Courseiva

Systems Security Certified Practitioner SSCP (SSCP) — Questions 901–971

971 questions total · 13pages · All types, answers revealed

Page 12

Page 13 of 13

901
Multi-Selecteasy

Which TWO are common methods to secure a wireless network against unauthorized access?

Select 2 answers
A.Implement WPA2-Enterprise
B.Enable SSID broadcast
C.Disable DHCP
D.Use MAC filtering
E.Deploy a wireless intrusion prevention system (WIPS)
AnswersA, E

Provides strong authentication per user.

Why this answer

WPA2-Enterprise (option A) is correct because it uses IEEE 802.1X authentication with a RADIUS server, requiring each user or device to authenticate with unique credentials or certificates, which prevents unauthorized clients from joining even if they know the pre-shared key. A wireless intrusion prevention system (option E) is correct because a WIPS continuously monitors the RF spectrum for rogue access points, evil twins, and deauthentication attacks, and can automatically contain or block those threats. Enabling SSID broadcast (option B) actually advertises the network and does not secure it, since hidden SSIDs are not a real security control anyway.

Disabling DHCP (option C) only forces manual IP configuration and is easily bypassed by an attacker who assigns a static address. MAC filtering (option D) is weak because MAC addresses can be spoofed, so it does not reliably prevent unauthorized access.

Exam trap

The trap here is that candidates often mistake MAC filtering or disabling DHCP as effective security controls, when in fact they are easily bypassed and provide only a false sense of security, while the exam expects recognition of enterprise-grade authentication and active monitoring as the correct methods.

902
MCQmedium

A software development team is implementing input validation for a web application that accepts user email addresses. Which approach BEST prevents email injection attacks?

A.Whitelist allowed characters: alphanumeric, @, ., -, _
B.Blacklist known malicious email patterns
C.Set maximum email length to 100 characters
D.Rely on client-side JavaScript validation only
AnswerA

Whitelisting permitted characters (alphanumeric, @, ., -, _) rejects CRLF sequences and additional headers, the mechanism behind email injection. This input validation directly satisfies the stem's requirement to prevent injection through the email address field, rather than merely filtering known malicious patterns.

Why this answer

Whitelisting allowed characters (alphanumeric, @, ., -, _) restricts input to safe characters, effectively preventing injection of special characters used in email injection attacks. Option B is incorrect because blacklisting known malicious patterns is easily bypassed by attackers using novel patterns. Option C is incorrect because setting a maximum email length does not prevent injection of malicious characters within that length.

Option D is incorrect because client-side validation alone can be bypassed by disabling JavaScript or intercepting requests, so server-side validation is essential.

903
MCQmedium

An organization wants to reduce the likelihood that a terminated employee's credentials can still be used to access SaaS applications after departure. Which control BEST addresses this risk?

A.Conduct quarterly access reviews of all SaaS application user lists.
B.Integrate the identity provider with HR systems so account deactivation is triggered automatically on termination.
C.Enforce a stronger password complexity policy for all user accounts.
D.Require multi-factor authentication for all SaaS application logins.
AnswerB

Automating deactivation through an identity provider linked to HR status removes the manual delay that lets terminated credentials remain valid. When the HR record changes, the identity provider disables the account and revokes active sessions across federated SaaS applications, which directly reduces the window of exposure. This is the most effective control because it addresses the root cause rather than the symptom.

Why this answer

The core risk is that terminated credentials remain usable because deprovisioning depends on manual steps. Linking the identity provider to authoritative HR data automates deactivation and session revocation the moment employment status changes, closing the gap at its source. Complexity policies, MFA, and periodic reviews each reduce some exposure but none prevents a known valid credential from being used after departure.

Exam trap

The trap here is choosing a preventive-sounding control such as MFA or complexity policy when the actual weakness is the delay in revoking credentials that the departing employee already possesses.

904
Multi-Selectmedium

A security architect is designing an access control system for a healthcare application. The system must ensure that a nurse can view patient records but cannot modify them, and that a doctor can both view and update records. Additionally, the system must prevent a single user from both ordering a medication and approving its administration. Which TWO access control principles are being applied? (Select TWO.)

Select 2 answers
A.Discretionary access control
B.Separation of duties
C.Need to know
D.Mandatory access control
E.Least privilege
AnswersB, E

Splitting the medication workflow so no single user both orders and approves it enforces separation of duties, preventing one person from completing a sensitive transaction end to end. This satisfies the stem's explicit constraint that ordering and administration approval must remain with different individuals.

Why this answer

Least privilege ensures users have only the permissions needed (nurse view, doctor view/update). Separation of duties prevents a single user from performing conflicting actions (order and approve).

905
MCQeasy

Which protocol is used to provide secure remote shell access and replace Telnet?

A.SFTP
B.SSH
C.IPsec
D.HTTPS
AnswerB

SSH encrypts the entire session, including authentication credentials and commands, whereas Telnet transmits them in cleartext. This satisfies the stem's requirement for secure remote shell access and Telnet replacement. Operating over TCP port 22, SSH provides confidentiality and integrity that Telnet fundamentally lacks.

Why this answer

SSH (Secure Shell) is the correct answer because it provides encrypted remote shell access and command execution, replacing the insecure Telnet protocol which transmits data in cleartext. SSH uses public-key cryptography for authentication and symmetric encryption (e.g., AES, ChaCha20) for session confidentiality, as defined in RFC 4251.

Exam trap

In the SSCP exam, candidates often confuse SSH (remote shell) with SFTP (file transfer), mistakenly thinking SFTP is a replacement for Telnet when it actually relies on SSH for its secure transport.

How to eliminate wrong answers

Option A (SFTP) is wrong because SFTP (SSH File Transfer Protocol) is a file transfer protocol that runs over SSH, not a remote shell access protocol; it is used for secure file operations, not interactive shell sessions. Option C (IPsec) is wrong because IPsec is a network-layer security protocol suite used for encrypting IP packets (e.g., in VPNs), not for providing remote shell access or replacing Telnet. Option D (HTTPS) is wrong because HTTPS is HTTP over TLS, designed for secure web browsing, not for remote shell access or command-line interaction.

906
Multi-Selectmedium

An organization is implementing a privileged access management (PAM) solution. Which THREE of the following are common PAM capabilities?

Select 3 answers
A.Just-in-time (JIT) provisioning of privileged access
B.Single sign-on for all applications
C.Password vaulting for storing privileged credentials securely
D.Self-service password reset for end users
E.Recording and monitoring of privileged sessions
AnswersA, C, E

Just-in-time provisioning grants elevated rights only for a defined window, then revokes them automatically, directly satisfying PAM's need to eliminate standing privileges. This contrasts with permanent admin accounts, which persist indefinitely and widen the attack surface. JIT is a core PAM capability alongside credential vaulting and session recording.

Why this answer

PAM includes password vaulting, session recording, and just-in-time provisioning to secure privileged accounts.

907
MCQeasy

A small business uses MAC address filtering on its wireless network to prevent unauthorized access. Which attack is most likely to bypass this control?

A.Deauthentication attack
B.Man-in-the-middle attack
C.Evil twin attack
D.MAC spoofing
AnswerD

MAC spoofing directly defeats MAC address filtering because the attacker changes their network interface's hardware address to match an already-authorised device on the allowlist. The access point then permits the connection, satisfying the stem's constraint of bypassing the filter without needing valid credentials or breaking encryption.

Why this answer

MAC address filtering is a weak access control because MAC addresses are transmitted in plaintext over the air and can be easily captured using a wireless sniffer (e.g., Wireshark). An attacker can then change their network interface's MAC address to match an allowed client via MAC spoofing, thereby bypassing the filter and gaining access to the network. This attack directly defeats the filtering mechanism without needing to crack encryption keys or impersonate the access point.

Exam trap

The trap here is that candidates confuse MAC spoofing with deauthentication attacks, thinking that disconnecting a client is the primary method to bypass filtering, when in fact the attacker must spoof the allowed MAC to actually authenticate and gain network access.

How to eliminate wrong answers

Option A is wrong because a deauthentication attack disconnects clients from the access point but does not bypass MAC filtering—it only disrupts service, not authenticate the attacker. Option B is wrong because a man-in-the-middle attack intercepts traffic between two parties but requires the attacker to already be associated with the network, so it does not bypass the initial MAC filter. Option C is wrong because an evil twin attack creates a rogue access point with the same SSID to trick clients into connecting, but the attacker still needs to associate with the legitimate network or bypass its MAC filter to access internal resources.

908
MCQhard

A hospital uses a discretionary access control model on its file shares. A department head grants a colleague read access to a folder containing protected health information so they can cover a vacation. Months later an audit finds the access still active after the coverage ended. Which characteristic of discretionary access control most directly explains why this happened?

A.Permissions are derived from the user's job role rather than from individual grants.
B.Access decisions are enforced by system-wide labels that owners cannot override.
C.Resource owners can grant access at their own discretion, and no central authority automatically removes it.
D.The system enforces a strict need-to-know policy using centralized administration.
AnswerC

In discretionary access control the owner of a resource decides who receives access, and the system does not inherently revoke that access when the business need ends. Because the department head acted as owner and no centralized lifecycle process intervened, the permission persisted after the vacation coverage concluded. This decentralization of authority is the defining trait that produced the stale entitlement found during the audit.

Why this answer

Discretionary access control places grant authority with resource owners, which is flexible but creates lifecycle risk because nothing forces revocation when the original justification disappears. The stale protected health information access persisted until an audit surfaced it. Recognizing this characteristic explains why the hospital needs centralized entitlement review, time-bound access requests, and automated revocation rather than simply retraining the department head.

Exam trap

The trap here is blaming the user for forgetting to revoke access, when the real cause is the model's decentralized owner-controlled grants.

909
MCQmedium

An incident responder needs to create a forensic image of a suspect hard drive. Which of the following steps is ESSENTIAL to ensure the integrity of the evidence?

A.Run an antivirus scan on the drive before imaging
B.Use a write blocker to prevent modification of the original drive
C.Boot the suspect system to verify it is functional
D.Perform the imaging over the network to save time
AnswerB

A hardware write blocker intercepts write commands at the interface level, allowing reads while preventing any modification to the suspect drive. This preserves the original evidence's integrity, ensuring the forensic image is an admissible, verifiable copy.

Why this answer

Using a write blocker is essential because it ensures that no data can be written to the suspect hard drive during the imaging process, preserving the original evidence in a forensically sound state. Without a write blocker, any operating system or imaging tool could inadvertently modify metadata (e.g., access timestamps) or the file system, which would compromise the integrity and admissibility of the evidence in legal proceedings.

Exam trap

A common trap in SSCP is the misconception that booting the system or running software-based checks is acceptable. However, any interaction with the original drive that could alter its state—even a read-only mount without a write blocker—can change metadata and break the chain of custody.

How to eliminate wrong answers

Option A is wrong because running an antivirus scan on the drive before imaging could modify the drive's contents (e.g., by quarantining or deleting files), which violates forensic integrity principles. Option C is wrong because booting the suspect system can alter the system state, including writing to the drive (e.g., log files, temporary files), and may trigger anti-forensic mechanisms. Option D is wrong because performing imaging over the network introduces risks of data corruption, packet loss, or interception, and does not inherently prevent writes to the original drive; a write blocker is still required for forensic soundness.

910
MCQmedium

A hospital's IT department manages a network with hundreds of medical devices, including patient monitors and infusion pumps, all connected to a separate VLAN. The security team has identified that several devices are running outdated firmware with known vulnerabilities. The vendor has not released patches for these legacy devices. The hospital cannot replace them immediately due to budget constraints. The network team proposes moving the devices to a more restrictive firewall zone and implementing intrusion detection. Which of the following additional controls should be implemented to BEST reduce the risk of a breach exploiting these devices?

A.Conduct daily vulnerability scans on the device VLAN
B.Deploy host-based intrusion prevention on each device
C.Use a web application firewall (WAF) in front of the devices
D.Implement strict network segmentation and access control lists (ACLs) to allow only necessary traffic
AnswerD

Strict segmentation with ACLs limits lateral movement and blocks all traffic except what each device genuinely requires, containing any exploited legacy firmware. Since patching is unavailable, restricting reachability is the most effective compensating control for these unpatchable devices.

Why this answer

Strict network segmentation with ACLs limits lateral movement and restricts medical devices to only the traffic they require (e.g., specific management or telemetry flows). Since the devices cannot be patched or replaced, reducing their attack surface via network controls is the most effective compensating control. This directly addresses the risk of a breach exploiting outdated firmware.

Exam trap

SSCP often tests the difference between detective controls (scans, IDS) and preventive controls (segmentation, ACLs), and candidates may pick scanning or host-based tools that are impractical for legacy medical devices.

How to eliminate wrong answers

Option A is wrong because daily vulnerability scans detect issues but do not reduce the attack surface or prevent exploitation; they are detective, not preventive. Option B is wrong because host-based IPS cannot typically be installed on legacy medical devices, which often run closed embedded OSes and do not support third-party agents. Option C is wrong because a WAF protects web applications at the HTTP layer, while medical devices use proprietary protocols and are not web apps.

911
MCQhard

A medium-sized financial services company has recently deployed a new web application that processes sensitive customer data, including Social Security numbers and account balances. The security team implemented network segmentation, a web application firewall (WAF) from a reputable vendor, and quarterly vulnerability scans. The developers assert that they use parameterized queries for all database calls in the main application code. During a recent penetration test, testers successfully exploited a SQL injection vulnerability, extracting the entire customer database. Further investigation reveals that the main application indeed uses parameterized queries, but a third-party reporting module, integrated to generate compliance reports, constructs SQL queries by concatenating user-supplied date range inputs directly into SQL strings. The WAF is configured with a generic rule set and has not been tuned to the application's specific traffic patterns. What is the most effective course of action to remediate this vulnerability and prevent future occurrences?

A.Replace the third-party reporting module with an alternative that uses parameterized queries.
B.Implement strict input validation to sanitize user-supplied date inputs.
C.Increase the frequency of vulnerability scans from quarterly to monthly.
D.Configure the WAF to block SQL injection patterns with custom rules.
AnswerA

This directly removes the vulnerable coding practice (concatenation) and replaces it with a secure method, permanently fixing the SQL injection flaw.

Why this answer

The root cause is the third-party module's insecure query construction. Replacing it with a module that uses parameterized queries directly eliminates the vulnerability at its source. Input validation (A) is a defense-in-depth measure but not sufficient if concatenation is still used.

Increasing scan frequency (C) does not fix the underlying issue. Configuring the WAF (D) provides a layer of defense but can be bypassed and is not as reliable as eliminating the vulnerable code.

912
MCQeasy

Which of the following is the primary purpose of a configuration management database (CMDB)?

A.To provide a centralized repository of configuration items and their relationships
B.To track changes to network devices in real time
C.To automate the deployment of patches
D.To store backup copies of configuration files
AnswerA

A CMDB stores configuration items and the dependencies linking them, giving change and incident teams the impact visibility they need. This centralised record of assets and their relationships is precisely the repository function the question asks for, rather than monitoring, ticketing or licence tracking.

Why this answer

A configuration management database (CMDB) is a centralized repository that stores information about configuration items (CIs) and their relationships. Its primary purpose is to provide a single source of truth for managing IT assets, dependencies, and their interconnections, which is foundational for change management, incident management, and impact analysis.

Exam trap

In the SSCP exam, candidates may confuse the CMDB's role as a metadata repository with operational tools like change tracking systems or backup solutions. A CMDB is a vendor-neutral concept that stores configuration item data and relationships to support decision-making.

How to eliminate wrong answers

Option B is wrong because tracking changes to network devices in real time is a function of network monitoring tools (e.g., SNMP traps, NetFlow) or change detection systems, not the primary purpose of a CMDB. Option C is wrong because automating patch deployment is the role of patch management systems (e.g., WSUS, SCCM), while a CMDB stores CI data but does not execute deployment actions. Option D is wrong because storing backup copies of configuration files is a function of backup and version control systems (e.g., RANCID, Git), whereas a CMDB focuses on metadata and relationships, not file-level backups.

913
MCQmedium

After implementing a new IDS, the security team receives numerous alerts about legitimate traffic being flagged as malicious. This phenomenon is known as:

A.False positives
B.Noise
C.False negatives
D.True positives
AnswerA

Legitimate traffic flagged as malicious constitutes false positives: the IDS incorrectly classifies benign activity as an attack. This directly matches the stem's constraint of numerous alerts on genuine traffic, distinguishing it from false negatives, which would be malicious traffic mistakenly permitted. Tuning detection thresholds reduces these erroneous alerts.

Why this answer

A false positive occurs when the IDS incorrectly classifies legitimate traffic as malicious, generating an alert for benign activity. This is a common issue after deploying a new IDS with default or overly sensitive signature sets, leading to alert fatigue. The core reasoning is that the IDS's detection logic (e.g., pattern matching or anomaly thresholds) misidentifies normal behavior as an attack.

Exam trap

The trap here is that candidates confuse 'false positives' with 'noise' (Option B), but noise is a broader category that includes false positives as well as other irrelevant alerts, while the question specifically describes legitimate traffic being flagged as malicious, which is the precise definition of a false positive.

How to eliminate wrong answers

Option B (Noise) is wrong because noise refers to irrelevant or low-value alerts that may be triggered by benign events, but it is not the specific term for legitimate traffic flagged as malicious—noise often includes false positives but also encompasses other non-actionable alerts. Option C (False negatives) is wrong because false negatives occur when the IDS fails to detect actual malicious traffic, not when it flags legitimate traffic. Option D (True positives) is wrong because true positives are alerts that correctly identify actual malicious activity, which is the opposite of the scenario described.

914
MCQmedium

A security analyst is reviewing logs from a web application and notices numerous requests with the following pattern: GET /products?category=1' OR '1'='1. The analyst suspects a SQL injection attack. Which of the following is the MOST effective control to prevent this type of attack?

A.Deploy a web application firewall (WAF) to block SQL injection patterns.
B.Use parameterized queries (prepared statements) for all database access.
C.Implement input validation to reject requests containing single quotes.
D.Store the database in a read-only mode to prevent data modification.
AnswerB

Parameterized queries ensure that user input is treated as data, not executable code, by separating SQL logic from data. This prevents attackers from altering the query structure, effectively mitigating SQL injection regardless of the input's content. It is the most effective control for this vulnerability.

Why this answer

SQL injection occurs when user input is concatenated into SQL queries, allowing attackers to alter the query logic. Parameterized queries separate the query structure from the data, ensuring that input cannot change the intended SQL command. This is the most effective and reliable prevention method, as it addresses the root cause rather than relying on detection or input filtering.

Exam trap

The trap here is relying on input validation or a WAF as the primary defense, when they can be bypassed or may not cover all injection vectors.

915
MCQeasy

Which type of disaster recovery test involves running the DR systems alongside production systems to verify functionality without impacting operations?

A.Tabletop exercise
B.Full interruption test
C.Parallel test
D.Simulation test
AnswerC

A parallel test runs DR systems concurrently with production, processing transactions or workloads in isolation, so functionality is verified without disrupting live operations. This matches the stem's constraint of validating DR capability while leaving production systems unaffected.

Why this answer

A parallel test runs the disaster recovery (DR) systems in a live, non-disruptive manner alongside the production environment. This allows the organization to validate that the DR systems can process transactions and handle workloads correctly without affecting the primary production operations, making it the correct choice for verifying functionality without impact.

Exam trap

The trap here is that candidates often confuse a parallel test with a simulation test, thinking both are 'non-disruptive,' but a simulation test does not run DR systems alongside production and typically uses synthetic data, whereas a parallel test uses real production data and systems in a concurrent, non-interfering manner.

How to eliminate wrong answers

Option A is wrong because a tabletop exercise is a discussion-based walkthrough of roles and procedures, not an actual technical test of DR systems running alongside production. Option B is wrong because a full interruption test (also called a full-scale or hot start test) involves shutting down production systems and failing over to the DR site, which directly impacts operations. Option D is wrong because a simulation test mimics a disaster scenario in a controlled environment but does not run DR systems concurrently with production systems; it often uses isolated test beds.

916
MCQeasy

An administrator notices that a terminated employee's account is still active. Which access control process was likely skipped?

A.Authorization
B.Authentication
C.Provisioning
D.Accounting
AnswerC

Provisioning is the process that creates, maintains, and deactivates accounts in line with a user's employment status. A terminated employee's account remaining active shows the deprovisioning step was skipped, leaving credentials valid after the employment relationship ended.

Why this answer

Provisioning is the access control process that includes creating, modifying, and disabling user accounts and their associated privileges. When a terminated employee's account remains active, the de-provisioning step—specifically account revocation—was likely skipped, leaving the account enabled and accessible.

Exam trap

The trap here is that candidates confuse provisioning with authorization or authentication, thinking that account termination is about setting permissions (authorization) rather than the account lifecycle itself.

How to eliminate wrong answers

Option A is wrong because authorization determines what an authenticated user is allowed to do (e.g., read, write), not whether the account itself exists or is active. Option B is wrong because authentication verifies a user's identity (e.g., via password or certificate), not the lifecycle management of the account. Option D is wrong because accounting tracks user actions and resource usage (e.g., via logs or RADIUS accounting), not the creation or removal of accounts.

917
Multi-Selectmedium

A security administrator is evaluating encryption protocols for email communication. Which of the following protocols can secure email in transit? (Select TWO)

Select 2 answers
A.IMAPS
B.HTTPS
C.SSH
D.SMTPS
E.SFTP
AnswersA, D

IMAPS wraps IMAP within TLS, encrypting mail retrieval between client and server on port 993. This protects credentials and message content in transit, satisfying the requirement to secure email communication against interception during mailbox access.

Why this answer

IMAPS (Option A) is correct because it wraps the IMAP mail-retrieval protocol inside TLS (typically on TCP port 993), encrypting the client-to-server session so credentials and message contents are protected in transit. SMTPS (Option D) is correct because it applies TLS to SMTP (commonly on TCP port 465, or via STARTTLS on 587/25), securing the transport of outgoing email between mail clients and servers or between mail relays. HTTPS (Option B) secures web traffic via TLS but is not an email transport protocol, so it does not directly secure email in transit.

SSH (Option C) provides an encrypted remote-shell/tunneling channel and is not an email protocol, and SFTP (Option E) is a file-transfer protocol over SSH, unrelated to securing email delivery.

Exam trap

A common challenge on the SSCP exam is distinguishing between protocols that secure email in transit (IMAPS, SMTPS) versus protocols that secure other services (HTTPS for web, SSH for remote access, SFTP for file transfer). Candidates may confuse secure versions of unrelated protocols.

918
MCQhard

A security analyst receives a chain of custody form for a hard drive that was seized from a suspected insider threat. The form shows that the drive was handled by three individuals over two days. Which of the following is the PRIMARY reason for maintaining a chain of custody?

A.To prove that the evidence has not been tampered with and is admissible in legal proceedings
B.To determine the cost of the forensic investigation
C.To ensure the hard drive is stored in a secure location
D.To track the productivity of forensic analysts
AnswerA

The chain of custody documents every person who handled the drive and when, proving the evidence remained unaltered since seizure. This continuity is what allows the drive to be admitted in legal proceedings against the insider threat suspect.

Why this answer

The chain of custody is a documented chronological record of evidence handling, which is essential to demonstrate that the hard drive has not been altered, damaged, or substituted since seizure. Without this unbroken record, the evidence could be challenged as inadmissible in court under rules like the Federal Rules of Evidence (FRE) 901, which require authentication. This is the primary reason because legal admissibility hinges on proving integrity and continuity of custody.

Exam trap

(ISC)² often tests the distinction between the legal necessity of chain of custody (admissibility) versus operational tasks like storage or cost tracking, leading candidates to confuse a supporting activity (secure storage) with the primary purpose.

How to eliminate wrong answers

Option B is wrong because determining the cost of the forensic investigation is an administrative or budgeting concern, not the primary legal purpose of chain of custody. Option C is wrong because while secure storage is a component of proper evidence handling, the chain of custody specifically documents who had access and when, not just the storage location itself. Option D is wrong because tracking analyst productivity is a management metric unrelated to the forensic integrity and legal admissibility requirements that chain of custody is designed to satisfy.

919
MCQmedium

A company uses discretionary access control (DAC) for its file shares. A project manager creates a folder and wants to grant a team member read-only access. Which of the following best describes how access is determined in this model?

A.The team member must request access through a centralized approval workflow.
B.The project manager, as the owner of the folder, can set the permissions for the team member.
C.The team member's access is determined by their role in the organization.
D.The system administrator must assign a label to the folder and the user's clearance.
AnswerB

In discretionary access control, the owner of a resource has the discretion to grant or revoke access. Since the project manager created the folder, they are the owner and can assign read-only permission to the team member. This is the defining characteristic of DAC.

Why this answer

Discretionary access control (DAC) is characterized by the owner of the resource having the ability to determine who can access it and with what permissions. In this scenario, the project manager owns the folder and can grant read-only access to the team member. The other options describe characteristics of MAC, RBAC, or administrative approval processes, which are not inherent to DAC.

Exam trap

The trap here is confusing DAC with RBAC or MAC, assuming that access is determined by roles or labels rather than by the resource owner's discretion.

920
MCQeasy

An analyst notices unusual outbound traffic from a workstation to an external IP on port 445. Which protocol is likely being used?

A.HTTP
B.SMB
C.FTP
D.DNS
AnswerB

Port 445 carries SMB directly over TCP, so outbound traffic to an external address on that port indicates SMB exposure, satisfying the stem's requirement to identify the likely protocol. SMB's use here is anomalous because it normally stays within internal networks, making external connections a strong exfiltration or lateral-movement indicator.

Why this answer

Port 445 is the default port for Microsoft-DS (Direct Hosting of SMB over TCP/IP), which is used by the Server Message Block (SMB) protocol for file and printer sharing. Unusual outbound traffic on this port often indicates SMB activity, such as a workstation attempting to connect to a remote share or, in a security context, potential data exfiltration or lateral movement using SMB.

Exam trap

ISC2 often tests the association of well-known ports with their protocols, and the trap here is that candidates may confuse port 445 with NetBIOS (ports 137-139) or assume SMB only uses ports 137-139, forgetting that modern SMB over TCP/IP uses port 445 directly.

How to eliminate wrong answers

Option A is wrong because HTTP typically uses ports 80 (unencrypted) or 443 (TLS), not port 445. Option C is wrong because FTP uses ports 20 (data) and 21 (control), not port 445. Option D is wrong because DNS uses port 53 (UDP primarily, with TCP for zone transfers), not port 445.

921
MCQhard

During a penetration test, a security analyst captures a packet containing a gratuitous ARP reply that associates the attacker's MAC address with the default gateway's IP address. This is a classic indicator of which attack?

A.ARP spoofing
B.DHCP spoofing
C.MAC cloning
D.DNS poisoning
AnswerA

A gratuitous ARP reply that binds the gateway's IP to the attacker's MAC is the defining signature of ARP spoofing, poisoning victims' ARP caches so traffic destined for the gateway is redirected to the attacker for interception or modification.

Why this answer

A gratuitous ARP reply is an ARP packet sent without a prior request, typically used to announce a change in MAC-to-IP mapping. In this case, the attacker sends a gratuitous ARP reply claiming that the default gateway's IP address now maps to the attacker's MAC address. This poisons the ARP cache of other hosts on the network, causing them to send traffic destined for the gateway to the attacker instead.

This is the defining characteristic of ARP spoofing (also called ARP poisoning).

Exam trap

SSCP often tests the distinction between ARP spoofing and DHCP spoofing, as both can redirect traffic but operate at different layers and use different protocols; candidates may confuse the two if they overlook the specific mention of gratuitous ARP.

How to eliminate wrong answers

Option B is wrong because DHCP spoofing involves a rogue DHCP server offering false IP configuration (including a malicious default gateway), not a gratuitous ARP reply associating an attacker's MAC with the gateway's IP. Option C is wrong because MAC cloning (or MAC spoofing) refers to changing a device's MAC address to impersonate another device, but it does not inherently involve sending gratuitous ARP replies to poison ARP caches; the attack described is specifically about manipulating ARP mappings. Option D is wrong because DNS poisoning involves corrupting DNS cache records to redirect domain name resolution, not ARP traffic; it operates at the application layer (DNS) rather than the data link layer (ARP).

922
MCQmedium

A security administrator needs to dispose of hard drives that contain sensitive data. Which method provides the highest assurance that data cannot be recovered?

A.Deleting all files and emptying the recycle bin
B.Performing a quick format of the drive
C.Physically shredding the hard drives
D.Using a degausser to erase magnetic data
AnswerC

Physical shredding reduces the drive to fragments, so platters and controller chips cannot be read by any laboratory technique. Degaussing leaves solid-state media and some high-coercivity platters intact, and overwriting can miss bad sectors. Shredding therefore satisfies the stem's demand for the highest assurance of unrecoverable data.

Why this answer

Physically shredding the hard drives reduces them to small particles, making any recovery of magnetic or solid-state data physically impossible. This provides the highest level of assurance because the storage media itself is destroyed, not just the data on it. It is the recommended method for media containing highly sensitive data when reuse is not required.

Exam trap

The trap here is confusing 'erasing' with 'destroying' — candidates often pick degaussing because it sounds technical, but it does not provide the same assurance as physical shredding, especially for SSDs.

How to eliminate wrong answers

Option A is wrong because deleting files and emptying the recycle bin only removes file system references; the underlying data blocks remain intact and are easily recoverable with forensic tools. Option B is wrong because a quick format only rewrites the file system metadata and leaves the actual data sectors untouched, so recovery is still possible. Option D is wrong because a degausser only works on magnetic media and renders the drive unusable; it does not affect SSDs, and it provides less assurance than physical destruction because some high-coercivity drives may retain residual data.

923
MCQhard

A security engineer is deploying a Network Intrusion Detection System (NIDS) on a switched network. The engineer needs to ensure the NIDS can monitor all traffic passing through a critical switch port that connects to a server. Which technology should be configured on the switch to copy traffic from the server port to the NIDS monitoring port?

A.Link Aggregation Control Protocol (LACP)
B.Port mirroring (SPAN)
C.Spanning Tree Protocol (STP)
D.Virtual LAN (VLAN) trunking
AnswerB

Port mirroring, often called Switched Port Analyzer (SPAN) on Cisco switches, copies frames from one or more source ports to a designated destination port where a monitoring device is connected. This allows the NIDS to see all traffic passing through the server port without disrupting network flow. It is the standard method for enabling intrusion detection on switched networks.

Why this answer

Port mirroring (SPAN) is the correct technology because it copies traffic from a source port to a destination port, allowing a NIDS to monitor all traffic without being inline. STP, VLAN trunking, and LACP serve different purposes: loop prevention, carrying multiple VLANs, and link aggregation, respectively. None of them replicate traffic to a monitoring port.

Port mirroring is essential for passive monitoring in switched environments.

Exam trap

The trap here is assuming that any port that carries traffic (like a trunk or LACP bundle) will automatically provide full visibility to a monitoring device.

924
Multi-Selecthard

Which THREE of the following are types of application security testing that should be included in a secure SDLC?

Select 3 answers
A.Static application security testing (SAST)
B.Penetration testing
C.User acceptance testing (UAT)
D.Dynamic application security testing (DAST)
E.Load testing
AnswersA, B, D

SAST analyses source, bytecode or binaries without executing the program, flagging insecure coding patterns such as injection flaws and unchecked input early in development. It satisfies the stem's secure SDLC requirement by shifting detection left, before code reaches testing or production.

Why this answer

Static application security testing (SAST) (A) is correct because it analyzes source code, bytecode, or binaries without executing the application, catching flaws like injection or hardcoded secrets early in the secure SDLC. Penetration testing (B) is correct because it simulates real attacker techniques against the running system to validate exploitable vulnerabilities and the effectiveness of controls. Dynamic application security testing (DAST) (D) is correct because it tests the application in its running state, exercising inputs and observing responses to find runtime issues such as authentication, session, and configuration flaws.

User acceptance testing (C) is excluded because it verifies business requirements and usability, not security weaknesses, and load testing (E) is excluded because it measures performance, scalability, and stability under stress rather than identifying security defects.

Exam trap

SSCP often tests the confusion between security testing (SAST, DAST, pen testing) and non-security testing (UAT, load testing); candidates must recognize that UAT and load testing are not security-focused.

925
Multi-Selecthard

Which three of the following are best practices for securing a database? (Choose three.)

Select 3 answers
A.Encrypt sensitive data at rest
B.Use default passwords for database accounts
C.Implement row-level security
D.Apply the principle of least privilege for database users
E.Enable public access to the database
AnswersA, C, D

Encrypting sensitive data at rest protects the database files, backups and logs from disclosure if storage media or snapshots are compromised, satisfying the requirement to safeguard stored information. Encryption keys managed separately via Microsoft Entra ID or a hardware security module ensure attackers lacking key access cannot read exfiltrated data.

Why this answer

Option A is correct because encrypting sensitive data at rest (e.g., using Transparent Data Encryption or column-level encryption) protects the data even if the underlying storage media or backups are compromised. Option C is correct because row-level security restricts which rows a user can access based on their identity or role, enforcing fine-grained access control within a shared table. Option D is correct because applying the principle of least privilege ensures database users and applications receive only the minimum permissions needed, reducing the attack surface and limiting damage from compromised accounts.

Option B is not a best practice because default passwords are widely known and easily exploited; they should be changed immediately. Option E is not a best practice because enabling public access exposes the database to unauthorized internet-based attacks and should be restricted via firewalls, private endpoints, or VPC controls.

926
Multi-Selectmedium

Which two commands can be used to modify existing file permissions on a Linux system? (Select TWO)

Select 2 answers
A.chattr
B.setfacl
C.umask
D.chown
E.chmod
AnswersB, E

`setfacl` modifies access control lists, granting or revoking per-user and per-group permissions beyond the standard owner/group/other model. This satisfies the stem's requirement to modify existing file permissions, since ACL entries can be added, altered, or removed on files that already exist, without changing their base mode bits.

Why this answer

Option B, setfacl, is correct because it modifies existing file permissions by adding, modifying, or removing POSIX ACL entries (e.g., setfacl -m u:alice:rw file), which directly changes the access permissions on a file. Option E, chmod, is correct because it changes the existing permission bits (read/write/execute for user, group, and other) of a file or directory, for example chmod 640 file or chmod u+x file. Option A, chattr, does not set standard permissions; it changes extended filesystem attributes such as immutable (+i) or append-only (+a), so it is not a permission-modifying command in this sense.

Option C, umask, does not modify existing file permissions; it sets the default permission mask applied only when new files and directories are created. Option D, chown, changes file ownership (user and/or group), not the permission bits themselves, so it does not modify existing permissions.

Exam trap

ISC2 often tests the distinction between commands that modify existing permissions (`chmod`, `setfacl`) versus commands that set defaults for new files (`umask`) or change file ownership (`chown`), leading candidates to mistakenly select `umask` or `chown` as tools for altering current permissions.

927
MCQmedium

An organization needs to recover data from a backup after a ransomware attack. The backup was taken 12 hours ago, and the RPO is 4 hours. What is the impact?

A.The RPO is met because data can be recovered
B.The RPO is violated because more than 4 hours of data may be lost
C.The RTO is exceeded
D.The 3-2-1 rule is violated
AnswerB

A 12-hour-old backup means up to 12 hours of data could be lost, exceeding the 4-hour RPO. The recovery point objective defines maximum tolerable data loss, so this gap violates it regardless of restore speed. The impact is therefore an RPO breach.

Why this answer

RPO (Recovery Point Objective) defines the maximum acceptable data loss. If the backup is 12 hours old and RPO is 4 hours, the organization has lost 8 hours of data, exceeding the objective.

928
Multi-Selectmedium

Which TWO actions are appropriate during the containment phase of incident response?

Select 2 answers
A.Restoring data from backups
B.Removing malware from the system
C.Isolating the affected system from the network
D.Blocking malicious IP addresses at the firewall
E.Analyzing the root cause of the incident
AnswersC, D

Isolating the affected system from the network severs the attacker's access path and prevents lateral movement to other hosts. This is a containment action because it stops the incident spreading while evidence is preserved for later analysis.

Why this answer

During the containment phase of incident response, the primary goal is to stop the incident from spreading and to limit damage. Isolating the affected system from the network (Option C) immediately prevents lateral movement of the threat and further data exfiltration. Blocking malicious IP addresses at the firewall (Option D) is another containment action that cuts off communication with known command-and-control servers or attack sources, effectively containing the network-level impact.

Exam trap

ISC2 often tests the distinction between containment, eradication, and recovery phases, and the trap here is that candidates mistakenly classify malware removal or root cause analysis as containment actions, when they actually belong to later phases.

929
MCQeasy

A security administrator has been asked to establish baseline monitoring for a set of Linux web servers so that unexpected changes to critical system files are detected quickly. The administrator wants the tool to compute cryptographic hashes of files, store them, and alert when they change. Which of the following should the administrator deploy to meet this requirement?

A.A vulnerability scanner scheduled to run weekly against the server group
B.A network-based intrusion detection system watching the web server subnet
C.A security information and event management platform with syslog collection only
D.A host-based intrusion detection system performing file integrity monitoring
AnswerD

File integrity monitoring computes cryptographic hashes of critical files, stores the known-good values, and alerts when a hash changes, which is exactly the requirement. A host-based intrusion detection system running file integrity monitoring on each server provides this baseline change detection, making it the appropriate control for detecting unexpected modification of system files.

Why this answer

Detecting unexpected modification of critical system files requires periodic or real-time hashing of those files against a stored known-good baseline. File integrity monitoring, delivered by a host-based intrusion detection agent, performs exactly this function and generates alerts when hashes diverge, which no network sensor, log aggregator, or periodic vulnerability scan accomplishes.

Exam trap

The trap here is confusing general monitoring platforms with file integrity monitoring, when only a hashing-based agent detects changes to local files.

930
MCQeasy

An organization wants to prevent unauthorized applications from running on Windows workstations. Which Windows feature should be used to enforce application whitelisting?

A.User Account Control (UAC)
B.Windows Firewall with Advanced Security
C.Windows Defender Application Control (WDAC)
D.Windows Defender Antivirus
AnswerC

WDAC enforces application whitelisting by validating executables against code-integrity policies at the kernel level, blocking anything unsigned or untrusted. This directly satisfies the requirement to prevent unauthorised applications from running on Windows workstations, unlike AppLocker's weaker user-mode enforcement.

Why this answer

Windows Defender Application Control (WDAC) is Microsoft's application control feature that enforces application whitelisting by allowing only explicitly trusted code to run on Windows workstations. It uses code integrity policies (based on publisher, hash, or path) to block unauthorized executables, scripts, and drivers. WDAC is the modern successor to AppLocker and is built into Windows 10/11 and Windows Server.

Exam trap

SSCP often tests the distinction between preventive controls (WDAC/AppLocker) and detective controls (antivirus), so candidates who see 'prevent unauthorized applications' and pick 'Windows Defender Antivirus' fall for the detection-vs-prevention confusion.

How to eliminate wrong answers

Option A is wrong because User Account Control (UAC) only prompts for elevation when administrative privileges are requested; it does not restrict which applications can execute. Option B is wrong because Windows Firewall with Advanced Security filters network traffic by port, protocol, and IP address, not by application identity or code integrity. Option D is wrong because Windows Defender Antivirus is signature/heuristic-based malware detection, not a whitelisting enforcement mechanism — it detects known bad files rather than allowing only approved ones.

931
Multi-Selectmedium

Which TWO controls are examples of physical security controls that can help prevent unauthorized access to a data center? (Select TWO.)

Select 2 answers
A.Biometric readers
B.Encryption of data at rest
C.Mantraps
D.Firewalls
E.Intrusion detection system (IDS)
AnswersA, C

Biometric readers verify a unique physiological trait, such as a fingerprint or iris pattern, before releasing the door strike. Unlike a badge, credentials cannot be lent or duplicated, so the control satisfies the stem's requirement to prevent unauthorised access at the data centre perimeter.

Why this answer

Biometric readers (A) are physical security controls because they authenticate a person via a unique physical trait such as a fingerprint, iris, or retina before granting entry to the data center, directly preventing unauthorized physical access. Mantraps (C) are also physical controls: they use two interlocking doors with a small vestibule to allow only one person through at a time, preventing tailgating and piggybacking into the facility. Encryption of data at rest (B) is a logical/cryptographic control that protects data confidentiality but does not stop someone from physically entering the data center.

Firewalls (D) are logical network security controls that filter traffic, not physical access controls. An intrusion detection system (E) is a logical monitoring/detection control that alerts on malicious activity but does not physically prevent unauthorized entry.

Exam trap

The trap here is that candidates often confuse 'physical security controls' with 'technical/administrative controls'—for example, selecting encryption or firewalls because they 'secure' the data center, but they do not prevent physical entry.

932
MCQeasy

Which access control model allows the owner of a resource to determine who can access it and what privileges they have?

A.Mandatory Access Control (MAC)
B.Attribute-Based Access Control (ABAC)
C.Discretionary Access Control (DAC)
D.Role-Based Access Control (RBAC)
AnswerC

Discretionary Access Control satisfies the stem's requirement that a resource owner assigns permissions, since DAC grants each owner discretion over their own objects via access control lists. Unlike mandatory or role-based models, where central policy or job function dictates access, DAC places that authority directly with the owner.

Why this answer

DAC (Discretionary Access Control) is defined by the resource owner having discretion over who can access the resource and what permissions they receive. In DAC systems, ownership is the basis for control — the owner can grant, revoke, or modify access rights at will, typically via ACLs. This owner-driven discretion is the defining characteristic that separates DAC from the other models.

Exam trap

SSCP often tests the distinction between who controls access — the owner (DAC), the system/labels (MAC), the role (RBAC), or attributes/policy (ABAC) — so candidates who focus on 'how access is checked' rather than 'who decides' pick the wrong model.

How to eliminate wrong answers

Option A is wrong because MAC enforces access decisions based on system-assigned labels (e.g., Bell-LaPadula sensitivity levels) and the owner cannot override those policy decisions. Option B is wrong because ABAC evaluates attributes of subjects, objects, and environment against policy rules — access is determined by policy evaluation, not by owner discretion. Option D is wrong because RBAC grants access based on the subject's assigned role within the organization, not on ownership of the resource.

933
MCQmedium

A security engineer is designing a system that requires non-repudiation of data origin. Which cryptographic technique should be used?

A.Keyed hash (HMAC)
B.Digital signature using RSA or ECDSA
C.Hash function only
D.Symmetric encryption with a shared key
AnswerB

A digital signature binds the signer's private key to the message, letting any verifier confirm origin and integrity with the public key while the signer cannot later deny signing. RSA and ECDSA both provide this non-repudiation property.

Why this answer

Digital signatures using RSA or ECDSA provide non-repudiation of data origin because they bind the signer's identity to the data through a private key that only the signer possesses. The recipient can verify the signature with the corresponding public key, and the signer cannot later deny having signed the data, as the private key is uniquely under their control. This meets the legal and technical requirement for non-repudiation, unlike symmetric or hash-only methods.

Exam trap

The trap here is that candidates confuse integrity (provided by HMAC or hash) with non-repudiation, or assume a shared secret (HMAC or symmetric encryption) can prove origin, but only asymmetric digital signatures satisfy the legal requirement of non-repudiation.

How to eliminate wrong answers

Option A is wrong because a keyed hash (HMAC) uses a shared secret key between sender and receiver, which cannot prove which party generated the MAC, thus failing to provide non-repudiation. Option C is wrong because a hash function alone provides integrity but no authentication or proof of origin, as anyone can compute the same hash. Option D is wrong because symmetric encryption with a shared key does not provide non-repudiation; both parties possess the same key, so the sender can deny creating the ciphertext.

934
MCQmedium

A security engineer is deploying a new VPN concentrator that must use a symmetric encryption algorithm approved by NIST for protecting sensitive government data. The algorithm must operate as a block cipher with a 128-bit block size and support key sizes of 128, 192, and 256 bits. Which algorithm should the engineer select?

A.RSA
B.Blowfish
C.AES
D.3DES
AnswerC

AES is a symmetric block cipher standardized by NIST (FIPS 197) with a 128-bit block size and supported key sizes of 128, 192, and 256 bits. It is approved for protecting sensitive government data up to Top Secret when used with appropriate key lengths. This matches the engineer's requirements exactly.

Why this answer

AES is the only NIST-approved symmetric block cipher that meets all stated requirements: 128-bit block size and support for 128-, 192-, and 256-bit keys. It is widely implemented in VPN concentrators and is suitable for protecting sensitive government data. The other algorithms either have smaller block sizes, are asymmetric, or lack NIST approval for this use case.

Exam trap

The trap here is assuming that any well-known symmetric cipher is NIST-approved for government data, when only AES meets the block size and key length requirements.

935
Multi-Selecteasy

A company is implementing an access control system for a high-security environment. Which TWO of the following are characteristics of Mandatory Access Control (MAC)?

Select 2 answers
A.Permissions are assigned to roles.
B.Access rules are defined by the system, not users.
C.Users can grant access to other users.
D.Subjects and objects have security labels.
E.Access is based on the owner's discretion.
AnswersB, D

Mandatory Access Control enforces access decisions through a central authority using security labels and clearances, so users cannot alter permissions themselves. This satisfies the high-security constraint, where only the system assigns sensitivity labels and determines access, preventing user discretion or ownership-based control that discretionary models permit.

Why this answer

MAC uses labels for subjects and objects, and access decisions are based on clearance and classification. Users cannot change permissions.

936
MCQeasy

A company wants to implement a policy where no single individual can approve a purchase order and also receive the goods. Which access control principle does this enforce?

A.Rotation of duties
B.Separation of duties
C.Need to know
D.Least privilege
AnswerB

Separation of duties splits a sensitive transaction across different people so no single individual controls the whole process. Preventing one person from both approving a purchase order and receiving the goods enforces that principle directly.

Why this answer

This policy enforces separation of duties by ensuring that no single individual has the authority to both approve a purchase order and receive the goods. This control prevents fraud and errors by requiring two different people to complete related but conflicting tasks, which is a fundamental access control principle in financial and operational systems.

Exam trap

The trap here is that candidates often confuse separation of duties with least privilege, but least privilege focuses on minimizing permissions per role, whereas separation of duties mandates that conflicting tasks be split across multiple roles to prevent fraud or error.

How to eliminate wrong answers

Option A is wrong because rotation of duties involves periodically moving personnel between different roles to reduce the risk of collusion or skill stagnation, not preventing a single person from performing two conflicting tasks. Option C is wrong because need to know restricts access to information based on job requirements, not the segregation of conflicting operational steps. Option D is wrong because least privilege limits users to the minimum permissions necessary for their job functions, but does not specifically address the requirement that two separate individuals must handle approval and receipt of goods.

937
MCQmedium

A company deploys a web application that processes credit card payments. The development team uses parameterized queries for all database interactions. However, during a penetration test, the tester successfully injects malicious code into a search field and retrieves sensitive customer data. Which of the following is the most likely cause?

A.The application uses dynamic SQL despite parameterized queries for some fields.
B.The web server is misconfigured to allow directory traversal.
C.The database server has weak permissions allowing direct query execution.
D.The search field output is not sanitized, allowing stored XSS.
AnswerA

Parameterised queries only protect the specific statements where they are applied. If the search field concatenates user input into dynamic SQL, that path bypasses parameterisation entirely, permitting injection. The stem's successful retrieval of sensitive data confirms an unprotected query path, not a failure of parameterisation itself.

Why this answer

Parameterized queries prevent SQL injection only when they are actually used for the vulnerable input; if the search field is concatenated into a dynamic SQL string instead of being bound as a parameter, the injection succeeds despite parameterized queries being used elsewhere. The penetration test result — successful injection through the search field — points directly to that field bypassing parameterization.

Exam trap

SSCP often tests the assumption that 'we use parameterized queries' means the application is safe — candidates overlook that a single unparameterized code path (like a search field) reintroduces the vulnerability.

How to eliminate wrong answers

Option B is wrong because directory traversal allows reading files on the web server, not retrieving sensitive customer data from the database via injected code in a search field. Option C is wrong because weak database permissions would allow a compromised account to do more damage, but the injection itself still requires an unparameterized query to succeed; permissions are not the root cause here. Option D is wrong because stored XSS executes in a victim's browser and does not retrieve customer data from the database on the attacker's behalf — the symptom described is classic SQL injection, not XSS.

938
MCQhard

An organization implements a Privileged Access Management (PAM) solution. Which capability best describes granting temporary administrative rights just when needed?

A.Session recording
B.Just-in-time provisioning
C.Password vaulting
D.Role mining
AnswerB

Just-in-time provisioning grants elevated privileges only for the duration of a specific task, then revokes them automatically. This directly satisfies the PAM requirement for temporary administrative rights issued on demand, eliminating standing access. Unlike permanent role assignment, it enforces least privilege by limiting the exposure window during which credentials could be abused.

Why this answer

Just-in-time (JIT) provisioning grants elevated privileges only for the duration they are needed, then automatically revokes them. This directly matches the requirement of temporary administrative rights granted on demand. It reduces standing privilege and the window of exposure if credentials are compromised.

Exam trap

SSCP often tests the distinction between PAM capabilities that manage credentials (vaulting), audit sessions (recording), or analyze roles (mining) versus those that actually grant time-bound access (JIT) — candidates who focus on 'privileged access' broadly pick the wrong capability.

How to eliminate wrong answers

Option A is wrong because session recording captures and audits privileged sessions for compliance and forensics — it does not grant temporary rights. Option C is wrong because password vaulting stores and checks out privileged credentials securely; it manages secrets but does not by itself provide time-bound elevation. Option D is wrong because role mining analyzes existing entitlements to help design roles — it is an analytics/design activity, not a runtime privilege-granting capability.

939
MCQhard

During a security assessment, an analyst finds that multiple snapshots of a critical virtual machine are stored on the hypervisor host. Some snapshots are several months old. Which risk is MOST likely?

A.VM escape via snapshot file corruption
B.Unauthorized access to snapshot data
C.Reintroduction of unpatched vulnerabilities
D.Hypervisor memory exhaustion
AnswerC

Old snapshots preserve the VM's disk state from months earlier, including operating system and application versions that have since been patched. Restoring or reverting to such a snapshot reinstates those unpatched vulnerabilities, directly satisfying the stem's concern about stale, months-old snapshots retained on the hypervisor host.

Why this answer

Old VM snapshots preserve the exact state of the VM at the time of capture, including the OS and application binaries. If a VM is reverted to a months-old snapshot, any patches applied since then are lost, reintroducing known vulnerabilities that attackers can exploit. This is the most likely and direct risk of retaining stale snapshots on the hypervisor.

Exam trap

SSCP often tests snapshot risks — candidates focus on exotic threats like VM escape or data theft, missing the mundane but most probable risk: reverting to an unpatched state.

How to eliminate wrong answers

Option A is wrong because VM escape via snapshot file corruption is a theoretical and rare attack vector, not the primary risk of stale snapshots. Option B is wrong because unauthorized access to snapshot data is a confidentiality risk that depends on access controls, not on snapshot age. Option D is wrong because hypervisor memory exhaustion is a resource management issue unrelated to the age of snapshots; snapshots consume storage, not hypervisor RAM.

940
MCQmedium

Refer to the exhibit. A user at IP 10.0.0.1 reports that they cannot access a web server at 203.0.113.5 on port 443. What is the most likely cause?

A.The firewall only permits inbound traffic to specific IPs.
B.The firewall rule order is incorrect.
C.The firewall blocks all outbound traffic.
D.The firewall does not have a rule permitting outbound traffic.
AnswerD

A missing outbound firewall rule blocks the TCP handshake to 203.0.113.5 on port 443, matching the reported symptom exactly. Most firewalls deny outbound traffic by default, so no permit rule means the SYN never leaves 10.0.0.1, producing the connection failure described.

Why this answer

The user at 10.0.0.1 cannot reach 203.0.113.5:443, which indicates that outbound traffic to that destination is not permitted. Firewalls by default block all traffic unless explicitly allowed; if no rule permits outbound HTTPS (TCP/443) traffic, the connection will be dropped. The symptom (inability to access an external web server) points to a missing outbound rule, not an inbound rule issue.

Exam trap

The trap here is that candidates often focus on inbound rules when a user cannot reach an external server, forgetting that outbound traffic must also be explicitly permitted by the firewall's egress policy.

How to eliminate wrong answers

Option A is wrong because the problem is outbound from 10.0.0.1 to 203.0.113.5; inbound rules control traffic coming into the network, not traffic leaving it. Option B is wrong because rule order matters only when multiple rules conflict or overlap; here, there is no indication of any rule at all for outbound traffic, so order is irrelevant. Option C is wrong because if the firewall blocked all outbound traffic, no user could reach any external resource, but the question specifies only this user and this destination are affected, implying a selective block or missing rule.

941
MCQeasy

A small business wants to protect data stored on employee laptops. The security policy requires that if a laptop is lost or stolen, the data on its disk cannot be read by anyone without the proper authentication. Which of the following should be implemented?

A.A personal firewall
B.File integrity monitoring
C.Full disk encryption
D.A host-based intrusion detection system
AnswerC

Full disk encryption converts the entire drive contents into ciphertext so that data at rest is unreadable without the decryption key or authentication credential. If a laptop is lost or stolen, an attacker cannot extract files by removing the drive. This directly satisfies the requirement that lost-device data remain protected without proper authentication.

Why this answer

Full disk encryption ensures that data at rest is ciphertext and unreadable without the correct key or authentication, which is exactly the protection needed when a laptop is lost or stolen. The other controls address runtime monitoring, integrity, or network filtering and do not prevent offline disk reading. For portable devices, encryption is the foundational data-at-rest control.

Exam trap

The trap here is selecting a monitoring or network control that sounds security-related but operates only while the system is running, leaving the disk fully readable after physical theft.

942
MCQhard

A security administrator is configuring a firewall to allow outbound web traffic from internal users. The firewall must inspect the application layer data to block malicious URLs. Which type of firewall should be used?

A.Application proxy firewall
B.Stateless packet filter
C.Stateful firewall
D.Network Access Control (NAC) system
AnswerA

An application proxy firewall terminates and inspects traffic at Layer 7, examining HTTP request contents including URLs. This satisfies the requirement to inspect application-layer data and block malicious URLs, which packet-filtering firewalls cannot achieve since they only examine headers.

Why this answer

An application proxy firewall is correct because it operates at the application layer (Layer 7) and can inspect HTTP/HTTPS traffic to block malicious URLs. It acts as an intermediary, terminating the client connection and initiating a new one to the server, allowing deep inspection of application data. This meets the requirement to inspect application layer data for outbound web traffic.

Exam trap

The trap is assuming that a stateful firewall can inspect URLs because it tracks connections, but stateful firewalls only track state at Layers 3-4; application layer inspection requires a proxy or NGFW.

How to eliminate wrong answers

Option B is wrong because a stateless packet filter only examines headers (IP, port, protocol) and cannot inspect application layer payloads like URLs. Option C is wrong because a stateful firewall tracks connection state but still does not inspect application layer data such as HTTP URLs; it operates at Layers 3 and 4. Option D is wrong because NAC systems control device access to the network based on policy, not inspect outbound web traffic for malicious URLs.

943
MCQmedium

A security team detects lateral movement within the network. Which containment strategy should be applied first to limit the spread of the threat?

A.Disable user accounts associated with compromised systems.
B.Isolate the affected systems by disconnecting them from the network.
C.Block the attacker's IP addresses at the perimeter firewall.
D.Reimage all compromised systems immediately.
AnswerB

Disconnecting affected systems from the network immediately severs the attacker's command-and-control and lateral movement channels, satisfying the requirement to limit spread first. Isolation precedes eradication or credential resets because every minute of connectivity lets the adversary pivot to additional hosts.

Why this answer

Isolating affected systems by disconnecting them from the network is the immediate priority because it physically or logically severs the attacker's ability to propagate laterally via SMB, RDP, or other network protocols. This containment step stops the spread without destroying forensic evidence, which would be lost if systems were reimaged or powered off prematurely.

Exam trap

ISC2 often tests the misconception that blocking external IPs or disabling accounts is sufficient for containment, when in fact internal lateral movement requires immediate network-level isolation of the compromised host.

How to eliminate wrong answers

Option A is wrong because disabling user accounts does not stop an attacker who has already established remote access via a service account, kernel-level backdoor, or cached credentials; the compromised system remains on the network and can still be used for lateral movement. Option C is wrong because blocking IP addresses at the perimeter firewall is ineffective against internal lateral movement, which occurs on the LAN and does not traverse the perimeter; the attacker can also easily change IP addresses or use internal routing to bypass the block. Option D is wrong because reimaging destroys volatile evidence (e.g., memory dumps, active network connections) and takes too long, allowing the attacker to continue spreading while the system is being rebuilt; containment must precede eradication.

944
MCQhard

During a security audit, it is discovered that a developer has direct access to production databases. The policy requires that changes be reviewed and deployed by a separate team. Which control is being violated?

A.Need-to-know
B.Job rotation
C.Least privilege
D.Separation of duties
AnswerD

Separation of duties requires that the person authoring a change differs from the person deploying it. The developer holding direct production database access and making unreviewed changes concentrates both duties in one individual, violating that control.

Why this answer

The scenario describes a direct violation of separation of duties (SoD), a core access control principle that requires critical tasks to be divided among multiple individuals to prevent fraud or error. In this case, the developer both writes code and has direct access to production databases, bypassing the required review and deployment by a separate team. SoD ensures no single person has end-to-end control over a sensitive process, which is essential for maintaining integrity and accountability in production environments.

Exam trap

A common mistake is confusing least privilege with separation of duties. Least privilege restricts access to only what is needed, while separation of duties divides critical tasks among multiple people to prevent fraud or error.

How to eliminate wrong answers

Option A is wrong because need-to-know restricts access to only the information necessary for a user's job role, but the violation here is about the process of change management, not about the developer having access to specific data they don't need. Option B is wrong because job rotation is a control that periodically moves employees between roles to reduce risk of collusion or monotony, but the issue is not about rotating roles; it's about the developer performing both development and production deployment tasks. Option C is wrong because least privilege limits users to the minimum permissions required for their duties, but the developer may have exactly the permissions needed for their job; the violation is that they are performing two conflicting duties (development and production deployment) that should be separated.

945
MCQhard

During a security audit, a penetration tester successfully extracts the PMKID from a wireless beacon. What information can be derived from this attack?

A.The PMK (pairwise master key) directly
B.The ability to crack the passphrase offline
C.The encryption keys used in the session
D.The PSK (pre-shared key) directly
AnswerB

Extracting the PMKID from a single beacon frame enables offline brute-force or dictionary attacks against the WPA2 passphrase, without requiring a full four-way handshake capture or client interaction. This satisfies the scenario's constraint: deriving the network passphrase from minimal captured data.

Why this answer

The PMKID attack captures the PMKID from a wireless beacon or association frame, which is derived from the PMK and other values. This PMKID can be used to perform an offline brute-force or dictionary attack against the passphrase (PSK). The attacker cannot directly derive the PMK or PSK from the PMKID, but can attempt to crack the passphrase offline.

Exam trap

SSCP often tests the distinction between the PMKID and the actual keys, and candidates may incorrectly assume that capturing the PMKID directly yields the PSK or PMK, when in fact it only enables an offline cracking attempt.

How to eliminate wrong answers

Option A is wrong because the PMK (pairwise master key) cannot be directly derived from the PMKID; the PMKID is a hash of the PMK and other values, and reversing it is computationally infeasible. Option C is wrong because the encryption keys used in the session (such as the PTK) are derived after a successful 4-way handshake and are not exposed by the PMKID. Option D is wrong because the PSK (pre-shared key) is the passphrase itself, and it cannot be directly extracted from the PMKID; it must be cracked offline.

946
MCQhard

A company uses a SIEM to monitor security events. Recently, they are experiencing false positives from a new IDS rule. Which approach would best reduce false positives while maintaining detection?

A.Disable the rule.
B.Increase the log review frequency.
C.Whitelist false positive sources.
D.Adjust the rule threshold.
AnswerD

Raising the rule threshold means the signature fires only when activity exceeds a defined count or frequency, filtering benign single events while still alerting on genuine patterns. This preserves detection coverage rather than disabling the rule entirely.

Why this answer

Adjusting the rule threshold (Option D) is the best approach because it fine-tunes the sensitivity of the IDS rule to reduce false positives without completely disabling detection. By raising the threshold (e.g., increasing the number of matching packets or the time window), the SIEM will only generate an alert when the rule's criteria are met more persistently, filtering out noise while still capturing genuine threats. This maintains the rule's detection capability for actual attacks that exceed the adjusted threshold.

Exam trap

The trap here is that candidates often choose to whitelist false positive sources (Option C) because it seems like a quick fix, but this approach can inadvertently suppress alerts for real attacks from those same sources, whereas threshold tuning preserves detection capability.

How to eliminate wrong answers

Option A is wrong because disabling the rule eliminates detection entirely, which could allow real attacks to go unnoticed and violates the principle of maintaining detection. Option B is wrong because increasing log review frequency does not reduce false positives; it only increases the volume of alerts to review, potentially overwhelming analysts and not addressing the root cause of the false positives. Option C is wrong because whitelisting false positive sources only suppresses alerts from those specific sources, which can mask legitimate attacks originating from the same sources and does not address the underlying rule sensitivity issue.

947
MCQmedium

An analyst reviewing the risk register notices that a web application vulnerability has an annualized loss expectancy (ALE) of $40,000 before controls. A web application firewall (WAF) would cost $12,000 per year to operate and is expected to reduce the ALE to $10,000. Based on this quantitative analysis, what should the analyst recommend?

A.Recommend the WAF because the control cost of $12,000 is less than the $30,000 reduction in annualized loss expectancy.
B.Recommend against the WAF because the annualized loss expectancy is still $10,000 after implementation.
C.Recommend against the WAF because the $12,000 cost exceeds ten percent of the original $40,000 annualized loss expectancy.
D.Recommend the WAF only if the residual annualized loss expectancy can be reduced to zero.
AnswerA

The control yields a $30,000 annual reduction in expected loss and costs $12,000 to operate, producing a net benefit of $18,000 per year. Since the cost is clearly below the mitigated loss, the quantitative analysis supports implementing the WAF as a cost-effective risk mitigation measure.

Why this answer

Quantitative risk analysis compares the annual cost of a control with the reduction in annualized loss expectancy it produces. The WAF cuts expected loss by $30,000 while costing $12,000 per year, yielding a positive net benefit of $18,000. That favorable relationship is the basis for recommending implementation; the residual loss simply reflects that no control eliminates risk entirely.

Exam trap

The trap here is fixating on the residual annualized loss expectancy instead of comparing the control's cost against the loss it actually prevents.

948
MCQmedium

Which federated identity protocol uses XML-based assertions and provides single sign-on across different security domains?

A.Kerberos
B.OAuth 2.0
C.OpenID Connect
D.SAML
AnswerD

SAML satisfies the cross-domain single sign-on requirement by exchanging XML-based assertions between an identity provider and service provider. Its assertion format carries authentication and attribute statements, enabling federated trust across separate security domains without sharing credentials, which matches the stem's specified XML assertion and SSO constraints precisely.

Why this answer

SAML (Security Assertion Markup Language) is an XML-based federated identity protocol that uses assertions to convey authentication and authorization information between identity providers and service providers. It enables single sign-on across different security domains by allowing a user authenticated at one domain to access resources in another without re-authenticating.

Exam trap

SSCP often tests whether candidates confuse SAML (XML-based, authentication/SSO) with OAuth 2.0 (JSON-based, authorization) and OpenID Connect (JSON/JWT-based, authentication layer on OAuth), so the XML assertion detail is the key discriminator.

How to eliminate wrong answers

Option A is wrong because Kerberos is a ticket-based authentication protocol that uses symmetric key cryptography and does not use XML assertions; it operates within a realm and is not typically described as a federated identity protocol for cross-domain SSO in the web sense. Option B is wrong because OAuth 2.0 is an authorization framework, not an authentication protocol, and it uses JSON tokens (access tokens), not XML assertions. Option C is wrong because OpenID Connect is built on OAuth 2.0 and uses JSON Web Tokens (JWTs), not XML assertions, for identity information.

949
MCQhard

A multinational corporation has a disaster recovery plan with a Recovery Time Objective (RTO) of 2 hours for its customer-facing e-commerce platform. During a regional power outage, the primary data center goes offline. The DR team activates the hot site, but the database replication lag causes the e-commerce platform to come online after 5 hours. Which of the following should the incident response team do FIRST after restoring services?

A.Immediately fail back to the primary data center without testing.
B.Terminate the DR team lead for failing to meet the RTO.
C.Update the DR plan to reflect the actual recovery time achieved.
D.Conduct a root cause analysis of the replication lag and RTO miss.
AnswerD

After restoring services, the team should investigate why the hot site failed to meet the 2-hour RTO, focusing on database replication lag. A root cause analysis identifies whether the lag was due to bandwidth, configuration, or capacity issues, enabling corrective actions. This aligns with post-incident activity and ensures the DR capability is improved for future outages.

Why this answer

After restoring services, the incident response team should perform a root cause analysis to understand why the hot site did not meet the 2-hour RTO. The replication lag is a technical issue that must be diagnosed and corrected to improve DR readiness. Punitive actions, plan normalization, or untested failback do not address the underlying cause and could worsen future outcomes.

Exam trap

The trap here is focusing on restoring services or updating documentation, when the critical next step is to analyze why the RTO was missed and fix the root cause.

950
MCQhard

During an application security review, a penetration tester discovers that a web application allows users to view other users' profiles by changing an ID parameter in the URL (e.g., /profile?id=123). Which OWASP Top 10 vulnerability does this represent?

A.Broken Authentication
B.Security Misconfiguration
C.Insecure Direct Object References (IDOR)
D.Injection
AnswerC

Manipulating the id parameter grants access to another user's profile because the application trusts client-supplied input without verifying ownership. This is IDOR: an authorisation flaw where the object reference is exposed and no access control check confirms the requester's entitlement to that record.

Why this answer

Insecure Direct Object Reference (IDOR) occurs when an application exposes an internal object identifier (like a user ID in a URL) and fails to verify that the requesting user is authorized to access that object. Changing /profile?id=123 to another ID to view another user's profile is the classic IDOR pattern. It falls under OWASP's Broken Access Control category (A01:2021).

Exam trap

SSCP often tests the confusion between Broken Authentication and Broken Access Control, so candidates who see 'changing an ID' and pick Broken Authentication miss that authentication is about identity, while IDOR is about authorization to access a specific object.

How to eliminate wrong answers

Option A is wrong because Broken Authentication refers to flaws in login, session management, or credential handling (e.g., weak password policies, session fixation), not to authorization checks on object access. Option B is wrong because Security Misconfiguration involves insecure default settings, verbose errors, or unnecessary features enabled — not missing per-object authorization. Option D is wrong because Injection involves untrusted input being interpreted as code or commands (SQLi, command injection), whereas IDOR is an access control flaw with no code execution.

951
MCQeasy

After a major security incident, an organization conducts a lessons learned meeting. Which of the following is the PRIMARY purpose of this meeting?

A.To identify improvements to the incident response process.
B.To calculate the financial cost of the incident.
C.To inform the public about the incident details.
D.To determine which team members should be disciplined.
AnswerA

The lessons learned meeting is held to review the incident and identify what went well and what could be improved. The primary outcome is to update policies, procedures, and training based on the findings. This helps the organization respond more effectively to future incidents. It is not about assigning blame or punishing individuals.

Why this answer

The lessons learned meeting is a post-incident review aimed at improving the incident response process. It brings together the response team to discuss what happened, what worked, and what didn't, with the goal of updating procedures, training, and tools. It is not about punishment, cost calculation, or public disclosure, although those may be separate follow-up activities.

Exam trap

The trap here is thinking the meeting is for assigning blame or calculating costs, but its core purpose is process improvement.

952
MCQeasy

An organization wants to perform a risk analysis for a new cloud application. Which quantitative metric is most commonly used to calculate risk?

A.Control effectiveness.
B.Threat likelihood.
C.Residual risk.
D.Annualized Loss Expectancy (ALE).
AnswerD

Annualized Loss Expectancy quantifies risk financially by multiplying the Single Loss Expectancy by the Annualized Rate of Occurrence, yielding a monetary yearly figure. This satisfies the stem's demand for a quantitative metric, unlike qualitative approaches that rank risk descriptively. ALE expresses expected annual loss in currency, enabling direct cost-benefit comparison.

Why this answer

Annualized Loss Expectancy (ALE) is the most commonly used quantitative metric for calculating risk because it combines the expected financial loss from a single event (Single Loss Expectancy) with the annual frequency of that event (Annualized Rate of Occurrence). This produces a dollar-value risk figure that organizations can directly compare against security control costs and budget decisions for a cloud application.

Exam trap

The trap here is that candidates confuse 'threat likelihood' (a qualitative input) with the complete quantitative risk metric, failing to recognize that ALE incorporates both likelihood and impact into a single financial figure.

How to eliminate wrong answers

Option A is wrong because control effectiveness is a qualitative or semi-quantitative measure of how well a safeguard reduces risk, not a direct quantitative risk metric. Option B is wrong because threat likelihood is only one component of risk calculation (used in ARO), not a complete risk metric itself. Option C is wrong because residual risk is the risk remaining after controls are applied, which is an output of risk analysis, not the primary quantitative metric used to calculate initial risk.

953
MCQeasy

Which of the following network protocols operates on TCP port 22 and provides secure remote administration of network devices?

A.SSH
B.Telnet
C.RDP
D.FTP
AnswerA

SSH listens on TCP port 22 and encrypts the entire session, providing secure remote administration of network devices. Telnet offers similar administration but transmits credentials in cleartext on port 23, so SSH uniquely satisfies both the port and security constraints.

Why this answer

SSH (Secure Shell) operates on TCP port 22 and provides encrypted remote administration of network devices, replacing insecure protocols like Telnet. It uses strong cryptography for authentication and session confidentiality, making it the standard for secure CLI management of routers, switches, and servers.

Exam trap

The trap here is confusing port numbers and protocol purposes — candidates may associate RDP with 'remote administration' and pick it, forgetting that RDP is GUI-based on port 3389, while the question specifies TCP port 22 and secure CLI administration.

How to eliminate wrong answers

Option B is wrong because Telnet uses TCP port 23 and transmits all data, including credentials, in cleartext, offering no confidentiality or integrity. Option C is wrong because RDP uses TCP port 3389 and provides graphical remote desktop access to Windows systems, not secure CLI administration of network devices. Option D is wrong because FTP uses TCP ports 20/21 for file transfer and does not provide remote administration or encryption (unless FTPS/SFTP variants are used).

954
Multi-Selecthard

A security analyst is reviewing OWASP Top 10 vulnerabilities in a web application. Which TWO are injection-related attacks? (Select TWO.)

Select 2 answers
A.Security Misconfiguration
B.Cross-Site Scripting (XSS)
C.Cross-Site Request Forgery (CSRF)
D.Insecure Direct Object References (IDOR)
E.SQL injection
AnswersB, E

Cross-Site Scripting injects malicious scripts into content served to other users, exploiting unvalidated input rendered without output encoding. This satisfies the injection criterion: untrusted data is interpreted as executable code by the victim's browser, distinct from server-side SQL or command injection, but still an injection flaw within the OWASP Top 10.

Why this answer

Cross-Site Scripting (XSS) (B) is correct because it is an injection attack in which attacker-supplied JavaScript is injected into a web page and executed in a victim's browser, typically via unescaped user input rendered into HTML, allowing session theft or DOM manipulation. SQL injection (E) is correct because it injects malicious SQL statements through unsanitized input into a database query, enabling data exfiltration, authentication bypass, or command execution on the DBMS. Both belong to the injection class of attacks where untrusted data is interpreted as code or commands by an interpreter.

Security Misconfiguration (A) is a configuration weakness, not an injection flaw. Cross-Site Request Forgery (CSRF) (C) abuses a victim's authenticated session to force unintended requests, not code injection. Insecure Direct Object References (IDOR) (D) is an access-control flaw where object identifiers are manipulated to reach unauthorized resources, not an injection attack.

Exam trap

The trap here is that candidates see 'web application attack' and lump CSRF or IDOR in with injection, forgetting that injection specifically requires untrusted input being interpreted as code by a parser or engine.

955
MCQhard

A security engineer is reviewing the configuration of a web application that uses JSON Web Tokens (JWT) for session management. The engineer notices that the application accepts tokens signed with the 'none' algorithm. Which of the following is the most critical security risk associated with this configuration?

A.Tokens will be transmitted in plaintext, exposing sensitive information.
B.Tokens will expire prematurely, causing denial of service for legitimate users.
C.The application will experience performance degradation due to lack of signature verification.
D.Attackers can forge tokens with arbitrary claims, leading to privilege escalation.
AnswerD

When the 'none' algorithm is accepted, the token's signature is not verified. An attacker can modify the token's payload, such as changing the user role to admin, and set the algorithm to 'none' to bypass signature validation. This allows forging tokens with arbitrary claims, resulting in unauthorized access and privilege escalation.

Why this answer

Accepting the 'none' algorithm means the application does not verify the token's signature. An attacker can craft a token with any claims and set the algorithm to 'none', bypassing authentication and authorization. This is a critical vulnerability that can lead to full account takeover and privilege escalation.

Exam trap

The trap here is focusing on transport or performance issues when the core risk is the loss of integrity and authenticity due to missing signature verification.

956
MCQhard

A security administrator is deploying a new web application on a Linux server and wants to prevent an attacker who compromises the web server process from reading the application's private TLS keys stored on the same host. The administrator decides to use a hardware security module (HSM) to protect the keys. Which of the following BEST describes how the HSM provides this protection?

A.The HSM stores the private keys in a file encrypted with a passphrase that only the web server process knows.
B.The HSM encrypts the private key with a key derived from the server's TPM and stores the ciphertext on disk.
C.The HSM performs cryptographic operations internally so the private key never leaves the hardware boundary.
D.The HSM replicates the private key to a secure enclave in the server CPU, where it is used for TLS handshakes.
AnswerC

An HSM generates and stores private keys in tamper-resistant hardware and performs signing or decryption operations internally. The web server sends data to the HSM and receives the result, but the private key itself is never exposed to the host memory or file system. Even if the web server process is compromised, the attacker cannot extract the key from the HSM.

Why this answer

A hardware security module protects private keys by generating and using them inside tamper-resistant hardware. The key never enters the host's memory or file system, so a compromised web server process cannot read it. Encrypting keys on disk, using a TPM, or replicating keys to a CPU enclave still exposes the key material to the host at some point, which fails the stated requirement.

Exam trap

The trap here is confusing encryption of a key at rest with isolation of the key from the host, since a compromised process can read a decrypted key from memory.

957
MCQhard

Refer to the exhibit. A firewall log shows repeated outbound connection attempts from an internal workstation (192.168.1.50) to an external IP (203.0.113.50) on TCP port 445. What is the most likely cause?

A.A worm or malware exploiting SMB
B.A misconfigured DNS client
C.A user browsing the web
D.A legitimate file share connection
AnswerA

Outbound TCP port 445 to an external host indicates SMB traffic leaving the network, which workstations should never generate. Worms such as WannaCry scan and propagate over SMB, so repeated connection attempts to port 445 strongly suggest malware exploiting the SMB service rather than legitimate file sharing.

Why this answer

Repeated outbound connection attempts to TCP port 445 (SMB) from an internal workstation to an external IP strongly indicate worm or malware activity — SMB is commonly exploited by worms like WannaCry, Conficker, and EternalBlue-based malware to propagate laterally and to external targets. Blocking outbound SMB at the firewall and isolating the host are immediate mitigations.

Exam trap

SSCP often tests port-to-protocol mapping and attack-pattern recognition — candidates who do not recognize TCP 445 as SMB may pick generic answers like misconfigured DNS or legitimate file sharing, missing the worm/malware signature of repeated external SMB attempts.

How to eliminate wrong answers

Option B is wrong because a misconfigured DNS client would generate DNS queries (UDP/TCP 53), not repeated TCP 445 connections to a specific external IP. Option C is wrong because web browsing uses TCP 80/443, not 445; SMB is not a web protocol. Option D is wrong because legitimate file share connections over SMB typically occur within the internal network to known file servers, not repeated attempts to an external IP — and the pattern of repeated attempts indicates malicious scanning/propagation, not normal file access.

958
MCQhard

A healthcare organization must comply with HIPAA and requires that access to electronic protected health information (ePHI) be logged and audited. They consider using an identity management system that supports single sign-on (SSO). What is the PRIMARY security concern with SSO in this environment?

A.Single credential compromise leads to broad access
B.Increased complexity of password policies
C.Lack of detailed audit logs for each application
D.User inconvenience due to multiple logins
AnswerA

SSO consolidates authentication into one credential, so its compromise grants the attacker the full breadth of federated ePHI access. That breadth conflicts with HIPAA's audit and least-privilege expectations, making credential compromise the primary concern rather than logging granularity.

Why this answer

In a healthcare environment subject to HIPAA, the primary security concern with SSO is that a single compromised credential (e.g., a password or smart card PIN) grants an attacker immediate access to all applications and ePHI systems that the user is authorized to use. This creates a single point of failure, dramatically increasing the blast radius of a credential theft incident. Unlike separate per-application credentials, SSO eliminates the need for repeated authentication, so an attacker who obtains the SSO token or password can move laterally across the entire application portfolio without additional authentication barriers.

Exam trap

ISC2 often tests the misconception that SSO inherently reduces audit capabilities, when in fact the primary risk is the amplified impact of a single credential compromise — candidates may incorrectly choose 'lack of detailed audit logs' because they assume SSO bypasses application-level logging, but proper SSO implementations log at the IdP and can integrate with SIEM systems.

How to eliminate wrong answers

Option B is wrong because SSO typically reduces the number of passwords a user must remember, which can simplify password policies rather than increase their complexity; the real concern is not policy complexity but the amplified risk from a single credential compromise. Option C is wrong because modern SSO systems (e.g., SAML 2.0, OAuth 2.0, OpenID Connect) can and do generate detailed audit logs at the identity provider (IdP) level, often including timestamp, user ID, application accessed, and session duration — the lack of logs is not an inherent SSO limitation. Option D is wrong because SSO is designed to eliminate multiple logins, providing user convenience; the question asks for the primary security concern, not a usability issue.

959
MCQeasy

A small business owner wants to implement access control for a shared folder on a Windows server. The owner wants to grant different permissions to individual employees based on their specific job duties, without creating groups. Which access control model is most appropriate?

A.Discretionary access control (DAC)
B.Attribute-based access control (ABAC)
C.Role-based access control (RBAC)
D.Mandatory access control (MAC)
AnswerA

DAC allows the owner of a resource to grant permissions to individual users at their discretion. This matches the owner's requirement to assign different permissions to employees based on job duties without using groups. DAC is the most appropriate model here.

Why this answer

Discretionary access control (DAC) is the model where the owner of a resource determines who can access it and with what permissions. In this scenario, the small business owner wants to grant individual permissions to employees based on their job duties without creating groups. DAC allows this flexibility.

RBAC would require roles, MAC uses labels, and ABAC uses attributes, all of which are more complex or not aligned with the owner's direct control.

Exam trap

The trap here is overcomplicating the solution by choosing a more complex model like ABAC or RBAC, when the simple requirement points to DAC.

960
MCQeasy

During a quantitative risk analysis, the asset value is $500,000, the exposure factor is 40%, and the annual rate of occurrence is 0.5. What is the annualized loss expectancy (ALE)?

A.$200,000
B.$500,000
C.$100,000
D.$250,000
AnswerC

ALE equals single loss expectancy multiplied by annualised rate of occurrence. SLE is $500,000 × 40% = $200,000; multiplying by 0.5 gives $100,000. This satisfies the stem's quantitative inputs directly, converting asset value, exposure factor and occurrence rate into an expected annual loss figure.

Why this answer

The annualized loss expectancy (ALE) is calculated as single loss expectancy (SLE) multiplied by the annual rate of occurrence (ARO). SLE is asset value ($500,000) times exposure factor (40%) = $200,000. ALE = $200,000 × 0.5 = $100,000.

This is the standard quantitative risk analysis formula per NIST SP 800-30.

Exam trap

ISC2 often tests the distinction between SLE and ALE, trapping candidates who compute the SLE ($200,000) and stop there, forgetting to multiply by the ARO (0.5) to get the annualized value.

How to eliminate wrong answers

Option A is wrong because $200,000 is the single loss expectancy (SLE), not the annualized loss expectancy (ALE); it fails to multiply by the annual rate of occurrence (0.5). Option B is wrong because $500,000 is the full asset value, ignoring both the exposure factor (40%) and the annual rate of occurrence (0.5). Option D is wrong because $250,000 would result from multiplying the asset value by the annual rate of occurrence (0.5) but ignoring the exposure factor (40%), or from incorrectly halving the SLE instead of multiplying by 0.5.

961
Multi-Selecthard

During a ransomware incident, the incident response team needs to recover encrypted servers. Which THREE steps are essential for successful recovery? (Select THREE)

Select 3 answers
A.Restore data from the most recent clean backup
B.Pay the ransom to obtain the decryption key
C.Patch the vulnerability that allowed the ransomware to enter
D.Delete all user accounts and recreate them
E.Scan restored systems to ensure eradication of malware
AnswersA, C, E

Ransomware encrypts data in place, so recovery depends on restoring from a backup taken before infection. Selecting the most recent clean copy minimises data loss while ensuring the restored files are free of the encryption payload, directly satisfying the recovery objective.

Why this answer

Option A is correct because restoring from the most recent clean backup is the primary and most reliable way to recover encrypted data without trusting the attacker or paying the ransom. Option C is correct because patching the vulnerability that allowed the ransomware to enter prevents immediate re-infection once systems are restored and brought back online. Option E is correct because scanning restored systems verifies that malware has been eradicated and that no residual persistence mechanisms or reinfection vectors remain before returning them to production.

Option B is not appropriate because paying the ransom does not guarantee a working decryption key, funds criminal activity, and may violate organizational or legal policy. Option D is not an essential recovery step because deleting and recreating all user accounts does not address the encrypted data or the malware itself and could cause unnecessary operational disruption.

Exam trap

The SSCP exam often tests the misconception that paying the ransom is a valid recovery step, but it emphasizes that payment should never be recommended due to lack of guarantee and ethical concerns.

962
MCQeasy

A network administrator is configuring a demilitarized zone (DMZ) to host a public web server. The server must be accessible from the internet but should be isolated from the internal network. Which of the following is the primary security benefit of placing the web server in a DMZ?

A.It provides encryption for all traffic to and from the web server.
B.It prevents all attacks against the web server by filtering malicious traffic.
C.It automatically patches the web server against vulnerabilities.
D.It limits the exposure of the internal network if the web server is compromised.
AnswerD

The primary security benefit of a DMZ is to isolate publicly accessible services from the internal network. If the web server is compromised, the attacker is contained within the DMZ and cannot directly access internal resources. Firewalls between the DMZ and internal network restrict traffic, adding a layer of defense. This segmentation limits the blast radius of a security breach.

Why this answer

The primary security benefit of a DMZ is to isolate public-facing services from the internal network. If the web server in the DMZ is compromised, the attacker cannot directly access internal systems because firewalls restrict traffic between the DMZ and the internal network. This segmentation limits the damage.

Other options describe encryption, prevention, or patching, which are not inherent to a DMZ.

Exam trap

The trap here is confusing the DMZ's isolation benefit with other security controls like encryption or patching, which are separate measures.

963
MCQmedium

A security team is collecting evidence from a compromised server. They need to create a forensic image. Which of the following is the CORRECT procedure to ensure data integrity?

A.Use a write blocker to create a bit-for-bit copy, then compute MD5 hash of the original and the copy to verify they match
B.Take a photo of the screen and document file timestamps manually
C.Create a compressed image file using software without a write blocker
D.Boot the system and run a backup utility to copy files to an external drive
AnswerA

A write blocker prevents any modification to the source drive during imaging, preserving evidential integrity. Hashing both the original and the bit-for-bit copy with MD5 confirms they are identical, satisfying the requirement to verify integrity.

Why this answer

Forensic imaging requires a write blocker to prevent any modification to the original evidence, and a bit-for-bit copy preserves all data, including slack space and deleted files. Computing an MD5 hash of both the original and the copy verifies integrity by ensuring the hashes match, confirming no data alteration occurred during acquisition.

Exam trap

The trap here is that candidates may think a simple backup or file copy is sufficient for forensic evidence, but the SSCP exam emphasizes that only a write-blocked bit-for-bit copy with hash verification ensures data integrity and admissibility.

How to eliminate wrong answers

Option B is wrong because taking a photo and manually documenting timestamps does not create a forensic image; it only captures superficial information and fails to preserve the full data for analysis. Option C is wrong because creating a compressed image without a write blocker risks altering the original drive's data due to write operations, compromising evidence integrity. Option D is wrong because booting the system and running a backup utility modifies the system state (e.g., writes to swap, logs, or file access times) and does not produce a bit-for-bit copy, violating forensic best practices.

964
MCQmedium

An application security team is reviewing code for vulnerabilities. They find that user input is directly concatenated into an SQL query without sanitization. This is an example of which OWASP Top 10 vulnerability?

A.Injection
B.Cross-Site Scripting (XSS)
C.Security Misconfiguration
D.Broken Access Control
AnswerA

Direct concatenation of unsanitised input into an SQL query is classic SQL injection, which falls under the OWASP Top 10 Injection category. The stem's defining constraint — untrusted input reaching an interpreter without sanitisation — is precisely the mechanism Injection describes, making it the accurate classification.

Why this answer

Concatenating unsanitized user input directly into an SQL query is the textbook definition of an Injection vulnerability (OWASP A03:2021). The untrusted input is interpreted as SQL code rather than data, allowing an attacker to alter query logic, bypass authentication, or exfiltrate the database. This is the classic SQL injection pattern.

Exam trap

The trap is confusing 'user input mishandled' with XSS — candidates must recognize that the interpreter here is the SQL database, not the browser, which makes it Injection.

How to eliminate wrong answers

Option B is wrong because XSS involves injecting client-side script into web pages rendered to other users, not manipulating database queries. Option C is wrong because Security Misconfiguration refers to insecure settings, defaults, or exposed services — not the handling of untrusted input in queries. Option D is wrong because Broken Access Control concerns users acting outside their intended permissions (e.g., IDOR, privilege escalation), not the injection of code into an interpreter.

965
MCQhard

A security analyst reviews the firewall log exhibit. Which type of activity is indicated?

A.Brute force attack against RDP service
B.Port scan of the internal network
C.Data exfiltration to an external server
D.Normal administrative remote access
AnswerA

Repeated failed RDP authentication attempts from a single source against multiple accounts, followed by a success, indicate credential guessing rather than scanning or exfiltration. The log's destination port 3389 and high failure volume satisfy the stem's brute force signature.

Why this answer

The firewall log shows repeated failed RDP (TCP/3389) connection attempts from a single external IP to a single internal IP within a short time window. This pattern of multiple authentication failures against the same service is characteristic of a brute force attack, where an attacker systematically tries common passwords to gain unauthorized access to the RDP service.

Exam trap

ISC2 often tests the distinction between a brute force attack (repeated attempts to the same service) and a port scan (attempts to multiple services), so candidates mistakenly choose 'port scan' when they see many entries, even though all entries target the same port.

How to eliminate wrong answers

Option B is wrong because a port scan would show connection attempts to multiple different ports (e.g., 22, 80, 443, 3389) across one or more target IPs, not repeated attempts to a single port (3389) on a single IP. Option C is wrong because data exfiltration typically involves outbound data transfers to an external server, often using protocols like HTTP/S, FTP, or DNS tunneling, not repeated failed inbound authentication attempts. Option D is wrong because normal administrative remote access would show successful RDP logins (e.g., TCP SYN-ACK followed by session establishment), not a high volume of failed authentication events.

966
MCQmedium

A company is deploying virtual machines (VMs) in a private cloud environment. To prevent VM escape attacks, which of the following is the most critical security control?

A.Using a separate management network for the hypervisor
B.Regularly patching the hypervisor software
C.Disabling unnecessary VM guest tools
D.Implementing a host-based firewall on each VM
AnswerB

VM escape exploits hypervisor or virtualisation-layer flaws to break isolation between guests and the host. Patching the hypervisor removes those known vulnerabilities, which is the control that directly prevents escape; guest patching and network controls do not address the shared layer.

Why this answer

Regularly patching the hypervisor software is the most critical control to prevent VM escape attacks because these attacks typically exploit vulnerabilities in the hypervisor itself. Keeping the hypervisor up to date ensures that known security flaws are remediated, reducing the attack surface. While other controls add defense in depth, patching directly addresses the root cause of most escape vulnerabilities.

Exam trap

The trap is selecting a control that provides isolation (like separate management network) or reduces attack surface (disabling tools) as the most critical, when the question asks for preventing VM escape, which is primarily achieved by patching the hypervisor.

How to eliminate wrong answers

Option A is wrong because a separate management network improves security by isolating management traffic, but it does not prevent VM escape if the hypervisor has an unpatched vulnerability. Option B is correct. Option C is wrong because disabling unnecessary VM guest tools reduces the attack surface within the guest, but VM escape exploits the hypervisor from the guest, so it is not the most critical control.

Option D is wrong because a host-based firewall on each VM controls network traffic to and from the VM, but it does not prevent a VM from exploiting a hypervisor vulnerability to escape.

967
MCQmedium

A security analyst is reviewing an OWASP Top 10 vulnerability report. Which vulnerability involves an attacker accessing unauthorized data by modifying URLs or API parameters?

A.Insecure Direct Object References (IDOR)
B.Cross-Site Scripting (XSS)
C.Injection
D.Security Misconfiguration
AnswerA

IDOR occurs when an application exposes a direct reference to an internal object, such as a record ID in a URL or API parameter, and fails to verify that the requester owns it. Manipulating that value returns another user's data.

Why this answer

Insecure Direct Object References (IDOR) occur when an application exposes internal object references without proper authorization checks, allowing attackers to manipulate parameters to access other objects.

968
MCQeasy

A payroll administrator at a healthcare company resigns. On her last day, the security team must ensure she can no longer access the HR payroll application, but her mailbox must remain active for 30 days so her manager can review pending correspondence. Which access management action BEST meets these requirements?

A.Change the user's password and share the new credential with her manager.
B.Delete the user account immediately after her last shift.
C.Terminate the payroll application entitlement while retaining the account for mailbox access during the review period.
D.Disable the user account and leave it disabled indefinitely.
AnswerC

Removing the payroll entitlement eliminates the risk that matters most, while the account and mailbox stay available for the 30-day review. This follows least privilege by revoking only the access no longer needed. A defined end date should be recorded so the account is disabled or deleted once the review completes.

Why this answer

Deprovisioning should remove the entitlements tied to the former role while preserving what the business still needs. Revoking the payroll application access addresses the security risk, and keeping the account for a bounded mailbox review satisfies the operational requirement. Documenting the end date prevents the account from lingering past its purpose.

Exam trap

The trap here is treating account termination as all-or-nothing, when entitlements can be revoked selectively while the account remains active for a defined purpose.

969
MCQmedium

A company is concerned about VM sprawl in its data center. Which of the following is the most effective mitigation strategy?

A.Enable host-based firewalls on each VM
B.Implement a CMDB with lifecycle management policies
C.Apply patches to the hypervisor regularly
D.Use a centralized snapshot management system
AnswerB

A CMDB records every VM, owner and lifecycle state, and lifecycle policies enforce decommissioning of unused instances. This directly addresses sprawl by giving visibility and control over VM provisioning and retirement, satisfying the stem's mitigation requirement more effectively than periodic manual audits.

Why this answer

VM sprawl refers to unmanaged VMs accumulating. A Configuration Management Database (CMDB) with lifecycle management tracks VMs from creation to decommission. Hypervisor patching prevents escapes.

Snapshots are for recovery. Host-based firewalls protect individual VMs but do not manage sprawl.

970
Multi-Selecthard

A security engineer is hardening a Windows server that hosts a critical database. The server currently has many unnecessary services running. Which TWO of the following actions are most effective in reducing the attack surface of this server? (Choose two.)

Select 2 answers
A.Implement full disk encryption on the server's drives.
B.Apply the principle of least privilege to user accounts.
C.Install the latest antivirus software and keep it updated.
D.Enable a host-based firewall and close unused ports.
E.Disable unused Windows services and features.
AnswersD, E

Closing unused ports and enabling a host-based firewall restricts network access to only necessary services, directly reducing the attack surface. This prevents attackers from reaching potentially vulnerable services. It is a key hardening measure for servers.

Why this answer

Reducing attack surface involves eliminating unnecessary functionality and restricting access. Disabling unused services and features removes potential vulnerabilities, while closing unused ports and enabling a host-based firewall limits network exposure. Together, these actions significantly shrink the opportunities for an attacker to exploit the server.

Exam trap

The trap here is confusing general security best practices like antivirus or least privilege with specific attack surface reduction techniques.

971
MCQeasy

A security analyst is recommending a symmetric encryption algorithm for a new application that requires both confidentiality and authentication. Which algorithm and mode combination should they select?

A.3DES-CBC
B.AES-ECB
C.RC4
D.AES-GCM
AnswerD

AES-GCM is a block cipher in Galois/Counter Mode, providing authenticated encryption: confidentiality plus an authentication tag verifying integrity and origin. This satisfies the stem's dual requirement for confidentiality and authentication in one symmetric primitive, unlike CBC or CTR, which lack built-in authentication.

Why this answer

AES-GCM (Galois/Counter Mode) is a symmetric encryption algorithm that provides both confidentiality and authentication in a single, efficient operation. It combines AES encryption in counter mode with a Galois field-based message authentication code (GMAC), making it ideal for applications requiring both security properties.

Exam trap

The trap here is that candidates often confuse CBC mode with providing authentication (since it uses an IV), but CBC only offers confidentiality; GCM is the correct choice for combined confidentiality and authentication in symmetric encryption.

How to eliminate wrong answers

Option A is wrong because 3DES-CBC provides only confidentiality, not authentication; CBC mode requires a separate MAC (e.g., HMAC) to ensure integrity and authenticity, and 3DES is deprecated due to its 64-bit block size and slow performance. Option B is wrong because AES-ECB is deterministic and does not provide authentication; it encrypts identical plaintext blocks into identical ciphertext blocks, leaking patterns and lacking any integrity check. Option C is wrong because RC4 is a stream cipher that provides only confidentiality, not authentication, and is considered broken due to biases in its output (e.g., RC4 biases in TLS), making it unsuitable for secure applications.

Page 12

Page 13 of 13