Courseiva

Systems Security Certified Practitioner SSCP (SSCP) — Questions 76–150

971 questions total · 13pages · All types, answers revealed

Page 1

Page 2 of 13

Page 3
76
Multi-Selectmedium

An organization is implementing multi-factor authentication (MFA). Which TWO of the following are examples of something you have?

Select 2 answers
A.Smart card
B.PIN
C.Retina scan
D.Hardware token (e.g., YubiKey)
E.Fingerprint
AnswersA, D

A smart card is a physical artefact issued to and held by the user, making it a possession factor. The embedded chip stores credentials or keys that the reader validates, so authentication depends on having the card rather than remembering a secret or presenting a biometric.

Why this answer

Something you have includes physical tokens like smart cards and hardware tokens. Biometrics are something you are, and passwords are something you know.

77
MCQeasy

An organization requires that all laptops used by employees be encrypted. Which type of encryption should be used to protect the entire hard drive?

A.File-level encryption
B.Full disk encryption (FDE)
C.Transport encryption (TLS)
D.Application-level encryption
E.Folder-level encryption
AnswerB

Full disk encryption operates below the file system, encrypting every sector of the drive including the OS, swap and temporary files. This satisfies the requirement that the entire hard drive be protected, since data at rest remains unreadable if the laptop is lost or stolen.

Why this answer

Full disk encryption (FDE) encrypts the entire hard drive, including the operating system and all files, providing the strongest protection for data at rest on lost or stolen laptops. File-level encryption only encrypts individual files, leaving metadata and other files exposed. Folder-level encryption is similar but at the folder level.

Transport encryption (TLS) protects data in transit, not at rest. Application-level encryption encrypts data within a specific application, not the entire drive. Therefore, full disk encryption (Option B) is the correct choice for protecting the entire hard drive.

78
Multi-Selecthard

During an access control audit, you find that a user has been assigned to two mutually exclusive roles. Which TWO principles are most likely violated?

Select 2 answers
A.Role hierarchy
B.Least privilege
C.Separation of duties
D.Mandatory access control
E.Accountability
AnswersB, C

Holding two mutually exclusive roles grants access beyond what either role alone requires for the user's duties. Least privilege is violated because the accumulated permissions exceed the minimum necessary to perform the assigned job function.

Why this answer

Option B (Least privilege) is correct because assigning a user to two mutually exclusive roles grants them more permissions than their job function requires, violating the principle that users should receive only the minimum access necessary to perform their duties. Option C (Separation of duties) is correct because mutually exclusive roles are specifically designed to prevent one person from holding conflicting responsibilities (e.g., initiating and approving a transaction), and assigning both to a single user directly defeats that control. Option A (Role hierarchy) is not necessarily violated, since a hierarchy merely organizes roles by inheritance and does not inherently prohibit holding two roles.

Option D (Mandatory access control) is unrelated, as MAC relies on system-enforced labels and clearances rather than conflicting role assignments. Option E (Accountability) concerns traceability of actions to an individual, which is not directly breached by holding two mutually exclusive roles.

Exam trap

SSCP often tests the overlap between least privilege and separation of duties — candidates pick only one, but the question asks for TWO principles, and both are directly violated by mutually exclusive role assignment.

79
MCQhard

An organization detects that an attacker is performing a MAC flooding attack on a switch. What is the primary goal of this attack?

A.To change the MAC address of the switch
B.To cause a denial of service on the network
C.To force the switch to act like a hub and allow packet sniffing
D.To bypass 802.1X authentication
AnswerC

Filling the CAM table causes the switch to flood frames out all ports.

Why this answer

MAC flooding attacks exploit the limited size of a switch's Content Addressable Memory (CAM) table. By sending thousands of fake source MAC addresses, the attacker fills the CAM table, causing the switch to fail open and flood all incoming frames out all ports, effectively behaving like a hub. This allows the attacker to sniff traffic that would normally be isolated to specific switch ports.

Exam trap

The trap here is that candidates often confuse the primary goal of MAC flooding (sniffing traffic) with a denial of service, but Cisco tests that the attacker's intent is to bypass port-level isolation to eavesdrop, not simply to crash the switch.

How to eliminate wrong answers

Option A is wrong because MAC flooding does not change the MAC address of the switch itself; it floods the switch's CAM table with fake MAC addresses, not the switch's own burned-in MAC address. Option B is wrong because while a MAC flooding attack can cause network degradation, its primary goal is not denial of service but rather to enable packet sniffing by forcing the switch into hub-like behavior; a true DoS attack would aim to disrupt all traffic, whereas MAC flooding aims to capture it. Option D is wrong because MAC flooding targets Layer 2 switching behavior and does not directly interact with 802.1X authentication, which operates at the port level using EAPoL (Extensible Authentication Protocol over LAN) to control access.

80
MCQhard

You are the security analyst for a mid-sized e-commerce company that processes credit card payments. The company uses a legacy payment application on a Windows Server 2012 R2 system, which is scheduled for decommission in six months. The server is isolated in a separate VLAN with strict firewall rules allowing only outbound HTTPS to the payment processor and inbound management from a jump box on a different subnet. During a routine vulnerability scan, you discover that the server is missing over 50 critical patches, including one for a remote code execution vulnerability (CVE-2023-XXXX) that is being actively exploited in the wild. The server cannot be patched because the vendor stopped support and patches are not available. The company's risk appetite is low due to PCI DSS requirements. You need to recommend a course of action that balances risk reduction with business continuity. What should you do?

A.Implement additional compensating controls such as an application-layer firewall, disable all unnecessary services, restrict outbound traffic to only the payment processor IP, enable detailed logging, and accelerate the migration
B.Immediately decommission the server and migrate to the new payment system, accepting a temporary outage
C.Apply the vendor's hotfix from an unofficial source to patch the vulnerability
D.Accept the risk and purchase additional cyber insurance to cover potential losses
AnswerA

Compensating controls reduce risk while allowing continued operation until decommission.

Why this answer

It implements compensating controls to reduce the risk of the unpatched remote code execution vulnerability while maintaining business continuity. By deploying an application-layer firewall (e.g., a WAF or host-based IPS), disabling unnecessary services, restricting outbound traffic to only the payment processor's IP via strict egress ACLs, enabling detailed logging for monitoring, and accelerating the migration to a supported system, you align with PCI DSS Requirement 6.2 (timely patching) and Requirement 11.5 (change detection) without causing an outage. This layered defense mitigates the active exploit risk until the legacy server can be decommissioned in six months.

Exam trap

The trap here is that candidates may choose Option B (immediate decommission) thinking it eliminates risk, but they overlook the business continuity requirement and the fact that PCI DSS allows compensating controls for legacy systems with a documented migration plan.

How to eliminate wrong answers

Option B is wrong because immediately decommissioning the server would cause a business outage, which is unacceptable for a mid-sized e-commerce company processing credit card payments; PCI DSS requires maintaining business continuity, and a temporary outage could lead to revenue loss and compliance issues. Option C is wrong because applying a vendor hotfix from an unofficial source introduces significant risk of malware, system instability, or violation of PCI DSS Requirement 6.1 (use only vendor-supplied patches), and it could void any remaining support or insurance. Option D is wrong because accepting the risk and purchasing cyber insurance does not address the active exploitation of CVE-2023-XXXX; PCI DSS requires compensating controls or patching, and insurance only covers financial loss after a breach, not the immediate security risk to cardholder data.

81
MCQhard

A company has a backup policy that performs a full backup every Sunday and incremental backups on other days. On Wednesday, a server fails. How many backup sets are needed to restore the server to its state on Tuesday night?

A.One
B.Two
C.Four
D.Three
AnswerD

Restoring Wednesday's failure to Tuesday night requires the Sunday full backup plus Monday's and Tuesday's incrementals — three sets. Incrementals capture only changes since the previous backup, so each intervening day must be applied sequentially; the full alone is insufficient and Tuesday's incremental cannot reconstruct Monday's changes.

Why this answer

To restore the server to its state on Tuesday night, you need the full backup from Sunday and the incremental backups from Monday and Tuesday. Incremental backups only capture changes since the last backup (full or incremental), so you must restore them in sequence: full backup first, then Monday's incremental, then Tuesday's incremental. This requires three backup sets total, making option D correct.

Exam trap

The trap here is confusing incremental backups with differential backups; candidates often think two sets are enough (full + latest incremental) or mistakenly count the days incorrectly, leading them to choose option B or C instead of recognizing the sequential dependency of incremental chains.

How to eliminate wrong answers

Option A is wrong because a single backup set cannot restore the state after multiple days of changes; only the full backup alone would restore Sunday's state, not Tuesday's. Option B is wrong because two backup sets would only cover the full backup and one incremental, missing the changes from the other day (e.g., full + Monday would miss Tuesday's changes). Option C is wrong because four backup sets would be needed only if the policy used differential backups (which accumulate all changes since the last full backup) or if there were additional days; with incremental backups, the number of sets equals the number of days since the last full backup plus one (the full), which is three for Tuesday.

82
MCQmedium

A security administrator is reviewing the organization's awareness program after a recent phishing campaign. Several employees clicked the link, and one entered credentials on the fake page. The administrator wants to reduce the likelihood of credential theft in future campaigns. Which control should the administrator implement to best address this risk?

A.Increase the frequency of phishing simulation campaigns to once per month.
B.Implement a policy that prohibits employees from clicking links in external email messages.
C.Deploy a secure email gateway that quarantines messages containing known malicious URLs.
D.Require multi-factor authentication for all user accounts and privileged access.
AnswerD

Multi-factor authentication requires a second factor beyond the password, so stolen credentials alone are insufficient for an attacker to authenticate. If the employee had entered credentials on the fake page, MFA would have blocked the account takeover unless the attacker also compromised the second factor. This directly reduces the impact of successful phishing and is the most effective control for credential theft in this scenario.

Why this answer

Multi-factor authentication is the strongest control against credential theft because it requires a second factor that a phishing page cannot capture with the password alone. Email filtering, awareness simulations, and link-clicking policies are valuable layers, but none of them prevents an attacker from using stolen credentials to authenticate. MFA directly interrupts the attack path after credentials are compromised.

Exam trap

The trap here is choosing user awareness or email filtering as the primary fix for credential theft, when the technical control that defeats stolen passwords is multi-factor authentication.

83
MCQmedium

After a ransomware incident, an organization decides to restore data from backups. The RPO (Recovery Point Objective) is 4 hours. What does this RPO indicate?

A.Backups must be taken at least every 4 hours to ensure data loss does not exceed 4 hours
B.The organization can tolerate 4 hours of downtime
C.The system must be restored within 4 hours of the incident
D.The recovery process will take a maximum of 4 hours
AnswerA

RPO defines the maximum tolerable data loss measured in time, so a four-hour RPO means backups must run at least every four hours; otherwise a failure could destroy more than four hours of transactions, breaching the objective.

Why this answer

The Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time. An RPO of 4 hours means the organization can tolerate losing up to 4 hours of data, so backups must be taken at least every 4 hours to ensure that in the worst case, no more than 4 hours of data is lost. This directly dictates the backup frequency, not the recovery time or downtime.

Exam trap

The trap here is confusing RPO (data loss tolerance) with RTO (downtime tolerance), leading candidates to select options that describe recovery time or downtime instead of backup frequency.

How to eliminate wrong answers

Option B is wrong because it describes the Recovery Time Objective (RTO), which is the maximum acceptable downtime, not the RPO. Option C is wrong because it also describes the RTO (time to restore service), not the RPO which is about data loss tolerance. Option D is wrong because it describes the actual recovery time, which is a metric of the restoration process, not the RPO's definition of acceptable data loss.

84
MCQmedium

A security administrator is configuring a VPN gateway that must support perfect forward secrecy for IPsec connections. Which key establishment method should be enabled to ensure that compromise of a long-term key does not expose previously established session keys?

A.RSA key transport with the gateway's static RSA key pair
B.Pre-shared key authentication with a static PSK
C.HMAC-SHA-256 for integrity protection of IKE messages
D.Internet Key Exchange with ephemeral Diffie-Hellman (DHE)
AnswerD

Ephemeral Diffie-Hellman generates a fresh key pair for each session and discards it afterward, so compromise of the long-term authentication key does not reveal past session keys. This property is exactly what perfect forward secrecy requires. Enabling DHE in IKE allows the VPN gateway to derive unique session keys per connection, protecting previously recorded traffic.

Why this answer

Perfect forward secrecy requires that session keys cannot be recovered from a long-term secret. Ephemeral Diffie-Hellman achieves this by generating temporary key pairs for each session and deleting them after use. Static PSK and static RSA key transport reuse long-term secrets, so compromise of those secrets can expose past sessions.

HMAC provides integrity, not key establishment, and is therefore not the correct control.

Exam trap

The trap here is assuming that any strong authentication method, such as a PSK or RSA key transport, automatically provides perfect forward secrecy.

85
MCQmedium

A security analyst notices repeated failed login attempts from a single IP address targeting a domain controller. The SIEM alerts after 10 failed attempts within 5 minutes. Which detection type is most likely used?

A.Anomaly-based detection
B.Signature-based detection
C.Rule-based detection
D.Behavior-based detection
AnswerC

A fixed threshold — ten failed attempts within five minutes from one source — is a deterministic signature. Rule-based detection matches events against predefined conditions, unlike anomaly or behavioural baselining, which flags deviations from learned norms.

Why this answer

The alert is triggered by a static threshold (10 failed attempts in 5 minutes) with no baseline learning. This is characteristic of rule-based detection, which uses predefined conditions (e.g., 'if count > 10 then alert'). Anomaly-based detection would require establishing a baseline of normal behavior and detecting deviations from that baseline.

Therefore, rule-based detection is the most likely type used.

Exam trap

Candidates may assume any threshold-based alert is anomaly-based, but a fixed, static threshold is a hallmark of rule-based detection. Anomaly-based detection derives thresholds from historical baselines.

How to eliminate wrong answers

Option A is wrong because anomaly-based detection relies on statistical baselines and deviations from normal behavior, not a fixed threshold like 10 attempts in 5 minutes. Option B is wrong because signature-based detection matches known attack patterns (e.g., specific payloads or exploit signatures), not volumetric thresholds. Option D is wrong because behavior-based detection analyzes patterns of user or entity behavior over time (e.g., UEBA), not a simple count of failed logins from a single IP.

86
MCQhard

After a security incident, the incident response team needs to analyze logs from multiple sources to reconstruct the timeline. The SIEM retains logs for 90 days, but the incident occurred 120 days ago. Which action should the organization have taken to ensure log availability?

A.Use a different SIEM vendor
B.Increase log verbosity
C.Implement real-time alerting
D.Extend log retention period to at least 1 year
AnswerD

The SIEM's 90-day retention expired before the 120-day-old incident could be investigated, so logs were gone. Extending retention to at least one year ensures evidence remains available beyond the investigation window, directly addressing the stem's availability constraint.

Why this answer

The organization's log retention policy was insufficient to cover the incident timeline. The SIEM retained logs for only 90 days, but the incident occurred 120 days ago, meaning the logs were overwritten or purged before the incident was discovered. Extending the retention period to at least one year ensures logs are available for post-incident forensic analysis, aligning with industry best practices (e.g., NIST SP 800-61) and regulatory requirements that often mandate 6–12 months of log retention.

Exam trap

The trap here is that candidates confuse log verbosity (option B) with log retention, thinking that capturing more data inherently preserves it longer, when in fact retention is a separate storage policy parameter.

How to eliminate wrong answers

Option A is wrong because switching SIEM vendors does not change the underlying retention policy; the new vendor would still need to be configured to retain logs for an adequate duration. Option B is wrong because increasing log verbosity (e.g., logging more events or details) does not extend the retention window; it actually consumes more storage and could shorten retention if capacity is fixed. Option C is wrong because real-time alerting helps detect incidents sooner but does not preserve historical logs beyond the configured retention period; logs older than 90 days would still be unavailable for timeline reconstruction.

87
MCQeasy

An organization experiences a ransomware attack that encrypts critical data. The incident response team isolates affected systems. What is the NEXT step?

A.Reimage systems
B.Notify law enforcement
C.Identify the root cause
D.Restore from backup
AnswerC

Identifying the root cause follows containment, satisfying the need to determine the initial infection vector before recovery. Analysis of logs and forensic artefacts reveals how the ransomware entered, preventing re-infection during restoration. This aligns with the SSCP incident response sequence: containment precedes eradication, which requires understanding the underlying cause.

Why this answer

After isolating affected systems to contain the ransomware, the next step is to identify the root cause (e.g., how the ransomware entered, which vulnerability was exploited, or which user account was compromised). This aligns with the NIST SP 800-61 incident response lifecycle, where identification and analysis precede eradication and recovery. Without determining the root cause, reimaging or restoring from backup risks reinfection or missing a persistent backdoor.

Exam trap

The trap here is that candidates often jump to 'Restore from backup' (Option D) as the immediate next step, but the SSCP exam emphasizes that containment and root cause analysis must precede recovery to prevent reinfection and ensure the backup is clean.

How to eliminate wrong answers

Option A is wrong because reimaging systems before identifying the root cause may destroy forensic evidence and fail to address the initial infection vector, potentially allowing the attack to recur. Option B is wrong because notifying law enforcement is a legal or compliance step that typically occurs after containment and root cause analysis, and it is not a technical incident response step. Option D is wrong because restoring from backup before understanding the root cause could restore encrypted or compromised data, and the backup itself might be infected or the same vulnerability could be exploited again.

88
MCQmedium

A network architect is designing a demilitarized zone (DMZ) for a company that hosts a public web server and an internal database. The architect must ensure that if the web server is compromised, the attacker cannot directly access the internal database. Which DMZ design principle should be applied?

A.Implement a single firewall with three interfaces: internet, DMZ, and internal network, with rules allowing any traffic between DMZ and internal.
B.Allow all traffic from the DMZ to the internal network to ensure the web server can retrieve data from the database.
C.Use a screened subnet with two firewalls: an external firewall between the internet and DMZ, and an internal firewall between DMZ and internal network.
D.Place the database in the same DMZ as the web server to simplify firewall rules.
AnswerC

A screened subnet with dual firewalls creates two distinct security boundaries. The external firewall controls internet-to-DMZ traffic, while the internal firewall restricts DMZ-to-internal traffic. Even if the web server is compromised, the attacker must bypass the internal firewall to reach the database. This layered defense enforces segmentation and is a best practice for DMZ design.

Why this answer

Using a screened subnet with two firewalls provides defense in depth: the external firewall protects the DMZ from the internet, and the internal firewall protects the internal network from the DMZ. If the web server is compromised, the attacker still faces the internal firewall, which should only allow specific traffic to the database. Placing the database in the DMZ or allowing unrestricted DMZ-to-internal traffic would eliminate this protection.

Exam trap

The trap here is thinking that a single firewall with multiple interfaces is inherently insecure, but the real issue is the rule set; however, the dual-firewall design provides a clearer separation of duties and is a stronger recommendation.

89
MCQmedium

Which of the following protocols is used to securely transfer files over SSH and is considered a replacement for FTP?

A.IPsec
B.HTTPS
C.SFTP
D.SMTPS
AnswerC

SFTP tunnels file transfers through SSH on port 22, encrypting both commands and data in a single connection. This satisfies the stem's requirement for a secure FTP replacement, unlike FTPS, which wraps standard FTP in TLS across separate control and data channels. SFTP's SSH foundation delivers the confidentiality and integrity the scenario demands.

Why this answer

SFTP (SSH File Transfer Protocol) is the protocol that runs over SSH to securely transfer files and is widely regarded as the secure replacement for FTP. It encrypts both commands and data within a single SSH connection, typically on port 22. HTTPS, IPsec, and SMTPS serve different purposes and are not FTP replacements over SSH.

Exam trap

SSCP often tests the confusion between SFTP, FTPS, and SCP — candidates see 'secure FTP' and pick FTPS or SCP, missing that the question specifies 'over SSH' and 'replacement for FTP,' which is SFTP.

How to eliminate wrong answers

Option A is wrong because IPsec is a network-layer suite for securing IP packets (VPNs), not a file transfer protocol. Option B is wrong because HTTPS secures web traffic over TLS, not a file transfer replacement for FTP over SSH. Option D is wrong because SMTPS is SMTP over TLS for sending email, not file transfer.

90
MCQhard

An organization is calculating the Annualized Loss Expectancy (ALE) for a server. The Asset Value (AV) is $50,000, the Exposure Factor (EF) is 40%, and the Annualized Rate of Occurrence (ARO) is 0.5. What is the Single Loss Expectancy (SLE) and ALE?

A.SLE = $20,000, ALE = $10,000
B.SLE = $50,000, ALE = $25,000
C.SLE = $10,000, ALE = $5,000
D.SLE = $20,000, ALE = $40,000
AnswerA

SLE equals AV multiplied by EF: $50,000 × 0.40 = $20,000. ALE equals SLE multiplied by ARO: $20,000 × 0.5 = $10,000. These figures satisfy the stem's quantitative risk calculation, correctly applying the standard formulas to the given asset value, exposure factor and annualised rate of occurrence.

Why this answer

The Single Loss Expectancy (SLE) is calculated as Asset Value (AV) × Exposure Factor (EF) = $50,000 × 0.40 = $20,000. The Annualized Loss Expectancy (ALE) is then SLE × Annualized Rate of Occurrence (ARO) = $20,000 × 0.5 = $10,000. This matches option A exactly.

Exam trap

The trap here is that candidates may forget to apply the EF to the AV when calculating SLE, or they may invert the ARO (e.g., using 2 instead of 0.5) when computing ALE.

How to eliminate wrong answers

Option B is wrong because it incorrectly uses the full AV as the SLE ($50,000) instead of applying the EF, and then multiplies by ARO to get $25,000, which is not the correct ALE. Option C is wrong because it mistakenly halves the AV to get SLE = $10,000 (perhaps confusing EF with ARO) and then multiplies by ARO to get ALE = $5,000, misapplying both formulas. Option D is wrong because it correctly calculates SLE = $20,000 but then multiplies by the reciprocal of ARO (2) instead of ARO (0.5), yielding ALE = $40,000 instead of $10,000.

91
MCQhard

You are the security administrator for a mid-sized financial company that processes credit card transactions. The company has a mix of on-premises servers and cloud-based services. Recently, the company experienced a data breach where an attacker exfiltrated customer data from a database server. The investigation reveals that the attacker used compromised credentials of a database administrator (DBA) account. The DBA account had been used by multiple administrators without proper auditing. The company wants to implement a solution to prevent such incidents in the future. The solution must: 1) ensure that each administrator has a unique account for database access, 2) require approval for privileged actions, 3) provide a full audit trail of all privileged activities, and 4) be cost-effective. Which of the following is the best course of action?

A.Enforce the use of a shared DBA account with a complex password that is changed monthly.
B.Implement a privileged access management (PAM) solution that provides just-in-time access and session recording.
C.Require multi-factor authentication for all database access without any additional controls.
D.Install a database activity monitoring (DAM) solution that logs all SQL queries.
AnswerB

PAM enforces unique per-administrator credentials, brokers privileged actions through approval workflows, and records sessions for a complete audit trail. Just-in-time access limits standing privileges, addressing the shared DBA account that enabled the breach, while remaining cost-effective for a mid-sized firm.

Why this answer

A privileged access management (PAM) solution provides just-in-time access, approval workflows for privileged actions, and session recording for a full audit trail, directly addressing all four requirements. It ensures each administrator has a unique account by vaulting credentials and allowing check-out, and it is cost-effective compared to building custom controls. MFA alone does not provide approval or session recording, and DAM only logs queries without controlling access.

Exam trap

SSCP often tests the misconception that MFA or DAM alone can solve privileged access issues, when in fact a comprehensive PAM solution is needed to meet all requirements.

How to eliminate wrong answers

Option A is wrong because a shared DBA account with a complex password does not provide unique accounts, approval for privileged actions, or a full audit trail; it perpetuates the shared account problem. Option C is wrong because requiring MFA for all database access without additional controls does not ensure unique accounts (if shared accounts are still used), nor does it provide approval workflows or session recording. Option D is wrong because a DAM solution logs SQL queries but does not enforce unique accounts, approval for privileged actions, or provide session recording; it is only a monitoring tool.

92
MCQhard

An organization using PaaS (Platform as a Service) for application hosting wants to ensure the application code is secure. Which of the following is the customer's responsibility under the shared responsibility model?

A.Physical security of the data center
B.Patching the web server runtime
C.Patching the underlying operating system
D.Securing the application code from SQL injection
AnswerD

In PaaS, the provider secures the runtime, OS and infrastructure, but the customer retains ownership of the deployed application. Input validation and parameterised queries to prevent SQL injection sit squarely with the customer, satisfying the stem's requirement to secure application code.

Why this answer

Under the shared responsibility model for PaaS, the cloud provider manages the physical infrastructure, the operating system, and the runtime environment, while the customer is responsible for the security of the application code and data they deploy. Securing application code against SQL injection is therefore the customer's responsibility because it involves how the application is written and how it handles input.

Exam trap

SSCP often tests the shared responsibility model by presenting platform-layer tasks (OS patching, runtime patching) as if they were customer duties; the trap is forgetting that in PaaS the provider owns everything below the application, so only application code and data remain with the customer.

How to eliminate wrong answers

Option A is wrong because physical security of the data center is always the cloud provider's responsibility in any cloud service model (IaaS, PaaS, SaaS). Option B is wrong because patching the web server runtime is part of the platform layer managed by the PaaS provider, not the customer. Option C is wrong because patching the underlying operating system is also handled by the PaaS provider, unlike in IaaS where the customer patches the guest OS.

93
MCQhard

Which of the following best describes the function of SYN cookies in mitigating SYN flood attacks?

A.They block all incoming SYN packets from suspicious sources.
B.They encode connection state in the SYN-ACK sequence number, allowing the server to avoid storing state until the ACK is received.
C.They increase the backlog queue size to accommodate more half-open connections.
D.They require clients to solve a computational puzzle before completing the handshake.
AnswerB

SYN cookies encode connection state within the SYN-ACK sequence number, so the server holds no state until the client's ACK returns. This removes the half-open connection table exhaustion that defines a SYN flood, satisfying the stem's mitigation requirement.

Why this answer

SYN cookies encode the connection state (such as sequence numbers and timestamps) into the initial sequence number of the SYN-ACK. This allows the server to avoid allocating resources until the final ACK is received, mitigating SYN flood attacks that exhaust the backlog queue.

Exam trap

The trap is confusing SYN cookies with other DoS mitigation techniques like rate limiting or CAPTCHAs, leading candidates to pick options that involve blocking or puzzles.

How to eliminate wrong answers

Option A is wrong because SYN cookies do not block SYN packets; they allow the handshake to proceed without storing state. Option C is wrong because increasing the backlog queue only delays the exhaustion and does not address the root cause. Option D is wrong because computational puzzles are used in proof-of-work systems, not SYN cookies.

94
MCQeasy

Which backup type copies all data that has changed since the last full backup, regardless of subsequent backups?

A.Incremental backup
B.Snapshot backup
C.Differential backup
D.Full backup
AnswerC

A differential backup captures every block changed since the last full backup, so successive differentials each grow larger until the next full backup resets the baseline. This matches the stem's requirement of copying changes since the last full backup regardless of subsequent backups.

Why this answer

A differential backup copies all data that has changed since the last full backup, regardless of any intermediate backups. This means each differential backup grows in size as it accumulates all changes made since the last full backup, making it distinct from incremental backups which only capture changes since the last backup of any type.

Exam trap

ISC2 often tests the distinction that differential backups grow over time because they accumulate all changes since the last full backup, while incremental backups are smaller but require a chain of backups for restoration.

How to eliminate wrong answers

Option A is wrong because an incremental backup copies only data that has changed since the last backup (whether full or incremental), not since the last full backup. Option B is wrong because a snapshot backup captures the state of a system at a point in time using copy-on-write technology, not by tracking changes since a full backup. Option D is wrong because a full backup copies all selected data regardless of change status, not just data that has changed since a previous backup.

95
MCQhard

An organization is migrating a legacy application to a PaaS cloud environment. According to the shared responsibility model, which security control is the organization still responsible for?

A.Configuring the network firewall at the cloud perimeter
B.Securing the application code against SQL injection
C.Patching the underlying operating system
D.Managing the hypervisor and virtualization layer
AnswerB

In PaaS, the provider secures the platform, runtime and OS, but the customer retains responsibility for their application code. Input validation and parameterised queries preventing SQL injection remain the organisation's duty, satisfying the shared responsibility boundary for application-layer controls.

Why this answer

In the shared responsibility model for PaaS, the cloud provider manages the underlying infrastructure (network, OS, hypervisor, runtime), while the customer is responsible for the security of their application code and data. Securing application code against SQL injection is therefore the customer's responsibility. The other options are provider-managed in PaaS.

Exam trap

The trap is overestimating provider responsibility in PaaS — candidates assume the provider handles everything below the application, but the customer still owns application code security, IAM, and data protection.

How to eliminate wrong answers

Option A is wrong because in PaaS the cloud provider manages the network firewall at the perimeter as part of the platform infrastructure. Option C is wrong because patching the underlying operating system is the provider's responsibility in PaaS (the customer does not manage the OS). Option D is wrong because the hypervisor and virtualization layer are always managed by the cloud provider in any cloud service model (IaaS, PaaS, SaaS).

96
MCQhard

A security administrator must verify that a third-party service provider meets the organization's security requirements before signing a contract. The provider will process regulated customer data. Which action provides the most reliable assurance?

A.Obtain and review an independent third-party audit report covering the provider's relevant controls.
B.Ask the provider to confirm verbally during a call that it follows industry best practices.
C.Rely on the provider's marketing materials describing its security program.
D.Accept the provider's completed security questionnaire signed by its sales director.
AnswerA

An independent audit report, such as a SOC 2 report, provides evidence that controls were examined by a qualified external party against defined criteria. Reviewing the scope, period, and exceptions gives reliable assurance for regulated data handling. It is stronger than self-attestation because the provider does not control the assessment.

Why this answer

Independent third-party audit reports give the most reliable assurance because an external auditor examines the provider's controls against recognized criteria and reports scope, period, and exceptions. Self-signed questionnaires, marketing claims, and verbal confirmations are unverified and unsuitable as primary evidence when regulated customer data is involved.

Exam trap

The trap here is treating a provider's self-reported questionnaire or verbal assurance as equivalent to independent audit evidence when regulated data is at stake.

97
MCQmedium

An organization is implementing a digital signature solution to ensure non-repudiation of documents. Which combination of keys is used during the signing process?

A.Recipient's public key to sign, recipient's private key to verify
B.Sender's private key to sign, sender's public key to verify
C.Sender's public key to sign, recipient's private key to verify
D.A shared symmetric key for both signing and verification
AnswerB

Non-repudiation requires the signer to use their private key, which only they hold, and verifiers to use the corresponding public key. This asymmetric pairing proves origin and prevents the sender denying authorship of the signed document.

Why this answer

Digital signatures use asymmetric cryptography where the sender creates a signature with their private key, and the recipient verifies it with the sender's public key. This ensures non-repudiation because only the sender possesses their private key, so they cannot deny having signed the document. The process typically involves hashing the document and encrypting the hash with the sender's private key.

Exam trap

ISC2 SSCP often tests the misconception that signing uses a public key or that verification uses a private key, leading candidates to confuse the roles of keys in encryption versus signing.

How to eliminate wrong answers

Option A is wrong because the recipient's public key is used for encrypting messages to the recipient, not for signing; signing requires the sender's private key, and verification uses the sender's public key, not the recipient's private key. Option C is wrong because the sender's public key cannot sign (signing requires a private key), and the recipient's private key is never used for verification of a sender's signature. Option D is wrong because symmetric keys do not provide non-repudiation; they are shared secrets and cannot uniquely tie a signature to a single sender, as both parties possess the same key.

98
MCQeasy

Which attack sends a flood of forged ICMP echo requests to a network's broadcast address to overwhelm a target?

A.Ping of death
B.Smurf attack
C.SYN flood
D.DNS amplification
AnswerB

A Smurf attack spoofs the victim's source address and sends ICMP echo requests to a network broadcast address, so every host replies to the victim, amplifying traffic. This matches the stem's forged ICMP flood against a broadcast address.

Why this answer

A Smurf attack sends a flood of forged ICMP echo requests to a network's broadcast address with the source IP spoofed as the target's IP. All hosts on the network respond to the broadcast, overwhelming the target with ICMP echo replies. This is a classic amplification attack.

Therefore, Smurf attack is correct.

Exam trap

SSCP often tests the distinction between various flood attacks, and candidates might confuse Smurf with SYN flood or DNS amplification due to the common element of flooding.

How to eliminate wrong answers

Option A is wrong because Ping of death involves sending malformed or oversized ICMP packets to crash a system, not a flood to a broadcast address. Option C is wrong because a SYN flood sends TCP SYN packets to a target to exhaust its connection table, not ICMP to a broadcast address. Option D is wrong because DNS amplification uses DNS queries with spoofed source IPs to overwhelm a target with DNS responses, not ICMP.

99
MCQhard

A certificate authority (CA) issues a certificate with the extended key usage (EKU) extension specifying 'serverAuth'. Which of the following is this certificate allowed to do?

A.Encrypt email
B.Authenticate a TLS server
C.Sign code
D.Issue subordinate CA certificates
AnswerB

The serverAuth EKU value permits the certificate's public key to authenticate a TLS server during the handshake, proving the server's identity to clients. This satisfies the stem's specified extension, restricting usage to server authentication rather than clientAuth, code signing or email protection.

Why this answer

The Extended Key Usage (EKU) extension specifies the intended purpose of a certificate. The 'serverAuth' OID (1.3.6.1.5.5.7.3.1) explicitly permits the certificate to be used for authenticating a TLS server during the SSL/TLS handshake, such as in HTTPS. This is defined in RFC 5280 and is enforced by TLS clients to ensure the certificate is used only for its designated purpose.

Exam trap

A common pitfall is assuming that a certificate with 'serverAuth' can also be used for client authentication or other purposes, but the EKU extension strictly limits usage. Candidates often confuse 'serverAuth' with other EKUs like 'clientAuth' or 'emailProtection'.

How to eliminate wrong answers

Option A is wrong because encrypting email requires the 'emailProtection' EKU (1.3.6.1.5.5.7.3.4), not 'serverAuth'. Option C is wrong because signing code requires the 'codeSigning' EKU (1.3.6.1.5.5.7.3.3), which is a separate purpose. Option D is wrong because issuing subordinate CA certificates requires the 'keyCertSign' key usage extension and often the 'CA:TRUE' basic constraint, not the 'serverAuth' EKU; 'serverAuth' is for end-entity certificates, not for CA certificates.

100
MCQhard

A company's risk management policy states that all risks with a residual risk score of 8 or higher (on a scale of 1-10) must be treated. A risk is identified with an inherent risk score of 9, and after applying controls, the residual risk score is 7. What is the appropriate action?

A.Formally accept the residual risk
B.Apply additional controls to reduce the risk further
C.Purchase cyber insurance to transfer the risk
D.Reassess the inherent risk score
AnswerA

The residual score of 7 falls below the policy threshold of 8, so mandatory treatment is not triggered and the risk can be formally accepted. Inherent risk of 9 is irrelevant once controls reduce exposure; the policy tests residual, not inherent, scores.

Why this answer

The policy threshold is a residual risk score of 8 or higher requiring treatment. The residual score after controls is 7, which is below the threshold, so the risk no longer mandates further treatment and can be formally accepted. Inherent risk (9) is only the pre-control score and is not the trigger for action once controls are applied.

Therefore, documenting acceptance of the residual risk is the correct action.

Exam trap

The trap here is confusing inherent risk with residual risk, causing candidates to keep applying controls or transfer risk even though the post-control score already falls below the policy threshold.

How to eliminate wrong answers

Option B is wrong because additional controls are only required when residual risk remains at or above the policy threshold of 8; at 7, the risk is already within tolerance. Option C is wrong because risk transfer via cyber insurance is a treatment option typically chosen when residual risk cannot be reduced below tolerance or when the organization chooses to transfer financial impact, not the default action when residual risk is already acceptable. Option D is wrong because reassessing the inherent risk score does not change the fact that the residual score of 7 is below the treatment threshold; inherent risk is an input to control selection, not the decision criterion here.

101
MCQhard

A security team is reviewing access control models for a new document management system. The system must support discretionary sharing where document owners can grant access to other users, but it must also enforce a mandatory rule that any document labeled 'Confidential' cannot be accessed by users without a 'Confidential' clearance, regardless of owner intent. Which access control model best satisfies both requirements?

A.Mandatory Access Control (MAC)
B.Discretionary Access Control (DAC)
C.Role-Based Access Control (RBAC)
D.A hybrid approach combining DAC and MAC
AnswerD

A hybrid model allows owners to grant discretionary access while also enforcing mandatory label-based restrictions. This satisfies both the need for owner-controlled sharing and the requirement that Confidential documents remain inaccessible to users without proper clearance. No single traditional model provides both capabilities, so combining them is necessary.

Why this answer

The scenario requires both discretionary sharing by owners and mandatory enforcement of confidentiality labels. DAC provides the former but not the latter, while MAC provides the latter but not the former. A hybrid approach that layers MAC enforcement over DAC permissions meets both requirements simultaneously, which is why it is the correct choice.

Exam trap

The trap here is assuming that DAC alone can enforce mandatory restrictions, when in fact DAC permissions can be overridden by users with ownership rights.

102
MCQmedium

An organization's help desk receives multiple reports of employees unable to access a critical internal application. The IT team confirms the application server is running. What is the FIRST step in the incident response process?

A.Verify the reports and confirm the scope of the issue
B.Restore the application from the latest backup
C.Remove any malicious software from the server
D.Isolate the affected systems from the network
AnswerA

Verifying reports and confirming scope establishes whether a genuine incident exists and how widespread it is before declaring or escalating. This validation step precedes containment, eradication and recovery, ensuring responders act on confirmed facts rather than unverified help desk reports.

Why this answer

The first step in the incident response process is to verify that an incident has actually occurred and determine its scope. This involves validating the reports, confirming the issue is not a false alarm, and assessing the extent of impact. Only after verification should containment, eradication, or recovery actions be taken.

Exam trap

SSCP often tests the urge to jump to containment or recovery actions, but the first step is always verification and scoping to avoid acting on false positives or incomplete information.

How to eliminate wrong answers

Option B is wrong because restoring from backup is a recovery action that should only occur after the incident is verified, contained, and the cause identified. Option C is wrong because removing malware is an eradication step, which comes after verification and containment. Option D is wrong because isolating systems is a containment action, which follows verification and scoping.

103
MCQhard

A company's disaster recovery plan specifies an RTO of 4 hours for its customer relationship management (CRM) system. Which of the following DR site types is MOST appropriate to meet this RTO?

A.Warm site
B.Mobile site
C.Hot site
D.Cold site
AnswerC

A hot site maintains continuously synchronised hardware, data and applications, enabling near-immediate failover well inside the four-hour RTO. Unlike warm or cold sites, which require restoration from backups or hardware provisioning, it satisfies the stem's demanding recovery time constraint for the business-critical CRM system.

Why this answer

A hot site is fully configured with hardware, software, and live data replication, enabling recovery within minutes to a few hours. Since the RTO is 4 hours, a hot site can meet this requirement by allowing immediate failover without the need for extensive setup or data restoration.

Exam trap

The trap here is that candidates often confuse a warm site (which has hardware but not live data) as sufficient for a 4-hour RTO, underestimating the time needed to restore and validate backups, which can easily exceed 4 hours for a CRM system with large databases.

How to eliminate wrong answers

Option A is wrong because a warm site has pre-installed hardware but may lack up-to-date data and require several hours to days to restore from backups, making it unsuitable for a 4-hour RTO. Option B is wrong because a mobile site is a portable unit that must be transported and configured on-site, typically taking days to become operational, far exceeding the 4-hour RTO. Option D is wrong because a cold site provides only physical infrastructure (power, cooling, space) with no IT equipment or data, requiring weeks to procure and install systems, which cannot meet a 4-hour RTO.

104
MCQeasy

After a security incident at a retail company, the incident response team conducts a post-incident review. The team identifies that the attacker gained initial access through an unpatched web server. Which of the following is the PRIMARY purpose of the lessons learned meeting in this scenario?

A.To determine the exact financial cost of the incident for insurance claims.
B.To assign blame to the team responsible for the unpatched server.
C.To identify improvements to prevent similar incidents and enhance response capabilities.
D.To immediately reimage all servers in the environment.
AnswerC

The primary purpose of a lessons learned meeting is to review the incident and identify changes to processes, tools, and training that will improve future prevention and response. In this retail scenario, the unpatched web server highlights a need to strengthen patch management and vulnerability scanning, which the meeting should capture as actionable improvements.

Why this answer

The lessons learned meeting is a post-incident activity focused on improving future prevention, detection, and response. It should produce actionable recommendations, such as strengthening patch management, rather than assigning blame or calculating costs. In this scenario, the unpatched web server points to a process gap that the meeting should address to reduce recurrence risk.

Exam trap

The trap here is equating the lessons learned meeting with blame assignment or cost accounting, when its core purpose is to drive process and control improvements.

105
MCQmedium

An organization's incident response plan is tested annually. After a real incident, the team finds that the plan did not address cloud-based assets. What is the BEST action?

A.Migrate all cloud assets back on-premises
B.Retrain the IR team on cloud incident response
C.Create a separate cloud incident response plan
D.Update the incident response plan to include cloud scenarios
AnswerD

Incorporating cloud scenarios into the incident response plan closes the identified gap, ensuring future incidents involving cloud assets follow defined procedures. Updating the plan directly addresses the deficiency found during the post-incident review rather than only remediating the single event.

Why this answer

The BEST action is to update the existing incident response plan to include cloud scenarios, because the IR plan is a living document that must reflect the organization's actual environment. Since the gap was identified after a real incident, incorporating cloud assets into the same plan ensures a unified, tested response rather than fragmented procedures.

Exam trap

The trap is choosing 'create a separate cloud IR plan' or 'retrain the team' — both sound reasonable, but the question asks for the BEST action to fix the documented plan gap, which is updating the existing plan.

How to eliminate wrong answers

Option A is wrong because migrating cloud assets back on-premises is a business/architecture decision, not an IR remediation, and it defeats the purpose of cloud adoption. Option B is wrong because retraining the team addresses skills but not the documented plan gap — the plan itself still lacks cloud procedures. Option C is wrong because creating a separate cloud IR plan fragments response and creates coordination overhead; best practice is a single integrated plan with cloud-specific annexes or playbooks, not a wholly separate document.

106
Multi-Selectmedium

A vulnerability management team is scanning a network. Which THREE factors should be considered to minimize false positives?

Select 3 answers
A.Scanning only during peak hours
B.Using default scan profiles
C.Tuning the scanner based on the environment
D.Performing authenticated scans
E.Manually verifying results
AnswersC, D, E

Scanner signatures and severity thresholds are generic by default, so tuning them to the actual operating systems, applications and network topology removes checks that do not apply. This eliminates environment-specific false positives before they reach analysts.

Why this answer

Option C is correct because tuning the scanner to the specific environment—adjusting plugin sets, port ranges, timing templates, and severity thresholds—reduces noise from irrelevant checks and mismatched assumptions, which directly lowers false positives. Option D is correct because authenticated (credentialed) scans let the scanner read actual patch levels, registry keys, and installed software instead of inferring vulnerabilities from banners or version strings, eliminating many false positives caused by backported patches or obscured services. Option E is correct because manually verifying findings (for example, confirming a suspected open port with netstat or a service banner with a targeted probe) validates scanner output before it is reported, catching false positives that automated logic cannot resolve.

Option A is not correct because scanning only during peak hours does not reduce false positives and can actually increase them through timeouts and dropped packets under load. Option B is not correct because default scan profiles are generic and often produce more false positives, since they are not tailored to the target environment's operating systems, applications, or network topology.

Exam trap

A common misconception is that scanning during peak hours yields more accurate results, when in fact it degrades scan reliability and increases false positives due to network load and timeouts.

107
Matchingmedium

Match each disaster recovery site type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Fully operational, real-time replication

Partially configured, ready in hours

Empty facility, setup required

Portable unit with equipment

Why these pairings

Disaster recovery site types vary in readiness and equipment. Hot sites are fully operational, warm sites are partially equipped, cold sites provide only infrastructure, and mobile sites are portable units. Common confusions include mixing the definitions of hot and cold sites, or mistaking mobile sites for cold sites.

108
Multi-Selectmedium

A security analyst is responding to a confirmed malware infection on a Windows workstation. The workstation is still powered on and connected to the corporate network. The analyst needs to collect volatile data that could be lost if the system is shut down or the malware is allowed to continue running. Which TWO of the following data sources should the analyst prioritize for collection? (Choose two.)

Select 2 answers
A.Event logs stored in the C:\Windows\System32\winevt\Logs directory.
B.Active network connections and associated process IDs.
C.The master file table (MFT) on the NTFS volume.
D.The Windows Registry hive files stored on the hard drive.
E.Contents of the system's RAM, including running processes and network connections.
AnswersB, E

Active network connections and their associated process IDs are volatile and can reveal command-and-control (C2) communications or data exfiltration. This information is lost when the system is shut down or the connection is terminated. Collecting it early helps identify the malware's external infrastructure and affected processes. Tools like netstat and Get-NetTCPConnection can capture this data quickly.

Why this answer

The two most volatile data sources are RAM contents and active network connections with process IDs. Both are lost when the system is powered off or the malware terminates its connections. Registry hives, MFT, and event logs are stored on disk and persist, so they can be collected later.

Prioritizing volatile data aligns with the order of volatility in incident response.

Exam trap

The trap here is confusing important disk-based artifacts, such as registry hives or event logs, with volatile data that disappears when the system is powered off.

109
MCQhard

An organization is conducting a disaster recovery test for its critical database. The RTO is 4 hours, and the RPO is 15 minutes. During the test, the team restores the database from a backup taken 2 hours before the test. The restore completes in 3 hours. Which statement accurately reflects the test outcome?

A.The test failed because the restore took longer than 15 minutes.
B.The test passed because the backup was available and restorable.
C.The test passed because the RTO was met.
D.The test failed because the RPO was exceeded.
AnswerD

The RPO is 15 minutes, meaning the organization can tolerate losing at most 15 minutes of data. The backup used was 2 hours old, so up to 2 hours of data would be lost, exceeding the RPO. Even though the restore time was within the RTO, the data loss exceeds the RPO, so the test failed from a data loss perspective. This makes the statement correct.

Why this answer

The RPO defines the maximum tolerable data loss, measured in time. A 2-hour-old backup means up to 2 hours of data could be lost, which exceeds the 15-minute RPO. The RTO, which is the maximum tolerable downtime, was met because the restore took 3 hours out of 4 allowed.

However, since the RPO was violated, the test failed overall. The correct statement identifies the RPO exceedance as the failure reason.

Exam trap

The trap here is focusing only on the RTO and ignoring the RPO, or confusing the two metrics, when both must be satisfied for a successful disaster recovery test.

110
Multi-Selecteasy

Which TWO of the following are effective measures to prevent buffer overflow attacks in a custom-developed application?

Select 2 answers
A.Input validation
B.Using unpatched third-party libraries
C.Running the application with least privilege
D.Disabling ASLR
E.Stack canaries
AnswersA, E

Input validation rejects or sanitises oversized and malformed data before it reaches fixed-length buffers, directly removing the precondition buffer overflows exploit. Constraining length and content at trust boundaries prevents the excessive writes that overwrite adjacent memory.

Why this answer

Input validation (A) is correct because strictly checking length, type, and format of all user-supplied data before it is copied into fixed-size buffers prevents the oversized or malformed input that triggers a buffer overflow. Stack canaries (E) are correct because a compiler-inserted canary value placed between local variables and the saved return address is checked on function return, so an overflow that overwrites the return address is detected and the process is aborted before the attacker's code can execute. Running with least privilege (C) is not marked correct because it only limits the damage after a successful exploit rather than preventing the overflow itself.

Using unpatched third-party libraries (B) is wrong because it increases exposure to known memory-corruption vulnerabilities, and disabling ASLR (D) is wrong because ASLR is a memory-randomization defense whose removal makes exploitation easier, not harder.

Exam trap

SSCP often tests the confusion between preventive controls (input validation, canaries) and post-exploitation mitigations (least privilege) or defenses that are actually weakened by disabling them (ASLR).

111
MCQhard

A security analyst notices that an attacker on the same VLAN is able to capture traffic from other hosts, including sensitive data. The attacker has not compromised any switch or router. Which network attack is most likely being used?

A.ARP spoofing
B.MAC flooding
C.VLAN hopping
D.DHCP starvation
AnswerA

ARP spoofing sends forged ARP replies to associate the attacker's MAC address with the IP address of another host, such as the default gateway. This causes traffic to be sent to the attacker, who can then forward it to the legitimate destination while capturing it, enabling man-in-the-middle without switch compromise.

Why this answer

ARP spoofing, also called ARP poisoning, allows an attacker on the same subnet to intercept traffic by sending forged ARP messages. The attacker can then forward traffic to the real destination while capturing it, achieving a man-in-the-middle attack without compromising network devices.

Exam trap

The trap here is assuming that capturing traffic requires a compromised switch or router, when ARP spoofing can achieve it at the endpoint level.

112
MCQhard

Refer to the exhibit. An administrator runs an OpenSSL s_client command and receives the output shown. What is the most likely cause of the 'unable to get local issuer certificate' error?

A.The server's private key is missing.
B.The client does not trust the issuing CA.
C.The server certificate is self-signed.
D.The server certificate has expired.
AnswerB

OpenSSL verifies the server's chain against its local trust store; the error means the intermediate or root CA certificate is absent from that store, so the chain cannot be built. The issuing CA is therefore untrusted by the client, matching the stem's constraint.

Why this answer

The 'unable to get local issuer certificate' error from OpenSSL s_client indicates that the client (the machine running the command) does not have the issuing Certificate Authority (CA) certificate in its trust store. This means the client cannot verify the server certificate's chain of trust. Option B is correct because the error specifically points to a missing or untrusted CA certificate on the client side, not a problem with the server's private key, self-signing, or expiration.

Exam trap

The trap here is that candidates confuse 'unable to get local issuer certificate' with a server-side certificate issue (like expiration or self-signing), when it actually points to a client-side trust store problem.

How to eliminate wrong answers

Option A is wrong because a missing server private key would cause a different error, such as 'unable to load private key' or a TLS handshake failure, not an issuer certificate validation error. Option C is wrong because a self-signed certificate would produce an 'unable to verify the first certificate' or 'self-signed certificate in chain' error, not specifically 'unable to get local issuer certificate' (which implies a missing CA in the trust store, not a self-signed root). Option D is wrong because an expired server certificate would generate an 'certificate has expired' error during validation, not an issuer certificate lookup failure.

113
MCQmedium

A security administrator is configuring log collection for a new web application tier. The organization must retain logs for one year and needs to ensure that log data cannot be altered after collection. Which control best meets the integrity requirement?

A.Store logs on the same web servers that generate them, protected by the application's own file permissions
B.Compress logs into archives on each server and email weekly copies to the security team
C.Forward logs to a centralized server configured with write-once storage and cryptographic hashing of log records
D.Enable verbose logging on all servers and rely on the operating system's default log rotation
AnswerC

Centralized collection with write-once, read-many storage prevents modification or deletion of records, and cryptographic hashing lets auditors verify that entries have not been tampered with. Moving logs off the source hosts also removes them from the blast radius of a compromised application server. Together these controls directly satisfy the requirement that log data remain unaltered for the retention period.

Why this answer

Protecting log integrity requires moving records out of the control of the systems being monitored and storing them where they cannot be modified. Write-once storage plus cryptographic hashing delivers both immutability and verifiability, satisfying the one-year retention and tamper-evidence requirements. Local storage and email archives leave logs exposed to the same threats as the applications themselves.

Exam trap

The trap here is treating log retention as a storage-capacity problem when the requirement is really about tamper-evident integrity.

114
MCQmedium

An organization wants to implement a key exchange mechanism that provides forward secrecy. Which of the following should be used?

A.Pre-shared key
B.Ephemeral Diffie-Hellman
C.RSA key exchange
D.Static Diffie-Hellman
AnswerB

Ephemeral Diffie-Hellman generates a fresh, temporary key pair for each session, so compromising a long-term private key cannot decrypt previously captured traffic. This property is forward secrecy, exactly the mechanism the organisation requires, whereas static Diffie-Hellman or RSA key transport reuse persistent keys and lack it.

Why this answer

Ephemeral Diffie-Hellman (DHE or ECDHE) generates a fresh key pair for each session, so even if the long-term private key is compromised later, past session keys cannot be derived. This property is forward secrecy. It is the standard mechanism used in TLS 1.3 and modern cipher suites (e.g., ECDHE-RSA-AES256-GCM-SHA384).

Exam trap

SSCP often tests the misconception that any Diffie-Hellman provides forward secrecy — candidates must distinguish ephemeral DH (fresh keys per session) from static DH (reused keys), and recognize that RSA key exchange lacks forward secrecy entirely.

How to eliminate wrong answers

Option A is wrong because a pre-shared key is a static secret shared in advance; compromise of the PSK compromises all past and future sessions, providing no forward secrecy. Option C is wrong because RSA key exchange encrypts the session key with the server's long-term RSA private key — if that key is later compromised, all recorded sessions can be decrypted, so no forward secrecy. Option D is wrong because static Diffie-Hellman reuses the same DH key pair across sessions, so compromise of the static private key compromises all sessions, again lacking forward secrecy.

115
Multi-Selectmedium

Which TWO of the following are best practices for securing a wireless network?

Select 2 answers
A.Enabling MAC address filtering
B.Using WEP encryption
C.Leaving the default administrator password
D.Using WPA2-Enterprise with 802.1X
E.Disabling SSID broadcast
AnswersD, E

Provides strong authentication and encryption.

Why this answer

WPA2-Enterprise with 802.1X is a best practice because it provides strong encryption (AES-CCMP) and per-user authentication via a RADIUS server, eliminating the vulnerabilities of pre-shared keys. The 802.1X framework ensures that each user must authenticate individually, preventing unauthorized access even if a single credential is compromised. This is the gold standard for enterprise wireless security.

Exam trap

The trap here is that candidates often confuse 'disabling SSID broadcast' (option E) as a security measure, but it is a best practice for reducing network visibility in low-risk environments, even though it is not a strong security control; the SSCP exam expects you to recognize it as a valid defense-in-depth practice, not a primary security mechanism.

116
MCQhard

A financial services firm is migrating a customer-facing web application to a containerized platform. The security team wants to reduce the risk of a compromised container accessing the host kernel or other containers. Which of the following is the MOST effective control to limit the impact of a container breakout?

A.Scanning container images for known vulnerabilities before deployment
B.Enabling verbose logging of container stdout and stderr
C.Running containers with a read-only root filesystem
D.Enforcing a seccomp profile that allows only required system calls
AnswerD

Seccomp filters restrict which system calls a container process may invoke, directly limiting the kernel attack surface an attacker can use during a breakout attempt. By allowing only the calls the application needs, the profile blocks dangerous syscalls that are commonly abused for privilege escalation or container escape. This makes it the most effective control for reducing breakout impact.

Why this answer

Seccomp profiles constrain the system call interface exposed to container processes, directly shrinking the kernel attack surface an attacker can use to escape. Read-only filesystems, image scanning, and logging all add value at different stages but do not restrict runtime kernel interactions. Restricting syscalls is the most effective way to limit breakout impact on a shared host.

Exam trap

The trap here is equating preventive scanning or logging with runtime containment, when the control that actually limits a breakout must restrict what the running process can ask the kernel to do.

117
MCQeasy

Which access control model allows the owner of a resource to grant permissions to others?

A.Discretionary Access Control (DAC)
B.Attribute-Based Access Control (ABAC)
C.Mandatory Access Control (MAC)
D.Role-Based Access Control (RBAC)
AnswerA

Discretionary Access Control satisfies the stem's requirement because the resource owner holds discretion over permissions, typically via access control lists, and can pass that authority to other subjects. Unlike mandatory or role-based models, DAC permits owner-initiated delegation, directly matching the scenario where an owner grants permissions to others.

Why this answer

Discretionary Access Control (DAC) is defined by the owner of an object having the discretion to grant or revoke access to other subjects, typically via ACLs on files or resources. This owner-controlled permission model is the defining characteristic of DAC, as opposed to MAC where the system enforces labels and RBAC where roles determine access.

Exam trap

The trap is confusing 'owner grants permissions' with RBAC or ABAC; candidates often pick RBAC because it sounds like delegated administration, but only DAC explicitly places grant authority with the resource owner.

How to eliminate wrong answers

Option B is wrong because ABAC grants access based on a combination of attributes (user, resource, environment, action) evaluated by policy, not on owner discretion. Option C is wrong because MAC uses system-assigned sensitivity labels and clearances; owners cannot arbitrarily grant access. Option D is wrong because RBAC assigns permissions to roles, and users inherit permissions through role membership — the owner does not individually grant access.

118
MCQhard

A cloud security team is using Cloud Security Posture Management (CSPM) to identify misconfigurations. Which of the following scenarios is MOST likely to be detected by CSPM?

A.An application running on a cloud VM has a memory leak causing performance degradation
B.A cloud storage bucket is configured with public read access
C.A cloud-based database is experiencing slow query response times
D.An employee's credentials were used from an unusual geographic location
AnswerB

CSPM evaluates cloud resource configurations against security baselines and benchmarks. A storage bucket set to public read access is a classic configuration drift that CSPM detects and flags, since it inspects control-plane settings rather than runtime traffic or application behaviour.

Why this answer

CSPM tools continuously scan cloud configurations against security benchmarks (CIS, NIST, PCI-DSS) and detect misconfigurations like publicly accessible storage buckets, overly permissive IAM policies, unencrypted volumes, and disabled logging. A publicly readable S3 bucket is a textbook CSPM finding.

Exam trap

SSCP often tests whether candidates can distinguish CSPM (configuration/posture) from runtime monitoring, APM, and UEBA tools — the key is whether the issue is a static misconfiguration versus a behavioral or performance anomaly.

How to eliminate wrong answers

Option A is wrong because memory leaks are runtime application performance issues detected by APM tools (e.g., CloudWatch, Datadog), not configuration scanners. Option C is wrong because slow database queries are performance concerns surfaced by database monitoring tools (Performance Insights, slow query logs), not posture management. Option D is wrong because anomalous credential usage from unusual geographies is detected by UEBA/behavioral analytics tools (GuardDuty, CloudTrail Insights), not CSPM.

119
MCQmedium

A security team is implementing a risk treatment plan for a high-risk vulnerability. The cost to fix the vulnerability is $100,000, but the expected loss if exploited is $1,000,000. The annual likelihood of exploitation is 2%. Which risk treatment strategy is most appropriate?

A.Avoid the risk by decommissioning the asset
B.Remediate the vulnerability immediately
C.Accept the risk and monitor for changes
D.Transfer the risk by purchasing cyber insurance
AnswerC

Annualised loss expectancy is $20,000 ($1,000,000 x 2%), far below the $100,000 remediation cost, so accepting and monitoring is the economically justified strategy. Spending five times the expected annual loss to fix it is not cost-effective.

Why this answer

The annualized loss expectancy (ALE) is $20,000 (2% × $1,000,000), which is less than the $100,000 remediation cost. Since the cost to fix exceeds the expected loss, accepting the risk and monitoring for changes is the most cost-effective strategy. This aligns with the risk management principle that treatment should be proportional to the risk exposure.

Exam trap

ISC2 often tests the misconception that any high-severity vulnerability must be immediately remediated, ignoring the quantitative cost-benefit analysis that shows accepting risk can be the most appropriate strategy when the annualized loss is lower than the fix cost.

How to eliminate wrong answers

Option A is wrong because decommissioning the asset would eliminate all business value from it, which is an extreme measure not justified when the annual expected loss ($20,000) is far lower than the remediation cost ($100,000). Option B is wrong because immediate remediation would cost $100,000 to prevent a $20,000 annual expected loss, violating the cost-benefit principle of risk management. Option D is wrong because transferring the risk via cyber insurance would still involve premiums and deductibles that likely exceed the $20,000 ALE, and insurance does not reduce the technical vulnerability itself.

120
MCQmedium

A security administrator is configuring a mobile device management (MDM) policy for company-owned smartphones. The organization wants to ensure that if a device is lost or stolen, corporate data can be removed without affecting the user's personal data. Which of the following MDM capabilities should be enabled?

A.Selective wipe of corporate data
B.Enforcing a strong screen lock PIN
C.Containerization of corporate applications
D.Remote wipe of the entire device
AnswerA

Selective wipe (or enterprise wipe) removes only corporate data and configurations from a device, leaving personal data intact. This meets the requirement of protecting corporate information while respecting user privacy. It is a standard MDM feature for BYOD or company-owned devices with personal use.

Why this answer

Selective wipe is designed to remove only corporate data and settings from a mobile device, preserving personal data. This is essential for scenarios where devices are used for both work and personal purposes. It ensures that sensitive company information is not exposed if the device is lost or stolen, while not intruding on the user's personal data.

Exam trap

The trap here is choosing full remote wipe as the solution, which would erase personal data and is not appropriate when personal data must be preserved.

121
Multi-Selectmedium

An analyst is reviewing alerts from a network-based intrusion detection system (NIDS) deployed on a span port at the internet edge. Several alerts reference exploit attempts against services that are not exposed to the internet. Which TWO actions should the analyst take to improve the fidelity of the monitoring data? (Choose two.)

Select 2 answers
A.Verify the span port configuration and confirm which VLANs and interfaces are actually mirrored
B.Increase the alert severity of all exploit signatures to critical to ensure they are reviewed
C.Enable blocking mode so the NIDS drops packets matching the noisy signatures
D.Disable all exploit-class signatures and rely solely on anomaly-based detection
E.Tune the NIDS signature set to match the services actually exposed on the monitored segment
AnswersA, E

A span port that mirrors the wrong VLANs or an incorrect interface set can feed the NIDS traffic from internal segments, making internal-only services appear internet-facing in alerts. Confirming exactly what is mirrored establishes ground truth about what the sensor can see, which is essential before drawing conclusions from any alert and prevents misinterpretation of where attacks actually occurred.

Why this answer

Alerts against services that are not actually reachable indicate a mismatch between what the sensor is configured to detect or see and the environment it protects. Restricting signatures to the real exposed services removes irrelevant detections, and validating the span port mirroring confirms the sensor is observing the intended segment, so alerts can be trusted to reflect genuine attack surface.

Exam trap

The trap here is assuming noisy alerts require blocking or severity escalation, when the real issue is signature scope and what traffic the sensor actually receives.

122
MCQhard

An organization uses an ABAC system to control access to documents. Policies are defined using attributes such as user department, document classification, and time of day. Which of the following is an example of an ABAC policy rule?

A.The owner of a document can grant read access to any other user.
B.Users in the 'HR' role can read documents classified as 'Confidential'.
C.All users with security clearance 'Secret' can read documents labeled 'Secret'.
D.If user.department == 'HR' AND doc.classification == 'Confidential' AND time.business_hours == true then permit read.
AnswerD

ABAC evaluates boolean rules combining multiple attributes of subject, resource, and environment. This rule matches user department, document classification, and time of day, then permits read, exactly the attribute-based evaluation model rather than role- or label-only checks.

Why this answer

Option D is correct because ABAC (Attribute-Based Access Control) evaluates policies built from multiple attributes — user, resource, action, and environment — combined with Boolean logic. The rule 'user.department == HR AND doc.classification == Confidential AND time.business_hours == true then permit read' explicitly combines a subject attribute (department), a resource attribute (classification), and an environmental attribute (time of day), which is the defining characteristic of an ABAC policy. NIST SP 800-162 defines ABAC as evaluating attributes of the subject, object, operation, and environment to make access decisions.

Exam trap

The trap here is confusing RBAC with ABAC — option B looks attribute-like because it mentions 'HR' and 'Confidential', but it is a role-based rule with no Boolean combination of subject, resource, and environmental attributes.

How to eliminate wrong answers

Option A is wrong because it describes a Discretionary Access Control (DAC) rule based on ownership and delegation, not attribute evaluation. Option B is wrong because it is a Role-Based Access Control (RBAC) rule — access is granted based on the user's role ('HR'), not on evaluated attributes. Option C is wrong because it is a Mandatory Access Control (MAC)/clearance-based rule (Bell-LaPadula style), where access is determined by comparing clearance levels rather than by evaluating a policy expression of multiple attributes.

123
MCQhard

A hospital uses a MAC-based system where data labels carry classifications such as Restricted and Public, and user clearances are assigned by the security office. A nurse with a Secret-equivalent clearance attempts to read a patient record labeled with a higher classification. According to the Bell-LaPadula model, what should occur?

A.The read is permitted because the nurse is accessing the record over an encrypted channel
B.The read is denied because no-read-up prevents reading higher-classified data
C.The read is allowed but only if the nurse first writes a justification to the audit log
D.The read is allowed because the nurse has a legitimate business need
AnswerB

Bell-LaPadula's simple security property, often called no-read-up, states that a subject cannot read an object with a classification higher than the subject's clearance. The nurse's clearance is lower than the record's label, so the read must be denied. This preserves confidentiality by preventing lower-cleared subjects from accessing more sensitive data, even when they have a legitimate operational reason to see it.

Why this answer

Bell-LaPadula enforces confidentiality through the simple security property, which forbids a subject from reading an object at a higher classification than the subject's clearance. Since the nurse's clearance is below the record's label, the read is denied. Business need, logging, and encryption do not alter the mandatory clearance comparison that drives the access decision.

Exam trap

The trap here is treating a legitimate business need as sufficient authorization, when mandatory access control models decide access purely from clearance and label relationships.

124
MCQeasy

A security analyst is documenting an incident that involved unauthorized access to a file server. The analyst needs to record the timeline of events, actions taken, and evidence collected. Which of the following is the PRIMARY purpose of maintaining proper documentation during incident response?

A.To satisfy the requirement that all incidents must be reported to law enforcement within 24 hours.
B.To provide a detailed record that supports legal proceedings, regulatory compliance, and post-incident review.
C.To allow the public relations team to craft a press release about the incident.
D.To ensure that the incident response team can bill the organization for overtime hours.
AnswerB

Proper documentation during incident response serves multiple critical purposes: it creates an admissible record for legal action, demonstrates compliance with regulations and standards, and provides data for lessons learned and process improvement. Without accurate documentation, the organization may be unable to pursue legal remedies, face compliance penalties, or fail to understand the root cause. This is a fundamental requirement in NIST SP 800-61 and other incident response frameworks.

Why this answer

Incident response documentation is essential for creating a reliable record that can be used in legal proceedings, to demonstrate regulatory compliance, and to conduct meaningful post-incident reviews. It captures the timeline, actions taken, and evidence collected, ensuring accountability and enabling lessons learned. Without it, organizations risk losing critical information needed for prosecution, compliance audits, and improving future response efforts.

Other purposes like billing, blanket law enforcement reporting, or PR are secondary and not the primary drivers.

Exam trap

The trap here is confusing secondary benefits like public relations or billing with the primary purpose of documentation, which is to maintain an accurate and admissible record for legal, compliance, and improvement purposes.

125
MCQhard

An organization is configuring a VPN using IPsec. To ensure forward secrecy, which key exchange method should be used?

A.Ephemeral Diffie-Hellman (DHE or ECDHE)
B.RSA key exchange
C.Pre-shared key (PSK)
D.Static Diffie-Hellman
AnswerA

Ephemeral Diffie-Hellman generates a fresh, single-use key pair for each session, then discards it. Compromise of one session key therefore cannot expose past or future traffic, satisfying the forward secrecy requirement. Static Diffie-Hellman or pre-shared keys reuse the same secret, so they cannot provide this property.

Why this answer

Ephemeral Diffie-Hellman (DHE or ECDHE) provides forward secrecy because it generates a temporary, one-time key pair for each session. If the long-term private key is compromised, past session keys cannot be derived, as the ephemeral keys are discarded after use. This ensures that even if an attacker records encrypted traffic and later obtains the private key, they cannot decrypt past sessions.

Exam trap

The trap here is that candidates often confuse 'Diffie-Hellman' in general with forward secrecy, not realizing that only the ephemeral variant (DHE/ECDHE) provides it, while static Diffie-Hellman does not.

How to eliminate wrong answers

Option B (RSA key exchange) is wrong because RSA uses the server's static private key to encrypt the pre-master secret; if the private key is later compromised, all past session keys can be decrypted, providing no forward secrecy. Option C (Pre-shared key (PSK)) is wrong because PSK relies on a static shared secret that does not change per session; if the PSK is compromised, all past and future sessions can be decrypted. Option D (Static Diffie-Hellman) is wrong because it uses fixed, long-term Diffie-Hellman keys that do not change per session; compromise of the static private key allows an attacker to derive all past session keys, violating forward secrecy.

126
MCQhard

During a security audit, it is discovered that several employees have access to shared network drives containing sensitive HR data. The HR manager states that these employees no longer need access. What is the most efficient way to revoke access?

A.Remove the users from the security group that grants access to the drives.
B.Delete the user accounts of the affected employees.
C.Reconfigure the shared drive to deny access to all users except HR.
D.Manually remove each user's permissions on the shared drive.
AnswerA

Access to the shared drives is granted through security group membership, so removing the users from that group revokes their permissions in one action. Editing each folder's ACL individually would be slower and error-prone, making group removal the most efficient approach.

Why this answer

The most efficient way to revoke access is to remove the users from the security group that grants access to the drives. In Windows environments, shared drive permissions are typically assigned to Active Directory security groups rather than individual users. By removing the users from the group, their permissions are revoked immediately across all resources that group has access to, without needing to touch each resource individually.

Exam trap

The trap here is that candidates may think manually removing permissions (Option D) is more precise, but they overlook that group-based management is the most efficient and scalable method in enterprise environments, and that deleting accounts (Option B) is a disproportionate response that violates operational continuity.

How to eliminate wrong answers

Option B is wrong because deleting user accounts is an extreme and irreversible action that disrupts all other services and access the employees may need, and it is not a targeted revocation of drive access. Option C is wrong because reconfiguring the shared drive to deny all users except HR would affect all other employees who might legitimately need access, and it does not address the specific users who should lose access without impacting others. Option D is wrong because manually removing each user's permissions on the shared drive is inefficient and error-prone, especially in large environments, and does not leverage group-based access control which is the standard for scalable permission management.

127
MCQmedium

An employee is leaving the company. As part of the offboarding process, which action should be taken regarding the hardware assigned to the employee?

A.Keep the hardware in storage indefinitely
B.Sanitise the hard drive and then dispose or reassign
C.Recycle the hardware without any data removal
D.Reassign the hardware to a new employee without wiping
AnswerB

Sanitising overwrites or cryptographically erases residual data before the drive leaves the departing employee's control, satisfying the offboarding requirement to prevent unauthorised data recovery. Reassignment or disposal without sanitisation would expose company data, so this action directly addresses the hardware handling constraint in the stem.

Why this answer

Sanitising the hard drive before disposal or reassignment is the correct action because it ensures all sensitive company and employee data is securely removed, preventing data leakage. This aligns with data remanence best practices and regulatory requirements for media sanitisation. Reassigning or disposing without sanitisation exposes the organization to data breach risks.

Exam trap

SSCP often tests the misconception that simply deleting files or reformatting a drive is sufficient for sanitisation, when in fact secure overwrite or purge is required to prevent data remanence.

How to eliminate wrong answers

Option A is wrong because keeping hardware in storage indefinitely does not address data security and wastes assets; it also fails to sanitise the data, leaving it vulnerable if the storage is compromised. Option C is wrong because recycling hardware without data removal leaves sensitive data intact, violating data protection policies and increasing the risk of unauthorized access. Option D is wrong because reassigning hardware without wiping it allows the new employee to access the previous employee's data, which is a serious security and privacy violation.

128
MCQmedium

A company's policy requires that all data at rest be encrypted. Which of the following is the most effective method to encrypt files on a laptop?

A.Encrypt only the user's home folder.
B.Encrypt individual files using a symmetric key.
C.Implement full disk encryption (FDE).
D.Use a self-extracting encrypted archive.
AnswerC

Full disk encryption protects all data at rest on the laptop, including the operating system, temporary files and swap space, using a volume-level key tied to the drive. This satisfies the policy's blanket requirement for encrypting all data at rest, unlike file-level encryption that leaves unselected files exposed.

Why this answer

Full disk encryption (FDE) encrypts the entire storage volume, including the operating system, swap files, temporary files, and all user data. This ensures that if the laptop is lost or stolen, all data at rest is protected without relying on the user to selectively encrypt files or folders, which can leave sensitive data exposed in unencrypted system areas.

Exam trap

The trap here is that candidates often choose encrypting only the home folder or individual files because they think it is sufficient, but they overlook that system areas like swap, temp, and hibernation files can contain sensitive data in plaintext, making full disk encryption the only comprehensive solution for data at rest on a laptop.

How to eliminate wrong answers

Option A is wrong because encrypting only the user's home folder leaves the operating system, swap files, temporary files, and other system areas unencrypted, which can contain cached or residual copies of sensitive data. Option B is wrong because encrypting individual files with a symmetric key requires manual selection and management of each file, increasing the risk of human error and leaving metadata, temporary copies, and swap space unencrypted. Option D is wrong because a self-extracting encrypted archive only protects the specific files placed inside it, leaving the rest of the filesystem and system areas unencrypted, and it requires user interaction to create and extract, making it impractical for comprehensive data-at-rest protection.

129
MCQeasy

A healthcare organization is developing a mobile application that stores patient data locally on the device. The security team must ensure that if a device is lost or stolen, the data cannot be accessed without the user's authentication. Which of the following controls should be implemented to meet this requirement?

A.Use obfuscation to hide the application's code and data structures.
B.Store all patient data in a remote database and cache nothing locally.
C.Enable full-device encryption and require a strong passcode.
D.Implement certificate pinning for all API communications.
AnswerC

Full-device encryption protects all data at rest, including the application's local storage. When combined with a strong passcode, the encryption keys are derived from the passcode, so without it the data remains inaccessible. This directly satisfies the requirement that lost or stolen devices do not expose patient data, as the attacker cannot decrypt the storage without the passcode.

Why this answer

The most direct control to prevent access to locally stored data on a lost or stolen device is full-device encryption tied to a passcode. This ensures that without the correct passcode, the encryption keys cannot be derived, rendering the data unreadable. Other options address different threats such as network interception or reverse engineering, but not data-at-rest confidentiality.

Exam trap

The trap here is confusing data-in-transit protections like certificate pinning with data-at-rest protections, which are needed for lost device scenarios.

130
Multi-Selecthard

Which THREE are common types of network-based attacks? (Choose three.)

Select 3 answers
A.Buffer overflow
B.ARP spoofing
C.SQL injection
D.SYN flood
E.DNS amplification
AnswersB, D, E

ARP spoofing sends forged Address Resolution Protocol replies on a local segment, binding the attacker's MAC address to a legitimate IP. This enables man-in-the-middle interception and is network-based, exploiting link-layer protocol trust rather than host or application flaws.

Why this answer

ARP spoofing, SYN flood, and DNS amplification are all common network-based attacks. ARP spoofing operates at Layer 2 by sending falsified ARP messages to associate the attacker's MAC with a legitimate IP, enabling traffic interception. SYN flood exploits the TCP three-way handshake by sending numerous SYN packets without completing the handshake, exhausting server resources.

DNS amplification is a volumetric attack that uses open DNS servers to amplify traffic by sending small queries that generate large responses. Buffer overflow and SQL injection are application-layer attacks, not network-based.

Exam trap

The trap here is that candidates often confuse application-layer attacks (like SQL injection or buffer overflow) with network-based attacks, but the SSCP exam specifically tests whether you can distinguish attacks that operate at Layer 2 or Layer 3 of the OSI model from those targeting software or databases.

131
MCQhard

An organization uses a cloud-based file synchronization service to share project files with external partners. The security team discovers that an unauthorized third party accessed sensitive documents by guessing weak passwords. Which additional control would most effectively mitigate this risk?

A.Enforcing multi-factor authentication for all external users.
B.Requiring all file transfers to use SFTP instead of HTTPS.
C.Implementing file-level encryption with keys stored on-premises.
D.Configuring the service to use a custom domain certificate.
AnswerA

Enforcing multi-factor authentication adds a second verification factor beyond the password, so a guessed or reused credential alone no longer grants access. This directly addresses the weak-password guessing vector for external partners, satisfying the requirement to mitigate unauthorised access without disrupting file synchronisation.

Why this answer

The breach occurred because attackers guessed weak passwords, so the root cause is inadequate authentication strength. Enforcing multi-factor authentication (MFA) for all external users adds a second factor beyond the password, so even a correctly guessed or brute-forced password is insufficient to gain access. This directly addresses the credential-guessing attack vector described in the scenario.

Exam trap

The trap here is that candidates focus on encrypting or re-routing data (SFTP, file encryption, certificates) when the actual attack vector was weak authentication, so they pick a control that protects data in transit or at rest instead of strengthening the login process itself.

How to eliminate wrong answers

Option B is wrong because switching from HTTPS to SFTP only changes the transport protocol for file transfer; the cloud sync service still authenticates users with the same weak passwords, so credential guessing remains possible. Option C is wrong because file-level encryption with on-premises keys protects data confidentiality if storage is compromised, but it does not prevent an attacker who authenticates with a guessed password from accessing and decrypting files through the legitimate service. Option D is wrong because a custom domain certificate only affects TLS identity/branding for the service URL; it has no effect on authentication strength and does nothing to stop password guessing.

132
Multi-Selectmedium

Which three of the following are best practices for securing a wireless network? (Choose three.)

Select 3 answers
A.Use MAC address filtering
B.Set a weak passphrase for guest network
C.Disable SSID broadcast
D.Enable WPA3-Enterprise
E.Implement rogue AP detection
AnswersC, D, E

Hiding the SSID reduces casual detection.

Why this answer

Disabling SSID broadcast prevents the access point from including its network name in beacon frames, making the network less visible to casual scanning tools. While this does not provide true security (as the SSID can still be discovered via passive monitoring of probe responses or association frames), it reduces the attack surface by hiding the network from non-malicious users and automated discovery scripts.

Exam trap

ISC2 often tests the misconception that disabling SSID broadcast is a strong security measure, when in reality it is only a minor obscurity technique that does not protect against determined attackers using passive sniffing tools like Wireshark or airodump-ng.

133
MCQhard

A security awareness program is being developed. Which topic is MOST critical for all employees to understand to reduce the risk of social engineering?

A.The risks of posting on social media
B.The proper use of mobile devices
C.How to recognize and report phishing attempts and other suspicious communications
D.How to create strong passwords
AnswerC

Phishing underpins most social engineering attacks, exploiting human trust rather than technical flaws. Training every employee to recognise and report suspicious communications directly reduces the likelihood of credential theft and malware entry, addressing the human factor that technical controls cannot fully mitigate.

Why this answer

Social engineering attacks, such as phishing, vishing, and smishing, exploit human psychology rather than technical vulnerabilities. The most critical defense for all employees is the ability to recognize indicators of these attacks (e.g., spoofed sender addresses, urgent language, mismatched URLs) and follow the proper reporting procedure to enable rapid incident response. Without this skill, even the strongest technical controls can be bypassed by a single successful click.

Exam trap

ISC2 often tests the distinction between general security best practices (like strong passwords) and the specific, human-focused defense against social engineering, where recognition and reporting are paramount.

How to eliminate wrong answers

Option A is wrong because while social media risks are relevant, they are a subset of social engineering vectors and not the most immediate, universal threat; the primary attack vector is email-based phishing. Option B is wrong because mobile device usage policies (e.g., MDM, encryption) address device security but do not directly train employees to identify deceptive communications. Option D is wrong because strong passwords mitigate credential-guessing attacks, but social engineering bypasses passwords entirely by tricking users into revealing them or executing actions without authentication.

134
Multi-Selecthard

Which THREE of the following are valid considerations when deploying a remote access VPN using SSL/TLS? (Select THREE)

Select 3 answers
A.Typically uses UDP port 500
B.Supports endpoint security posture checks
C.Can be configured for split tunneling
D.Can traverse firewalls more easily than IPsec
E.Requires pre-shared keys for authentication
AnswersB, C, D

Many SSL/TLS VPN gateways integrate host checks, verifying patch level, antivirus state and device compliance before granting tunnel access. This satisfies the stem's deployment consideration by enforcing endpoint posture at connection time, a control IPsec remote-access deployments typically require separate tooling to achieve.

Why this answer

Option B is correct because SSL/TLS VPNs (such as Cisco AnyConnect or Fortinet SSL VPN) commonly integrate host-scanning or posture-assessment modules that verify antivirus, patch level, and firewall status on the endpoint before granting access. Option C is correct because SSL/TLS VPN clients can be configured for split tunneling, allowing only traffic destined for corporate subnets to go through the tunnel while other traffic (e.g., internet browsing) goes directly out the local gateway. Option D is correct because SSL/TLS VPNs typically operate over TCP port 443 (HTTPS), which is almost universally permitted through firewalls and proxies, whereas IPsec requires UDP 500/4500 and ESP (protocol 50), which are frequently blocked.

Option A is incorrect because UDP port 500 is used by IKE for IPsec, not by SSL/TLS VPNs. Option E is incorrect because SSL/TLS VPNs authenticate users via certificates, RADIUS, LDAP, or SAML, and pre-shared keys are characteristic of IPsec, not SSL/TLS VPNs.

Exam trap

SSCP often tests whether candidates can distinguish SSL/TLS VPN characteristics from IPsec characteristics — mixing up ports (UDP 500 vs TCP 443) and authentication methods (PSK vs certificates/SAML) is the common error.

135
MCQeasy

Which of the following is a method to check the revocation status of a digital certificate in real-time without the client downloading a full list?

A.Certificate Revocation List (CRL)
B.Self-signed certificate validation
C.Online Certificate Status Protocol (OCSP)
D.Certificate Transparency (CT)
AnswerC

OCSP queries a responder directly about a single certificate's status, returning good, revoked or unknown in real time. Unlike a CRL, the client never downloads the full revocation list, which satisfies the requirement for immediate status checking without bulk list retrieval.

Why this answer

OCSP (Online Certificate Status Protocol) lets a client query a responder in real time for the revocation status of a specific certificate, returning 'good,' 'revoked,' or 'unknown' without downloading the entire CRL. It is defined in RFC 6960 and is the standard real-time alternative to CRLs. This matches the requirement exactly.

Exam trap

SSCP often tests the difference between CRL (batch, download-heavy) and OCSP (real-time, per-certificate) — candidates pick CRL because it's the more familiar revocation concept, missing the 'real-time without downloading a full list' qualifier.

How to eliminate wrong answers

Option A is wrong because a CRL is a full list of revoked certificates that the client must download and parse — the opposite of real-time, per-certificate checking. Option B is wrong because self-signed certificate validation is about trust anchors, not revocation status. Option D is wrong because Certificate Transparency is a logging framework for issuing certificates to detect mis-issuance; it does not provide real-time revocation status.

136
Multi-Selectmedium

An organization is reviewing its account lifecycle management process. Which TWO activities are part of the provisioning phase? (Select TWO.)

Select 2 answers
A.Creating user accounts in the identity store
B.Modifying user roles due to job change
C.Archiving user data for compliance
D.Assigning initial role memberships and permissions
E.Disabling accounts upon termination
AnswersA, D

Provisioning covers creating and placing identities into the store, so account creation is a core provisioning activity. It precedes ongoing maintenance tasks such as permission updates, reviews and eventual deprovisioning, satisfying the lifecycle phase the stem asks about.

Why this answer

Option A is correct because provisioning begins with creating the user account (identity) in the identity store, such as an LDAP directory or IdP, so the user has a unique identity to authenticate with. Option D is correct because provisioning also includes granting the initial entitlements — assigning the baseline role memberships and permissions the user needs on day one. Option B is not part of provisioning; modifying roles after a job change is a re-provisioning/change (mover) activity in the lifecycle.

Option C is not part of provisioning; archiving user data for compliance belongs to the deprovisioning/retention phase. Option E is not part of provisioning; disabling accounts on termination is a deprovisioning (leaver) activity.

Exam trap

SSCP often tests the boundary between provisioning and deprovisioning by offering role modification and account disabling as distractors, since candidates conflate all account changes with 'provisioning'.

137
MCQeasy

An IT administrator needs to ensure that all workstations receive security patches in a timely manner. Which process is MOST effective for this?

A.Use only operating systems that no longer require security patches
B.Assign a technician to manually patch each workstation monthly
C.Deploy a centralized patch management solution
D.Enable automatic updates on each workstation from the vendor
AnswerC

A centralised patch management solution distributes and tracks security patches across all workstations from one console, ensuring timely, consistent deployment. This directly satisfies the requirement that every workstation receive patches promptly, unlike manual or per-machine updating.

Why this answer

A centralized patch management solution (C) is the most effective because it provides a single point of control to automate the distribution, installation, and verification of security patches across all workstations. It ensures consistency, timeliness, and scalability, and typically includes reporting and compliance features that manual or decentralized methods lack. This directly addresses the need to patch all workstations in a timely manner.

Exam trap

SSCP often tests the misconception that enabling automatic updates on individual workstations is sufficient for enterprise patch management, but the exam expects recognition that centralized control and reporting are essential for timely and consistent patching.

How to eliminate wrong answers

Option A is wrong because no operating system can remain secure without patches; even embedded or legacy systems require updates, and avoiding patches entirely is impossible and insecure. Option B is wrong because manual patching is error-prone, time-consuming, and not scalable for many workstations, making it difficult to ensure timely patching. Option D is wrong because enabling automatic updates on each workstation relies on individual user settings and network conditions, lacks centralized visibility and control, and may fail if users disable updates or if systems are offline.

138
MCQmedium

A company uses a SIEM to detect anomalies. An alert indicates a user logged in from two geographically distant locations within 5 minutes. What is the most likely indication?

A.Insider threat
B.Time synchronization issue
C.Credential theft and reuse
D.Misconfigured VPN
AnswerC

Simultaneous logins from geographically distant locations within five minutes are physically impossible for one person, so the session credentials have almost certainly been stolen and reused by an attacker. This impossible-travel pattern is a classic SIEM correlation rule indicating credential theft rather than a false positive.

Why this answer

Simultaneous logins from two geographically distant locations within a very short window is a classic impossible-travel indicator, which strongly suggests the credentials were stolen and reused by an attacker while the legitimate user is elsewhere. This pattern is a hallmark of credential theft, phishing, or credential-stuffing attacks. A SIEM correlates authentication logs with geolocation and time to flag exactly this anomaly.

Exam trap

The trap is overthinking the scenario and choosing 'insider threat' or 'VPN misconfiguration'; the exam expects you to recognize the textbook impossible-travel signature of compromised credentials.

How to eliminate wrong answers

Option A is wrong because an insider threat typically involves authorized users abusing their own access, not the same account appearing in two distant locations at once. Option B is wrong because time synchronization issues would cause timestamp inconsistencies across logs, not two successful authentications from different geographies. Option D is wrong because a misconfigured VPN would more likely cause failed connections or a single unexpected source IP, not two concurrent successful logins from distant locations.

139
MCQmedium

A security analyst is reviewing the organization's SIEM and notices that the daily log volume dropped by 60 percent overnight, but no maintenance window was scheduled. The analyst must determine whether this is a genuine reduction in activity or a monitoring failure. Which action should the analyst take FIRST to validate the health of the monitoring capability?

A.Perform a log-source inventory reconciliation against the SIEM's expected asset list and verify each critical source is actively sending events.
B.Increase the severity threshold for correlation rules so that only high-priority alerts are generated while the volume anomaly is investigated.
C.Run a full vulnerability scan against the entire environment to confirm whether any systems have stopped responding.
D.Review the SIEM's storage utilization and archive older logs to free capacity for incoming events.
AnswerA

A sudden drop in log volume usually indicates one or more sources stopped forwarding. Reconciling the expected source inventory against what the SIEM currently receives identifies silent sources, such as a failed collector or broken agent, before assuming the environment is quiet. This directly validates monitoring coverage and restores visibility.

Why this answer

A sharp, unexplained decrease in collected logs points to a monitoring failure rather than a quiet network. The fastest way to confirm this is to compare the SIEM's expected log sources with those actually reporting. Identifying silent sources restores visibility and prevents the organization from operating blind while believing it is fully monitored.

Exam trap

The trap here is assuming a drop in log volume means the environment became quieter, rather than suspecting that a log source stopped reporting.

140
MCQmedium

An organization wants to ensure that sensitive data on laptops is protected in case of loss or theft. Which control is MOST effective?

A.Full disk encryption
B.Strong password policy
C.Asset tracking software
D.Remote wiping capability
AnswerA

Full disk encryption renders the entire volume unreadable without the decryption key, so a stolen laptop's data stays confidential even if the drive is removed. This directly satisfies the loss-or-theft constraint, unlike file-level or database controls that leave unencrypted remnants exposed.

Why this answer

Full disk encryption (FDE) is the most effective control because it renders data unreadable at rest on the entire drive, including the operating system, swap files, and temporary files. Without the decryption key (e.g., a pre-boot PIN or TPM-bound key), an attacker cannot access any data even if the laptop is physically removed. This directly addresses the threat of data exposure from loss or theft, unlike controls that only limit access or track the device.

Exam trap

The trap here is that candidates often choose remote wiping (D) because it seems proactive, but they overlook the critical requirement that the device must be online and powered on to execute the wipe, whereas full disk encryption protects data even if the device is never turned on again.

How to eliminate wrong answers

Option B (Strong password policy) is wrong because it only protects against unauthorized login attempts; if the attacker bypasses the OS (e.g., by booting from a live USB or removing the hard drive), the data is fully accessible without decryption. Option C (Asset tracking software) is wrong because it only helps locate or recover the laptop after loss, but does not prevent data exposure if the device is stolen and the hard drive is removed or imaged. Option D (Remote wiping capability) is wrong because it relies on the laptop being powered on and connected to a network to receive the wipe command; if the thief immediately disconnects the device or removes the drive, the data remains intact and accessible.

141
MCQeasy

A company wants to ensure that employees connecting from home use a secure tunnel to access internal resources. Which protocol should be implemented?

A.SFTP
B.Telnet
C.SSH
D.SSL/TLS VPN
AnswerD

SSL/TLS VPN tunnels traffic over TCP 443, so remote employees reach internal resources through a secure encrypted session that traverses home networks and restrictive firewalls. It satisfies the requirement for a secure tunnel from home without exposing internal services directly.

Why this answer

An SSL/TLS VPN creates an encrypted tunnel over HTTPS (port 443) between the remote user's browser or client and the corporate VPN gateway, securing all traffic to internal resources. This is the standard solution for remote access VPNs because it uses ubiquitous SSL/TLS protocols, avoids the need for IPsec client software, and can traverse firewalls and NAT devices easily.

Exam trap

ISC2 often tests the distinction between SSH (a secure remote administration tool) and SSL/TLS VPN (a full remote access VPN solution), leading candidates to mistakenly choose SSH because they know it provides encryption, without realizing it does not create a comprehensive network tunnel for all internal resource access.

How to eliminate wrong answers

Option A is wrong because SFTP (SSH File Transfer Protocol) is designed only for secure file transfer, not for creating a full network tunnel to access multiple internal resources. Option B is wrong because Telnet transmits all data, including credentials, in cleartext and provides no encryption or security whatsoever. Option C is wrong because SSH creates a secure shell session or port forwarding tunnel, but it is not designed as a full VPN solution for all internal resource access; it requires manual port forwarding and does not natively support routing all client traffic through the tunnel.

142
MCQmedium

A healthcare SaaS provider runs its application stack on Docker containers orchestrated by Kubernetes in a public cloud. A security administrator must reduce the risk of a compromised container accessing the underlying node's kernel. Which control BEST addresses this requirement?

A.Deploy containers with gVisor or Kata Containers to provide a sandboxed kernel boundary.
B.Set CPU and memory resource requests and limits on each container specification.
C.Configure Kubernetes Secrets to encrypt environment variables used by the application.
D.Enable Kubernetes NetworkPolicy to restrict pod-to-pod traffic on the cluster network.
AnswerA

gVisor and Kata Containers insert an isolation layer between the container and the host kernel. gVisor intercepts system calls in user space, while Kata runs each pod in a lightweight virtual machine with its own kernel. Either approach prevents a container breakout from directly reaching the node kernel, directly satisfying the requirement to limit kernel-level exposure.

Why this answer

Sandboxed container runtimes such as gVisor and Kata Containers create a kernel boundary between the workload and the node, directly reducing the impact of a compromised container. Network policies, secret encryption, and resource quotas address networking, confidentiality, and availability respectively, but none of them prevent a container from interacting with the host kernel.

Exam trap

The trap here is assuming that any Kubernetes security feature, such as NetworkPolicy or Secrets, provides workload isolation, when only sandboxed runtimes change the kernel trust boundary.

143
MCQeasy

Which Windows feature provides mandatory integrity controls and helps prevent unauthorized changes to system settings by requiring administrator approval?

A.Windows Defender Application Control
B.Security Audit Policy
C.User Account Control (UAC)
D.Group Policy
AnswerC

User Account Control enforces mandatory integrity levels, prompting for administrator approval before privileged actions elevate a process. This prevents unauthorised changes to system settings by standard users, satisfying the requirement for mandatory integrity controls with administrator approval.

Why this answer

User Account Control (UAC) is the Windows feature that enforces mandatory integrity controls and prompts for administrator approval before allowing changes that require elevated privileges. It ensures that even administrator accounts run with standard-user rights by default and must explicitly consent to elevation, preventing unauthorized system changes.

Exam trap

SSCP often tests the confusion between UAC (elevation/integrity prompts) and WDAC or Group Policy (application control and centralized configuration) — candidates must match 'administrator approval for system changes' specifically to UAC.

How to eliminate wrong answers

Option A is wrong because Windows Defender Application Control (WDAC) restricts which applications and code can run via allow-listing — it controls execution, not privilege elevation prompts. Option B is wrong because Security Audit Policy governs logging of security-relevant events (logon, object access), not integrity enforcement or elevation approval. Option D is wrong because Group Policy is a centralized configuration-management mechanism for applying settings across users and computers; it can configure UAC but is not itself the integrity/elevation control.

144
Multi-Selectmedium

A company is migrating from 3DES to a modern encryption algorithm. Which of the following are acceptable choices? (Select TWO)

Select 2 answers
A.DES
B.ChaCha20
C.AES
D.RC4
E.Blowfish
AnswersB, C

ChaCha20 is a modern stream cipher using a 256-bit key and 96-bit nonce, avoiding 3DES's small block size and short effective key. It provides strong confidentiality, particularly in software without AES hardware acceleration, making it an acceptable replacement.

Why this answer

Option B (ChaCha20) is correct because it is a modern, secure stream cipher standardized by the IETF in RFC 8439, offering strong 256-bit security and excellent performance in software without hardware acceleration. Option C (AES) is correct because it is the current NIST-approved symmetric block cipher, available in 128-, 192-, and 256-bit key sizes, and is the standard replacement for deprecated algorithms like 3DES. Option A (DES) is not acceptable because its 56-bit key is trivially brute-forced and it has been obsolete for decades.

Option D (RC4) is not acceptable because it is a broken stream cipher with well-known biases (e.g., in WEP/TLS) and is prohibited by RFC 7465. Option E (Blowfish) is not acceptable as a modern choice because its 64-bit block size makes it vulnerable to birthday attacks (e.g., SWEET32) and it has been superseded by Twofish/AES.

Exam trap

The trap is that Blowfish sounds modern and 'strong' to candidates who recall it as a successor to DES, but its 64-bit block size disqualifies it; the exam expects you to recognize AES and ChaCha20 as the two current standard symmetric ciphers.

145
MCQhard

A security analyst is reviewing traffic logs and sees that a host is sending ICMP echo requests to multiple external IPs. This behavior is most likely indicative of:

A.Normal network monitoring
B.A DDoS attack
C.A DNS amplification attack
D.A ping sweep reconnaissance
AnswerD

ICMP echo requests sent to many external addresses in sequence indicate a ping sweep, used to discover which hosts are alive before deeper scanning. The pattern distinguishes reconnaissance from a single host simply testing connectivity.

Why this answer

ICMP echo requests (ping) sent to multiple external IPs from a single host is characteristic of a ping sweep, which is a reconnaissance technique used to map live hosts on a network. Unlike a DDoS or amplification attack, this activity originates from one host and targets many destinations to identify which IPs are responsive, aiding an attacker in planning further exploitation.

Exam trap

ISC2 often tests the distinction between reconnaissance and attack phases, so the trap here is confusing a single-source sweep (reconnaissance) with a multi-source flood (DDoS), leading candidates to incorrectly select the DDoS option.

How to eliminate wrong answers

Option A is wrong because normal network monitoring typically uses SNMP, NetFlow, or passive traffic analysis, not active ICMP echo requests to multiple external IPs, which would be noisy and unnecessary for routine monitoring. Option B is wrong because a DDoS attack involves many sources overwhelming a single target, whereas this scenario shows one host sending to many targets, which is the reverse traffic pattern. Option C is wrong because a DNS amplification attack uses spoofed source IPs with DNS queries to amplify traffic toward a victim, not ICMP echo requests from a single host to multiple IPs.

146
MCQmedium

Which wireless security protocol uses the Simultaneous Authentication of Equals (SAE) handshake to replace the Pre-Shared Key (PSK) method and provides stronger protection against offline dictionary attacks?

A.WPA2
B.WPA
C.WPA3
D.WEP
AnswerC

WPA3 replaces the pre-shared key handshake with Simultaneous Authentication of Equals, a dragonfly-based exchange that resists offline dictionary attacks. This directly satisfies the requirement for a protocol using SAE instead of PSK, unlike WPA2's four-way handshake.

Why this answer

WPA3 introduces Simultaneous Authentication of Equals (SAE), a Dragonfly-based handshake that replaces the WPA2 four-way handshake's PSK exchange. SAE provides forward secrecy and resists offline dictionary attacks because each session derives a unique key, so captured handshakes cannot be brute-forced offline.

Exam trap

SSCP often tests the difference between WPA2's 4-way handshake (vulnerable to offline dictionary attacks) and WPA3's SAE (resistant) — candidates pick WPA2 thinking it already includes SAE.

How to eliminate wrong answers

Option A is wrong because WPA2 uses the 4-way handshake with PSK (or 802.1X), which is vulnerable to offline dictionary attacks against captured handshakes (e.g., via hashcat against the PMKID or 4-way handshake). Option B is wrong because WPA (original) uses TKIP and a weaker PSK-based handshake, also vulnerable to offline attacks. Option D is wrong because WEP uses RC4 with static keys and is trivially broken — it has no SAE or modern handshake at all.

147
MCQhard

An organization is implementing 802.1X authentication for wired network access. Which server is required to authenticate users?

A.DHCP server
B.TACACS+ server
C.Kerberos server
D.RADIUS server
AnswerD

802.1X separates the supplicant, authenticator and authentication server roles; the switch forwards credentials via RADIUS to validate them against a directory. This satisfies the requirement for a dedicated authentication server, since RADIUS is the protocol and server that performs the actual credential verification.

Why this answer

802.1X is a port-based network access control protocol that uses the Extensible Authentication Protocol (EAP) to authenticate devices before granting network access. The authentication server in an 802.1X deployment must be a RADIUS server, as defined in IEEE 802.1X-2020, because it acts as the backend that validates credentials and communicates with the authenticator (switch) via RADIUS (RFC 2865).

Exam trap

The trap here is that candidates often confuse TACACS+ with RADIUS because both are AAA protocols, but 802.1X specifically mandates RADIUS for EAP transport, whereas TACACS+ encrypts the entire packet and is used for device administration, not port-based network access control.

How to eliminate wrong answers

Option A is wrong because a DHCP server dynamically assigns IP addresses and does not perform authentication; it operates after network access is granted. Option B is wrong because TACACS+ is a Cisco-proprietary protocol that separates authentication, authorization, and accounting (AAA) but is not used in 802.1X; 802.1X requires RADIUS for EAP encapsulation and port-based control. Option C is wrong because a Kerberos server provides ticket-based authentication for network services (e.g., Active Directory) but does not support the EAP-over-RADIUS exchange required by 802.1X; it is not designed for port-based access control.

148
Multi-Selectmedium

Which TWO of the following are essential components of a disaster recovery plan (DRP)?

Select 2 answers
A.Recovery Time Objective (RTO)
B.Recovery Point Objective (RPO)
C.Business Continuity Plan (BCP)
D.A RACI matrix for incident response
E.Results of a penetration test
AnswersA, B

The Recovery Time Objective defines the maximum tolerable downtime for each critical system, driving recovery priorities and resource decisions. Without it, a DRP cannot specify how quickly services must be restored, making it an essential component.

Why this answer

The Recovery Time Objective (RTO) is a correct answer because it defines the maximum acceptable downtime after a disruption, specifying how quickly systems and services must be restored, which is a core metric every DRP must establish to guide recovery priorities. The Recovery Point Objective (RPO) is also correct because it defines the maximum tolerable amount of data loss measured in time, determining the required backup frequency and replication strategy within the DRP. Together, RTO and RPO are essential, quantifiable components that shape the recovery strategies, resource allocation, and backup/replication design of a disaster recovery plan.

The Business Continuity Plan (BCP) is not a component of a DRP but rather a broader, higher-level plan that encompasses and coordinates the DRP alongside other continuity activities. A RACI matrix for incident response belongs to incident management and role assignment, not to the essential recovery objectives of a DRP, and penetration test results are security assessment artifacts that may inform risk analysis but are not essential DRP components.

Exam trap

SSCP often tests the confusion between DRP components and broader BCP elements, and candidates may incorrectly select BCP as a component of DRP rather than recognizing RTO and RPO as the core metrics.

149
MCQeasy

Which of the following is a connectionless transport layer protocol primarily used for services like DNS and DHCP?

A.UDP
B.IP
C.TCP
D.ICMP
AnswerA

UDP operates without establishing a session, sending datagrams independently with no handshake, acknowledgement, or retransmission. This connectionless design satisfies the stem's requirement, and its low overhead suits DNS and DHCP, which favour speed over guaranteed delivery. TCP, by contrast, is connection-oriented and would add unnecessary latency.

Why this answer

UDP (User Datagram Protocol) is a connectionless transport layer protocol that does not establish a session before sending data. It is used for services like DNS and DHCP because they require fast, lightweight communication without the overhead of TCP's three-way handshake. UDP operates at Layer 4 of the OSI model.

Exam trap

SSCP often tests the distinction between transport layer protocols (TCP/UDP) and network layer protocols (IP/ICMP), and candidates may incorrectly select IP or ICMP as transport layer protocols.

How to eliminate wrong answers

Option B is wrong because IP (Internet Protocol) is a network layer protocol, not a transport layer protocol, and it is connectionless but not used for transport-layer services like DNS and DHCP directly. Option C is wrong because TCP (Transmission Control Protocol) is connection-oriented and establishes a session, which adds overhead not suitable for DNS and DHCP. Option D is wrong because ICMP (Internet Control Message Protocol) is a network layer protocol used for diagnostic and error messages, not for transport-layer services.

150
MCQmedium

In a Kerberos environment, what is the primary function of the Ticket Granting Ticket (TGT)?

A.To store the user's password hash securely
B.To request service tickets from the Ticket Granting Service (TGS)
C.To provide a session key for encrypting communications
D.To authenticate the user to the Key Distribution Center (KDC)
AnswerB

After initial authentication, the client presents its TGT to the Ticket Granting Service. The TGS validates that ticket and issues service tickets for specific resources, so the TGT acts as the credential enabling service ticket requests without re-entering credentials.

Why this answer

The TGT is obtained after initial authentication and is used to request service tickets for various resources without re-authenticating.

Page 1

Page 2 of 13

Page 3