication (MFA), which is an authentication strength control, not accountability. Option C is wrong because verifying identity before granting access describes authentication, which is a prerequisite for accountability but does not by itself provide it. Option D is wrong because delegating access describes authorization administration by a resource owner, which is a permission-management activity, not accountability.

895
Multi-Selecthard

Which TWO of the following are examples of preventive controls for data leakage?

Select 2 answers
A.Encryption.
B.Data Loss Prevention (DLP) system.
C.Log monitoring.
D.Security awareness training.
E.User access reviews.
AnswersA, B

Encryption renders stored or transmitted data unreadable without keys, so exfiltration yields ciphertext rather than usable records. As a preventive control it stops leakage at the point of access, satisfying the requirement to block disclosure before it occurs.

Why this answer

Encryption (A) is a preventive control because it renders data unreadable to unauthorized parties, so even if data is exfiltrated, it cannot be disclosed without the decryption key. A Data Loss Prevention (DLP) system (B) is preventive because it inspects data in motion, at rest, or in use and actively blocks or quarantines policy-violating transfers before leakage occurs. Log monitoring (C) is detective, not preventive, since it only records and alerts on events after they happen.

Security awareness training (D) is typically classified as administrative/awareness-oriented and does not technically block leakage at the point of action. User access reviews (E) are detective/administrative controls that verify entitlements periodically rather than preventing a leakage event in real time.

Exam trap

The trap here is that candidates often confuse detective controls (like log monitoring) or administrative controls (like training) with preventive controls, because they seem to 'prevent' issues indirectly, but the SSCP exam strictly classifies controls by their primary function—preventive controls must actively block the threat before it occurs.

896
Multi-Selectmedium

Which TWO of the following are valid reasons to deny a change request during the CAB approval process?

Select 2 answers
A.The change is outside the approved budget
B.The change request lacks a rollback plan
C.The change has a low priority
D.The change has not been tested in a staging environment
E.The change was requested by a junior staff member
AnswersB, D

Without a documented rollback plan, the CAB cannot verify the change is reversible if it fails, leaving no safe recovery path. This directly violates change management's requirement that every approved change carry a tested backout strategy.

Why this answer

Option B is correct because a change request without a rollback plan presents an unacceptable risk: if the change fails in production, the organization has no defined, tested way to revert to the prior known-good state, so the CAB should deny it until a rollback (backout) plan is documented. Option D is correct because untested changes have unverified behavior and unknown failure modes; the CAB should deny approval until the change has been validated in a staging environment that mirrors production, satisfying change validation and testing requirements. Option A is not a valid denial reason in itself, since budget is a financial approval matter handled separately from CAB risk assessment, and a change can still be technically sound.

Option C is not valid because low priority affects scheduling and sequencing, not approval; a low-priority change can still be approved and deferred. Option E is not valid because the requester's seniority is irrelevant — the CAB evaluates the change's risk, impact, and readiness, not who submitted it.

Exam trap

In the SSCP exam, the pitfall is confusing administrative or financial reasons (budget, priority, requester seniority) with operational risk factors (lack of rollback plan, no staging test). The CAB's primary focus is on operational risk and technical feasibility, so only items affecting the change's safety and reliability are valid grounds for denial.

897
MCQeasy

Refer to the exhibit. A security analyst notices that multiple internal hosts are using the same inside global IP address but different port numbers. Which technology is being used?

A.Dynamic NAT
B.Static NAT
C.PAT (Port Address Translation)
D.Port forwarding
AnswerC

PAT maps many inside private addresses to one inside global address, differentiating sessions by translating source port numbers. The shared global IP with distinct ports in the exhibit is the defining signature of port address translation, satisfying the constraint of conserving public IPv4 addresses.

Why this answer

The scenario describes multiple internal hosts sharing a single inside global IP address but using different port numbers. This is the defining behavior of Port Address Translation (PAT), also known as NAT overload. PAT maps multiple private IP addresses to one public IP by differentiating sessions based on the transport-layer port number (TCP/UDP), allowing many hosts to share a single public address.

Exam trap

The trap here is that candidates often confuse PAT with Dynamic NAT, not realizing that Dynamic NAT requires a pool of public IPs and does not allow port-level multiplexing, whereas PAT is specifically designed to allow many-to-one address sharing using port differentiation.

How to eliminate wrong answers

Option A is wrong because Dynamic NAT maps private IPs to public IPs from a pool on a one-to-one basis, so multiple internal hosts cannot share the same inside global IP; each would require a unique public IP. Option B is wrong because Static NAT provides a fixed one-to-one mapping between a private IP and a public IP, which also prevents multiple hosts from using the same global address. Option D is wrong because Port forwarding is a manual configuration that directs external traffic to a specific internal host and port, not a mechanism for multiple internal hosts to share a single public IP with different source ports.

898
MCQmedium

An organization is implementing Windows Defender Application Control (WDAC) to prevent unauthorized applications from running on company workstations. Which of the following best describes the primary security benefit of this approach?

A.It prevents execution of any application not explicitly allowed
B.It encrypts application binaries at rest
C.It automatically updates applications from a trusted source
D.It ensures that all applications are digitally signed
AnswerA

WDAC enforces an allowlist model: only applications matching explicitly permitted publisher, hash or path rules may execute, blocking all else by default. This directly satisfies the requirement to prevent unauthorised applications from running, unlike audit-only or reputation-based approaches.

Why this answer

WDAC is an application control mechanism that enforces an allowlist of approved code, blocking execution of any binary, script, or package not explicitly permitted by policy. This default-deny posture is its primary security benefit, preventing unauthorized or malicious executables from running even if they land on the endpoint.

Exam trap

SSCP often tests the distinction between application allowlisting (WDAC) and adjacent controls like encryption, patching, or code signing, baiting candidates who conflate prevention of execution with integrity or confidentiality controls.

How to eliminate wrong answers

Option B is wrong because WDAC does not encrypt binaries at rest — that is the role of BitLocker or similar full-disk encryption technologies. Option C is wrong because WDAC does not perform application updates; patching is handled by tools like Intune, WSUS, or Configuration Manager. Option D is wrong because WDAC does not require all applications to be digitally signed — it can allow unsigned code via hash rules or explicit file path rules, though signing is a recommended best practice.

899
MCQeasy

During a risk assessment, a team identifies that a legacy inventory application has no vendor support and cannot be patched. Leadership decides to accept the risk because replacing the application would cost more than the potential loss. Which term best describes this decision?

A.Risk transference
B.Risk avoidance
C.Risk mitigation
D.Risk acceptance
AnswerD

Acceptance means the organization acknowledges the risk and chooses to proceed without additional mitigation because the cost of controls or replacement exceeds the expected loss. Leadership weighed the replacement cost against the potential loss and decided to retain the risk. Documenting this decision in the risk register, with a review date, is essential so the acceptance remains a conscious, accountable choice rather than neglect.

Why this answer

When leadership evaluates a risk and consciously decides to continue operating without adding controls because remediation costs outweigh expected losses, the decision is risk acceptance. This must be documented and periodically reviewed so it remains an informed choice. It differs from avoidance, which eliminates the activity, and from transference, which shifts financial impact to another party.

Exam trap

The trap here is confusing acceptance with doing nothing; acceptance is a documented, deliberate decision, while neglect is an unmanaged exposure.

900
MCQeasy

A risk manager is calculating the annualized loss expectancy (ALE) for a server. The single loss expectancy (SLE) is $5,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE?

A.$25,000
B.$1,000
C.$5,000
D.$100
AnswerB

ALE is calculated by multiplying single loss expectancy by annualised rate of occurrence: $5,000 × 0.2 = $1,000. This expresses the expected yearly loss from the risk, letting the risk manager compare it against the cost of controls.

Why this answer

The annualized loss expectancy (ALE) is calculated by multiplying the single loss expectancy (SLE) by the annualized rate of occurrence (ARO). Here, SLE = $5,000 and ARO = 0.2, so ALE = $5,000 × 0.2 = $1,000. This represents the expected annual financial loss from the server risk.

Exam trap

The trap here is that candidates often confuse the ALE formula by dividing SLE by ARO instead of multiplying, leading to the inflated $25,000 figure in option A.

How to eliminate wrong answers

Option A is wrong because $25,000 results from dividing SLE by ARO ($5,000 / 0.2), which is a common arithmetic reversal error. Option C is wrong because $5,000 is simply the SLE value, ignoring the ARO multiplier entirely. Option D is wrong because $100 would come from multiplying SLE by ARO but misplacing a decimal (e.g., $5,000 × 0.02), indicating a calculation mistake.

Page 11

Page 12 of 13

Page 13