Courseiva

Systems Security Certified Practitioner SSCP (SSCP) — Questions 151–225

971 questions total · 13pages · All types, answers revealed

Page 2

Page 3 of 13

Page 4
151
MCQmedium

A government contractor is required to comply with the Federal Information Security Management Act (FISMA). The security officer must implement a continuous monitoring program for all information systems. The contractor uses a mix of on-premises servers and cloud services. The contractor has a SIEM tool that collects logs from all systems. However, the SIEM generates a high number of alerts, many of which are false positives, overwhelming the security team. The team wants to improve the effectiveness of the monitoring program without increasing staff. Which of the following actions would MOST effectively address the issue?

A.Disable alerts for low-severity events
B.Hire additional security analysts to review all alerts
C.Increase the frequency of log collection to every minute
D.Tune the SIEM correlation rules and create custom filters to reduce false positive alerts
AnswerD

Tuning correlation rules and building custom filters directly targets the false-positive volume that overwhelms the team, satisfying the constraint of improving monitoring effectiveness without adding staff. By refining detection logic against the contractor's actual baseline across on-premises and cloud sources, genuine FISMA-relevant events surface, restoring continuous monitoring capability.

Why this answer

Tuning SIEM correlation rules and creating custom filters directly addresses the root cause of false positives by refining detection logic to match the contractor's specific environment and threat profile. This reduces alert noise without discarding potentially valuable low-severity data or requiring additional staff. It aligns with FISMA continuous monitoring requirements by improving the signal-to-noise ratio, enabling the existing team to focus on genuine threats.

This is the most effective and sustainable solution because it enhances the tool's accuracy rather than just suppressing or adding resources.

Exam trap

SSCP often tests the misconception that simply suppressing alerts or adding staff solves alert fatigue, when the most effective solution is to refine the detection logic itself.

How to eliminate wrong answers

Option A is wrong because disabling all low-severity alerts can cause the team to miss early indicators of compromise or correlated events that, in aggregate, signify a real attack, and it does not address the underlying issue of false positives among higher-severity alerts. Option B is wrong because hiring additional analysts increases costs and does not improve the monitoring program's effectiveness; it merely adds manpower to handle the same volume of false positives, which is unsustainable and contrary to the goal of not increasing staff. Option C is wrong because increasing log collection frequency to every minute would generate even more data and likely more alerts, exacerbating the false positive problem and overwhelming the team further, without improving detection accuracy.

152
Multi-Selecthard

A risk analyst is building a risk register for a cloud-hosted customer portal and must classify threats by their source. Which TWO of the following are examples of environmental threat sources that should be documented? (Choose two.)

Select 2 answers
A.A flood that inundates the facility housing the primary database cluster
B.A misconfigured firewall rule that exposes the portal's management interface
C.A disgruntled employee with administrative access to the portal's backend
D.A software vulnerability in the portal's third-party authentication library
E.A regional power grid failure that takes the primary data center offline
AnswersA, E

Natural disasters such as floods are environmental threats. They arise from geographic and climatic conditions rather than from people or technology failures. Including this in the risk register supports decisions about site selection, flood barriers, and geographic redundancy. It clearly belongs in the environmental category and is distinct from human or technical threat sources.

Why this answer

Environmental threat sources stem from natural events and supporting infrastructure, such as power failures and floods, that can disrupt operations regardless of human intent. Human threats like insiders and technical threats like misconfigured firewalls or vulnerable libraries are categorized separately. Correctly separating these categories sharpens the risk register and points to the right controls, from backup power to geographic redundancy.

Exam trap

The trap here is lumping all disruptive events together and missing that environmental threats specifically exclude human and technical origins.

153
MCQeasy

A security policy requires that all access to sensitive data be logged. Which access control function does this support?

A.Authentication
B.Authorization
C.Accounting
D.Provisioning
AnswerC

Accounting records and logs user activity, including access to sensitive data, so it directly satisfies the policy requiring all such access to be logged. Authentication verifies identity and authorisation grants rights; only accounting provides the audit trail.

Why this answer

The requirement to log all access to sensitive data directly supports the Accounting (auditing) function of access controls. Accounting tracks user activities and resource usage, providing an audit trail that can be reviewed for compliance, security incidents, and policy enforcement. This is distinct from Authentication (verifying identity) and Authorization (granting permissions), which do not inherently produce logs of access events.

Exam trap

The trap here is that candidates confuse Authorization (which controls access) with Accounting (which records access), mistakenly thinking that setting permissions automatically logs access, when in fact logging requires a separate audit configuration.

How to eliminate wrong answers

Option A is wrong because Authentication is the process of verifying a user's identity (e.g., via passwords, biometrics, or certificates) and does not inherently generate logs of access to sensitive data; logging is an Accounting function. Option B is wrong because Authorization determines what an authenticated user is allowed to do (e.g., via ACLs or RBAC) but does not itself record access events; that recording is the role of Accounting. Option D is wrong because Provisioning refers to the creation, modification, or removal of user accounts and access rights (e.g., via identity management systems) and does not include logging of access to data.

154
MCQmedium

A company uses virtualization extensively. The security team discovers that developers have created many unmanaged virtual machines that are not tracked in the configuration management database (CMDB). Which risk is MOST directly associated with this situation?

A.VM escape
B.VM sprawl
C.Snapshot vulnerability reintroduction
D.Insecure hypervisor configuration
AnswerB

Unmanaged VMs consume hypervisor CPU, memory, storage and licensing without lifecycle oversight, which is the defining characteristic of VM sprawl. Because these instances bypass the CMDB, they escape patching and vulnerability tracking, so sprawl is the risk most directly created by the missing inventory records.

Why this answer

VM sprawl refers to the proliferation of unmanaged VMs, increasing attack surface and management complexity.

155
Multi-Selectmedium

Which TWO of the following cryptographic algorithms are considered secure for modern use?

Select 2 answers
A.MD5 (Message Digest 5)
B.ChaCha20
C.AES-256 (Advanced Encryption Standard with 256-bit key)
D.RC4 (Rivest Cipher 4)
E.DES (Data Encryption Standard)
AnswersB, C

ChaCha20 is a modern stream cipher combining a 256-bit key with a 96-bit nonce, offering strong resistance to cryptanalysis and efficient software performance. Its design satisfies the stem's security requirement without the timing weaknesses of table-based ciphers.

Why this answer

ChaCha20 (B) is a modern stream cipher designed by Daniel J. Bernstein that remains secure and is widely deployed in TLS 1.3, WireGuard, and OpenSSH, offering strong resistance to cryptanalysis with no practical attacks against its full 20-round design. AES-256 (C) is a symmetric block cipher standardized by NIST that, with its 256-bit key, provides a very high security margin and is approved for protecting classified information up to Top Secret.

In contrast, MD5 (A) is a hash function broken by practical collision attacks since 2004 and is unsuitable for security purposes. RC4 (D) is a stream cipher with well-known biases in its keystream (e.g., the RC4 biases exploited in WEP and TLS attacks) and has been prohibited in TLS by RFC 7465. DES (E) uses only a 56-bit effective key and is trivially brute-forced with modern hardware, so it is obsolete.

Exam trap

SSCP often tests whether candidates recognize deprecated algorithms (MD5, RC4, DES) versus modern ones — the trap is assuming any 'encryption' algorithm is automatically secure.

156
MCQmedium

An administrator configures a Kerberos authentication system. After implementation, users are able to authenticate but cannot access network resources. The administrator verifies that the client time is synchronized with the KDC. What is the most likely cause?

A.The service principal name (SPN) is not registered
B.The user’s password is expired
C.The firewall blocks port 88
D.The TGT lifetime has expired
AnswerA

Kerberos authentication succeeds because the ticket-granting service works, but resource access fails when the target service's SPN is absent from the directory, so the KDC cannot issue a service ticket for that resource. Time synchronisation is already verified, ruling out clock skew.

Why this answer

The most likely cause is that the service principal name (SPN) is not registered. In Kerberos, the SPN uniquely identifies a network service instance and is required for the KDC to issue a service ticket. Even though users can authenticate (obtain a TGT), without a properly registered SPN, the KDC cannot grant a ticket for the target service, preventing access to network resources.

Exam trap

ISC2 often tests the distinction between authentication (TGT acquisition) and authorization (service ticket issuance), leading candidates to incorrectly focus on firewall rules or password expiration instead of the missing SPN.

How to eliminate wrong answers

Option B is wrong because an expired user password would prevent initial authentication (TGT acquisition), but the scenario states users can authenticate. Option C is wrong because port 88 is used for Kerberos authentication traffic; if it were blocked, users would not be able to authenticate at all. Option D is wrong because an expired TGT lifetime would prevent access only after the TGT expires, but users are currently able to authenticate and the issue is immediate access to network resources.

157
MCQeasy

A healthcare organization stores protected health information on a database server. Auditors require that the data remain unreadable if the physical disk is stolen, and that encryption keys never reside on the same disk as the ciphertext. Which approach BEST satisfies these requirements?

A.Use file-level encryption on individual tablespaces with passwords stored in a local script.
B.Apply column-level encryption using a symmetric key embedded in the application configuration file.
C.Implement database transparent data encryption with keys managed by the database instance on the same volume.
D.Enable full disk encryption using a key stored in a hardware security module or external key manager.
AnswerD

Full disk encryption protects data at rest if the drive is removed, and storing the key in an HSM or external key manager ensures the key is not on the same disk as the ciphertext. This satisfies both auditor conditions: confidentiality of stolen media and separation of key material from encrypted data. It is the standard approach for data-at-rest protection on servers.

Why this answer

The auditors require protection of data at rest plus separation of keys from ciphertext. Full disk encryption with keys held in an HSM or external key manager meets both conditions by ensuring a stolen disk yields only ciphertext and the key remains in a controlled, separate system. The other approaches either leave key material on the same disk or fail to provide equivalent protection.

Exam trap

The trap here is treating any form of encryption as sufficient, when the scenario specifically requires that key material not reside on the same disk as the encrypted data.

158
MCQmedium

A security administrator is configuring a VPN between two branch offices. The requirement is to encrypt the entire original IP packet and add a new IP header for routing over the internet. Which IPsec mode should be used?

A.Aggressive mode
B.Transport mode
C.Main mode
D.Tunnel mode
AnswerD

Tunnel mode encapsulates the entire original IP packet, including its header, then prepends a new IP header for routing across the internet. Transport mode encrypts only the payload, so tunnel mode satisfies the stated requirement.

Why this answer

Tunnel mode encapsulates the entire original IP packet — including its original header — inside a new IP packet with a new header, which is exactly what is required for site-to-site VPNs between branch offices. The new header carries the tunnel endpoint addresses so the encrypted payload can be routed across the public internet, and the original packet is restored on decapsulation.

Exam trap

SSCP often tests the confusion between IKE Phase 1 modes (main/aggressive) and IPsec encapsulation modes (transport/tunnel) — candidates pick aggressive or main mode thinking they describe packet wrapping.

How to eliminate wrong answers

Option A is wrong because aggressive mode is an IKE Phase 1 negotiation mode (fewer messages, no identity protection), not an IPsec encapsulation mode — it does not describe how packets are wrapped. Option B is wrong because transport mode encrypts only the payload and leaves the original IP header intact, which is used for host-to-host traffic, not for routing between two private networks over the internet. Option C is wrong because main mode is also an IKE Phase 1 exchange mode providing identity protection, not a packet encapsulation mode.

159
MCQhard

A healthcare provider's incident response team is handling a suspected ransomware incident on a clinical workstation. The team lead wants to determine whether the incident should be escalated to a full response or handled as a false positive. According to NIST SP 800-61, which activity is part of the detection and analysis phase?

A.Validating the incident by correlating alerts with known indicators and impact.
B.Implementing a network access control list to block the ransomware's command-and-control domain.
C.Conducting a lessons learned meeting with clinical staff.
D.Eradicating the malware by reimaging the workstation.
AnswerA

Validation is a core detection and analysis activity: responders correlate alerts, indicators, and impact to confirm whether an event is a real incident. This step prevents wasted resources on false positives and determines the appropriate response. In the ransomware scenario, validating the alert against known ransomware indicators and assessing clinical impact directly supports the decision to escalate or dismiss.

Why this answer

Detection and analysis in NIST SP 800-61 involves validating alerts, correlating indicators, scoping the incident, and determining impact. Validation is the critical step that separates real incidents from false positives and informs escalation decisions. Eradication, containment, and post-incident review occur in later phases, so they are not part of detection and analysis.

Exam trap

The trap here is confusing containment or eradication actions with detection and analysis, because responders often want to act immediately rather than first validating whether the incident is real.

160
MCQhard

An organization is planning to implement ECC for digital signatures. Which key size provides a security level equivalent to a 3072-bit RSA key?

A.192-bit ECC
B.256-bit ECC
C.1024-bit ECC
D.384-bit ECC
AnswerB

ECC delivers roughly half the key length of RSA for equivalent strength: a 256-bit ECC key matches 3072-bit RSA. This satisfies the stem's requirement for a 3072-bit RSA security equivalence, giving the same protection with far smaller keys and faster computation.

Why this answer

The National Institute of Standards and Technology (NIST) recommends that a 256-bit elliptic curve (e.g., P-256) provides a security strength of 128 bits, which is equivalent to a 3072-bit RSA key. This equivalence is based on the computational difficulty of the discrete logarithm problem in elliptic curve groups versus integer factorization, where ECC requires significantly smaller key sizes for the same security level.

Exam trap

The trap here is that candidates often confuse symmetric key equivalence (e.g., 256-bit ECC matches 128-bit symmetric) with RSA equivalence, or mistakenly think larger ECC keys (like 384-bit) are needed to match 3072-bit RSA, when in fact 256-bit ECC is the correct match per NIST guidelines.

How to eliminate wrong answers

Option A is wrong because a 192-bit ECC key provides only 96 bits of security strength, which is equivalent to a 2048-bit RSA key, not 3072-bit. Option C is wrong because 1024-bit ECC is not a standard key size; ECC key sizes are typically much smaller (e.g., 256-bit) and a 1024-bit ECC key would provide far more security than needed, but the question asks for the equivalent to 3072-bit RSA, which is 256-bit ECC. Option D is wrong because a 384-bit ECC key provides 192 bits of security strength, equivalent to a 7680-bit RSA key, which is stronger than required for 3072-bit RSA.

161
MCQhard

You are a security consultant for a hospital that is deploying a new IoT medical device system. The devices wirelessly transmit patient vital signs to a central server. The hospital is subject to HIPAA. The devices were developed by a startup and are not widely field-tested. The IT department wants to connect the devices to the existing network for real-time monitoring. The risk management team has identified potential threats including data interception, device tampering, and denial of service. They have no prior experience with IoT security. Which of the following risk treatment strategies is MOST appropriate given the high uncertainty?

A.Accept the risk because the devices improve patient care
B.Transfer the risk by purchasing cyber insurance
C.Avoid the risk by delaying deployment until a thorough risk assessment and independent security testing are completed
D.Mitigate the risk by segmenting the devices on a separate VLAN and encrypting all communications
AnswerC

Avoidance eliminates the risk by not undertaking the activity. Given untested devices, HIPAA exposure and no IoT experience, delaying deployment until independent testing and assessment complete removes the threat rather than transferring or accepting it under high uncertainty.

Why this answer

The high uncertainty surrounding the startup's untested IoT devices, combined with the criticality of patient safety and HIPAA compliance, makes avoidance the most prudent strategy. Delaying deployment allows for a thorough risk assessment and independent security testing to identify vulnerabilities before exposing the hospital network to potential data interception, device tampering, or denial-of-service attacks. This approach directly addresses the risk management team's lack of IoT security experience by preventing exposure until the threat landscape is better understood.

Exam trap

The trap here is that candidates often choose mitigation (Option D) because it seems proactive and technically sound, but they overlook the principle that mitigation is only appropriate when the risk is well-understood and the controls are proven effective—neither of which applies to untested IoT devices with unknown vulnerabilities.

How to eliminate wrong answers

Option A is wrong because accepting risk without understanding the specific vulnerabilities of untested IoT devices could lead to HIPAA violations and patient harm, as the devices transmit protected health information (PHI) over wireless links susceptible to interception. Option B is wrong because cyber insurance transfers financial risk but does not reduce the likelihood or impact of a security incident; it also does not address the immediate technical threats like device tampering or denial of service that could disrupt patient monitoring. Option D is wrong because while VLAN segmentation and encryption (e.g., using TLS 1.3 or IPsec) are valid mitigation techniques, they are insufficient when the devices themselves may have undisclosed backdoors, weak cryptographic implementations, or unpatched firmware flaws that could be exploited despite network controls.

162
Multi-Selecteasy

Which TWO of the following are considered key components of a disaster recovery plan?

Select 2 answers
A.SLA (Service Level Agreement)
B.RPO (Recovery Point Objective)
C.RTO (Recovery Time Objective)
D.BCP (Business Continuity Plan)
E.MTBF (Mean Time Between Failures)
AnswersB, C

RPO defines the maximum tolerable data loss measured in time, determining how frequently backups or replication must occur. It is a core DR component because it sets the recovery point target, directly driving backup frequency and replication design within the documented plan.

Why this answer

RPO and RTO are fundamental metrics in a disaster recovery plan. RPO defines the maximum acceptable data loss measured in time, dictating the frequency of backups. RTO defines the maximum acceptable downtime after a disaster, setting the target for system restoration.

Both directly drive the technical design of replication, backup schedules, and failover procedures.

Exam trap

ISC2 often tests the distinction between DR plan components (RPO/RTO) and broader business continuity concepts (BCP) or contractual metrics (SLA), leading candidates to confuse SLA with RTO or think BCP is part of the DR plan itself.

163
MCQhard

An analyst detects outbound traffic from a workstation to a known malicious IP address. The workstation is a developer machine with local admin rights. Which containment action should be taken first?

A.Block the malicious IP on the firewall
B.Isolate the workstation from the network
C.Shut down the workstation immediately
D.Disable the user's domain account
AnswerB

Isolation immediately severs the command-and-control channel, halting data exfiltration and preventing lateral movement while the compromised developer machine retains its state for forensic examination. Because local admin rights could enable rapid credential theft or malware propagation, network isolation satisfies the stem's requirement for the fastest, least destructive containment action.

Why this answer

Isolating the workstation from the network is the correct first containment step because it stops any further command-and-control communication, lateral movement, or data exfiltration while preserving volatile memory and forensic artifacts for investigation. A developer machine with local admin rights is especially dangerous — the attacker could pivot, install persistence, or harvest credentials — so cutting network connectivity immediately limits blast radius without destroying evidence.

Exam trap

SSCP often tests the order of containment actions, and candidates frequently pick 'shut down the machine' or 'block the IP' because they sound decisive — but the exam expects isolation first to preserve evidence and stop lateral movement.

How to eliminate wrong answers

Option A is wrong because blocking a single malicious IP on the firewall is too narrow — the attacker may use multiple C2 endpoints, domain generation algorithms, or fallback channels, and the workstation itself remains compromised and capable of lateral movement. Option C is wrong because shutting down the workstation destroys volatile evidence (RAM, running processes, network connections) and may trigger anti-forensic behavior or lose the ability to identify the malware; isolation is preferred over power-off. Option D is wrong because disabling the user's domain account addresses only one credential vector and does not stop the already-running malware on the workstation from continuing its activity or moving laterally with cached credentials.

164
Multi-Selectmedium

Which TWO factors are most critical when selecting a cryptographic algorithm for a government application?

Select 2 answers
A.Speed of encryption/decryption
B.Key length
C.Algorithm popularity
D.Regulatory compliance (e.g., FIPS 140-2)
E.Ease of implementation
AnswersB, D

Key length determines the brute-force resistance of the algorithm; longer keys increase the work factor for attackers. For government use, sufficient key length is critical to withstand sustained cryptanalysis, though it must be paired with an approved algorithm and mode.

Why this answer

For a government application, regulatory compliance (D) is critical because government systems must use algorithms and modules validated under standards such as FIPS 140-2 (or its successor FIPS 140-3), and non-compliant cryptography cannot legally be deployed in many federal environments. Key length (B) is equally critical because it directly determines the cryptographic strength and resistance to brute-force or cryptanalytic attacks, and government standards mandate minimum key sizes (e.g., AES-128/192/256, RSA or Diffie-Hellman of at least 2048 bits, ECC of at least 224 bits). Speed of encryption/decryption (A) is a performance consideration, not a primary selection factor for government cryptographic approval.

Algorithm popularity (C) is irrelevant to security assurance and can even be misleading, as popularity does not imply validation. Ease of implementation (E) affects development effort but does not determine whether an algorithm meets government security and compliance requirements.

Exam trap

ISC2 often tests the misconception that speed or popularity are primary selection criteria, when in fact government applications are driven by regulatory mandates and cryptographic strength (key length) as defined by standards like FIPS.

165
Multi-Selecteasy

A security engineer is designing a DMZ to host public-facing services. Which two security best practices should be applied? (Choose two.)

Select 2 answers
A.Use the same firewall rule set for DMZ and internal network
B.Place web servers on the internal network
C.Enable full mesh connectivity between DMZ hosts
D.Use a screened subnet with two firewalls
E.Allow inbound traffic from internet to DMZ on required ports only
AnswersD, E

A screened subnet with two firewalls creates distinct outer and inner perimeters, so a compromised public-facing host must breach a second firewall before reaching the internal network. This satisfies the DMZ requirement for defence in depth, unlike a single-firewall design where one policy failure exposes internal systems directly.

Why this answer

Option D is correct because a screened subnet architecture with two firewalls (an external firewall facing the internet and an internal firewall facing the trusted network) creates defense in depth, so if a DMZ host is compromised the attacker still must breach a second firewall to reach internal systems. Option E is correct because DMZ hosts should be reachable only on the specific ports their public services require (for example TCP 443 for HTTPS), enforcing least privilege and minimizing the attack surface exposed to the internet. Option A is wrong because applying the same rule set to the DMZ and internal network defeats segmentation and would let DMZ compromises pivot freely into the internal LAN.

Option B is wrong because placing public-facing web servers on the internal network exposes trusted systems directly to internet-facing risk instead of isolating them in the DMZ. Option C is wrong because full mesh connectivity between DMZ hosts enables lateral movement after a single host is compromised, whereas DMZ hosts should be isolated from one another unless a specific service dependency requires otherwise.

Exam trap

SSCP often tests the misconception that a single firewall with a DMZ interface is equivalent to a screened subnet with two firewalls; candidates who pick 'same rule set' or 'full mesh' fail to recognize the defense-in-depth principle.

166
MCQeasy

A small business needs basic protection against malware. Which solution is MOST cost-effective and provides real-time protection?

A.Schedule weekly antivirus scans
B.Deploy an endpoint protection platform (EPP)
C.Install a host-based firewall on each computer
D.Use email encryption for all communications
AnswerB

An endpoint protection platform delivers real-time malware detection and blocking on each host, giving the small business essential protection at predictable per-device cost. This satisfies the stem's combined requirements for basic malware defence, real-time capability and cost-effectiveness.

Why this answer

An Endpoint Protection Platform (EPP) provides real-time, continuous protection against malware on endpoints through signature-based detection, behavioral analysis, and often centralized management. For a small business needing basic but real-time malware defense, EPP is the most cost-effective solution because it replaces manual scanning with always-on protection and typically includes a management console for the whole fleet.

Exam trap

SSCP often tests the confusion between preventive network controls (firewalls, encryption) and real-time malware detection (EPP), causing candidates to pick a firewall or encryption when the question asks specifically about malware protection.

How to eliminate wrong answers

Option A is wrong because scheduled weekly scans are periodic, not real-time — malware can execute and spread for up to seven days before detection, and scans consume resources. Option C is wrong because a host-based firewall controls network traffic (ports, IPs) but does not detect or remove malware executing on the host; it is a network control, not an anti-malware control. Option D is wrong because email encryption protects confidentiality of messages in transit and at rest, but it does nothing to detect or block malware delivered via other vectors like USB drives, downloads, or drive-by web attacks.

167
Multi-Selectmedium

A security administrator is configuring a network access control deployment that must authenticate employee laptops before they receive an IP address on the corporate VLAN. The administrator wants to use the IEEE 802.1X framework. Which two components are required for this framework to function? (Choose two.)

Select 2 answers
A.A certificate revocation list published by the endpoint vendor
B.A domain name system server that resolves the switch management address
C.A mandatory captive portal that collects user consent before authentication
D.An authenticator that controls the port until authentication succeeds
E.An authentication server that validates the supplied credentials
AnswersD, E

The authenticator is the network device, such as a switch or wireless access point, that blocks or permits traffic on the controlled port based on the outcome of authentication. Without it, there is no enforcement point to hold the laptop in an unauthenticated state before an IP address is assigned. It relays credentials between the supplicant and the authentication server, making it an essential element of the framework.

Why this answer

The framework defines three roles, and the question asks for the two that the administrator must supply beyond the endpoint itself: the authenticator, which enforces port state on the switch or access point, and the authentication server, which validates credentials and returns authorization attributes. Together they hold the laptop in a pre-authentication state until the decision is rendered, which is what prevents an unauthenticated device from obtaining a corporate address.

Exam trap

The trap here is treating optional supporting infrastructure, such as revocation lists or captive portals, as core framework roles.

168
Multi-Selectmedium

Which TWO of the following are best practices for securing an application programming interface (API)?

Select 2 answers
A.Implement rate limiting to control the number of requests.
B.Validate and sanitize all input to the API.
C.Return detailed error messages to help clients debug.
D.Disable encryption to improve performance.
E.Use HTTP Basic Authentication without HTTPS.
AnswersA, B

Rate limiting caps how many requests a client may make in a given period, throttling automated abuse such as credential stuffing, enumeration, and denial-of-service attempts against the API. It satisfies the requirement to constrain request volume, protecting availability and slowing attackers' ability to iterate through payloads.

Why this answer

Option A is correct because implementing rate limiting controls the number of requests a client can make within a given time window, which mitigates abuse such as brute-force attacks, credential stuffing, and denial-of-service attempts against the API. Option B is correct because validating and sanitizing all input to the API defends against injection attacks (such as SQL injection and cross-site scripting) and ensures that malformed or malicious data cannot reach backend logic or data stores. Option C is not a best practice because detailed error messages can leak stack traces, internal paths, database schema details, or version information that aid attackers; generic error responses with server-side logging are preferred.

Option D is incorrect because disabling encryption exposes API traffic to eavesdropping and tampering, and performance should be addressed through other means such as TLS optimization rather than removing transport security. Option E is incorrect because HTTP Basic Authentication transmits credentials in Base64 (effectively cleartext) and is only safe when combined with HTTPS, so using it without HTTPS exposes credentials to interception.

Exam trap

SSCP often tests the misconception that detailed error messages aid security — candidates may pick them as helpful, but they actually leak information; similarly, candidates may overlook that Basic Auth without HTTPS is insecure.

169
MCQmedium

A system administrator is configuring a Linux server to ensure that only authorized users can execute commands with superuser privileges. Which file should be edited to control sudo access?

A./etc/shadow
B./etc/passwd
C./etc/group
D./etc/sudoers
AnswerD

/etc/sudoers defines which users and groups may run commands as root via sudo, using User_Spec and Cmnd_Spec entries. Editing it satisfies the stem's requirement to restrict superuser command execution to authorised users, unlike /etc/passwd or /etc/shadow.

Why this answer

The /etc/sudoers file is the central configuration file that defines which users and groups may run which commands with elevated privileges via sudo. It uses a specific syntax (user/group, host, runas, command) and is edited with visudo to prevent syntax errors that could lock out sudo access. Editing this file is the standard way to control sudo authorization on Linux.

Exam trap

The trap here is confusing authentication files (/etc/passwd, /etc/shadow) with authorization files (/etc/sudoers) — SSCP often tests whether candidates know that sudo rights are defined in sudoers, not in the password or group databases.

How to eliminate wrong answers

Option A is wrong because /etc/shadow stores hashed user passwords and aging information, not sudo authorization rules. Option B is wrong because /etc/passwd contains basic user account attributes (UID, GID, home, shell) but no sudo privilege definitions. Option C is wrong because /etc/group defines group membership, which can be referenced in sudoers but does not itself grant or control sudo access.

170
MCQhard

A company uses a Cloud Workload Protection Platform (CWPP) to secure IaaS workloads. They discover that a virtual machine (VM) is communicating with a known command-and-control server. What is the FIRST action the security team should take?

A.Immediately isolate the VM by removing it from the network
B.Run an antivirus scan on the VM to remove the malware
C.Terminate the VM and create a new one from a clean image
D.Analyze the traffic logs to determine the scope of the compromise
AnswerA

Network isolation severs the command-and-control channel immediately, halting data exfiltration and preventing lateral movement while evidence is preserved. Containment is the first incident response step for a confirmed compromised IaaS workload, satisfying the stem's demand for the initial action.

Why this answer

The FIRST action when a VM is confirmed to be communicating with a known command-and-control (C2) server is to isolate it from the network to prevent further data exfiltration, lateral movement, or remote control by the attacker. Isolation via network removal or quarantine stops the active threat immediately while preserving the VM's state for later forensic analysis. This aligns with incident response best practices of containment before eradication.

Exam trap

SSCP often tests the order of incident response steps — candidates may choose 'analyze logs' or 'run antivirus' first, but containment (isolation) must precede eradication and analysis to stop active harm.

How to eliminate wrong answers

Option B is wrong because running an antivirus scan does not stop ongoing C2 communication and may allow the attacker to continue exfiltrating data or move laterally during the scan. Option C is wrong because terminating the VM destroys volatile evidence (memory, running processes) needed for forensic investigation and does not address the immediate threat if the attacker has other footholds. Option D is wrong because analyzing traffic logs, while important, is a detection and scoping activity that should occur after containment — delaying isolation to analyze logs gives the attacker more time to cause damage.

171
MCQeasy

A company is deploying a new mobile application that handles sensitive customer data. Which practice BEST ensures data confidentiality on the device?

A.Require a strong screen lock passcode.
B.Disable cloud backups for the app.
C.Encrypt all sensitive data stored on the device using a key derived from the user's passcode.
D.Use app sandboxing to isolate app data from other apps.
AnswerC

Deriving the encryption key from the user's passcode means data at rest is unreadable without that secret, so a lost or stolen device exposes nothing. This directly satisfies the confidentiality requirement for sensitive customer data stored on the device.

Why this answer

Encrypting sensitive data with a key derived from the user's passcode ensures that even if the device is lost or stolen, the data remains unreadable without the passcode. This approach leverages the user's secret to protect confidentiality at rest, which is a fundamental principle of mobile data protection. Technologies like iOS Data Protection and Android File-Based Encryption use similar key derivation from the lock screen credential to encrypt app-specific data.

Exam trap

ISC2 often tests the distinction between access control (screen lock) and data protection (encryption), leading candidates to choose a strong passcode as the best practice for confidentiality, when encryption with a derived key is the actual requirement.

How to eliminate wrong answers

Option A is wrong because a strong screen lock passcode only prevents unauthorized access to the device interface but does not protect data if the device is compromised via other means (e.g., forensic extraction or jailbreak). Option B is wrong because disabling cloud backups prevents data from being stored off-device but does not address confidentiality of data already on the device; backups themselves can be encrypted separately. Option D is wrong because app sandboxing isolates app data from other apps to prevent unauthorized inter-app access, but it does not protect against physical device access or OS-level attacks that bypass sandboxing.

172
MCQmedium

A system administrator is hardening a Linux server. After installing the OS, which of the following steps should be taken to ensure that only authorized users can execute commands with elevated privileges?

A.Edit the /etc/sudoers file to restrict sudo access
B.Enable auditd to log all commands
C.Configure PAM to enforce password complexity
D.Set the setuid bit on critical binaries
AnswerA

Editing /etc/sudoers defines exactly which users or groups may run which commands via sudo, satisfying the requirement that only authorised accounts gain elevated execution. This replaces blanket root access with granular, auditable privilege delegation, so unauthorised users cannot escalate.

Why this answer

The /etc/sudoers file defines which users and groups may run which commands with elevated privileges via sudo. Restricting sudo access by editing this file (preferably with visudo) ensures that only authorized users can execute commands as root or another privileged account. This directly satisfies the requirement to control who can execute commands with elevated privileges.

Exam trap

The trap is confusing logging or authentication controls with authorization — candidates may pick auditd or PAM because they sound security-related, but only sudoers governs who may execute commands with elevated privileges.

How to eliminate wrong answers

Option B is wrong because auditd logs command execution for auditing and forensic purposes — it records what happened but does not restrict or authorize who can run privileged commands. Option C is wrong because PAM password complexity controls authentication strength (password length, character classes) but does not govern authorization to execute commands with elevated privileges. Option D is wrong because setting the setuid bit on binaries allows any user executing that binary to run it with the file owner's privileges — this actually broadens the attack surface and is a hardening anti-pattern, not a control for restricting elevated command execution.

173
MCQmedium

A Linux server is being hardened. The security team wants to enforce mandatory access control policies that confine processes to limited access to files and resources. Which technology should be implemented?

A.SELinux
B.PAM
C.iptables
D.auditd
AnswerA

SELinux enforces mandatory access control through type enforcement, confining each process to only the files and resources its policy permits, regardless of user identity. Standard discretionary permissions cannot constrain a compromised daemon this way, which is the hardening requirement.

Why this answer

SELinux (Security-Enhanced Linux) implements mandatory access control (MAC) by labeling processes and files with security contexts and enforcing policy rules that confine processes to only the resources they are permitted to access. This is exactly what the security team needs to enforce MAC and limit process access to files and resources.

Exam trap

The trap is conflating authentication (PAM), network filtering (iptables), and auditing (auditd) with mandatory access control — only SELinux (or AppArmor) enforces MAC at the process/resource level.

How to eliminate wrong answers

Option B is wrong because PAM (Pluggable Authentication Modules) handles authentication, account, session, and password management — it does not enforce mandatory access control over process-to-file interactions. Option C is wrong because iptables is a packet-filtering firewall that controls network traffic based on IP addresses, ports, and protocols — it operates at the network layer and does not confine processes' access to local files and resources. Option D is wrong because auditd is the Linux auditing daemon that records security-relevant events for compliance and forensics — it observes and logs but does not enforce access control policies.

174
MCQhard

A change request to update a critical database server has been approved by the Change Advisory Board (CAB). During testing, a major compatibility issue is discovered. What is the best course of action?

A.Report the issue to the CAB and request a revised change
B.Reject the change request and close it permanently
C.Implement the change but have a rollback plan ready
D.Proceed with the change and resolve the issue after implementation
AnswerA

The CAB owns change approval, so a discovered compatibility issue invalidates the approved change and must be escalated for reassessment. Proceeding without reapproval bypasses change control; reporting back and requesting a revised change preserves governance and satisfies the stem's testing constraint.

Why this answer

Reporting the issue to the CAB and requesting a revised change is the best course because the change management process requires that any significant deviation from the approved change, such as a major compatibility issue, be re-evaluated by the CAB. This ensures proper risk assessment and approval before proceeding. It maintains the integrity of the change control process and prevents unintended outages.

Exam trap

SSCP often tests the misconception that an approved change can proceed despite new critical findings, when in fact any significant issue requires re-evaluation by the CAB.

How to eliminate wrong answers

Option B is wrong because rejecting and closing the change permanently ignores the possibility of revising and resubmitting a modified change that addresses the compatibility issue; it is not a constructive step. Option C is wrong because implementing the change with a rollback plan still proceeds despite a known major compatibility issue, which could cause significant disruption and violates the principle of not implementing changes with unresolved critical issues. Option D is wrong because proceeding and resolving after implementation is risky and can lead to system failures, data loss, or downtime, and it bypasses the change control process.

175
MCQeasy

Which UDP port is used by the Domain Name System (DNS) for name resolution queries?

A.UDP 161
B.UDP 67
C.UDP 53
D.UDP 123
AnswerC

DNS name resolution queries use UDP port 53 for standard lookups, with TCP 53 reserved for zone transfers and responses exceeding 512 bytes. This satisfies the stem's requirement for the specific UDP port used in resolution queries.

Why this answer

DNS uses UDP port 53 for standard name resolution queries because the request and response are small and UDP's low overhead is ideal for the query-response pattern. TCP port 53 is used only for zone transfers (AXFR/IXFR), DNSSEC responses exceeding 512 bytes, or when the TC (truncated) bit forces a TCP retry.

Exam trap

The trap here is confusing DNS with other common UDP services — candidates who memorize port numbers loosely may pick UDP 67 (DHCP) or UDP 123 (NTP) under time pressure.

How to eliminate wrong answers

Option A is wrong because UDP 161 is used by SNMP for polling and management queries, not DNS. Option B is wrong because UDP 67 is used by DHCP servers to assign IP addresses to clients (with UDP 68 on the client side). Option D is wrong because UDP 123 is used by NTP for time synchronization.

176
MCQmedium

During a qualitative risk analysis, an organization assesses a threat of a data breach due to weak encryption. The likelihood is rated as 'Medium' and the impact as 'High'. According to a standard 3x3 risk matrix, what is the overall risk rating?

A.Medium
B.High
C.Low
D.Critical
AnswerB

A standard 3x3 matrix maps Medium likelihood against High impact to High risk, because impact drives severity upward when likelihood is not Low. The combination does not average to Medium; the matrix's defined intersection for these two ratings is High.

Why this answer

In a standard 3x3 qualitative risk matrix, likelihood and impact are each rated Low, Medium, or High, and the intersection of Medium likelihood with High impact yields a High overall risk rating. This is the conventional mapping used in most risk frameworks. The combination is serious enough to warrant prioritized treatment but does not reach the highest tier.

Exam trap

SSCP often tests the mechanical application of a risk matrix, and candidates err by assuming Medium likelihood always yields Medium risk regardless of impact, or by inventing a 'Critical' rating that does not exist in a 3x3 matrix.

How to eliminate wrong answers

Option A is wrong because Medium overall risk would result from combinations such as Medium likelihood with Medium impact or High likelihood with Low impact, not Medium likelihood with High impact. Option C is wrong because Low overall risk requires both likelihood and impact to be Low or near-Low, which is not the case here. Option D is wrong because Critical is not a standard rating in a 3x3 matrix (which uses Low, Medium, High); even in expanded matrices, Critical typically requires High likelihood with High impact, not Medium likelihood with High impact.

177
MCQmedium

A military system uses mandatory access control with classifications Unclassified, Confidential, Secret, and Top Secret. A user with Secret clearance attempts to read a file labeled Top Secret. What will occur?

A.Access is denied because the subject's clearance is lower than the object's classification
B.Access is granted because the user has write permission
C.Access is granted if the user is the owner of the file
D.Access is granted because the user has a need-to-know
AnswerA

Under mandatory access control, the no-read-up rule enforces that a subject's clearance must dominate the object's classification. Here the Secret clearance is lower than the Top Secret label, so the read is refused regardless of need-to-know or any discretionary permission. This satisfies the stem's constraint that classification levels govern access.

Why this answer

In a mandatory access control (MAC) system, access decisions are based on comparing the subject's clearance level with the object's classification label. Since the user has a Secret clearance and the file is classified Top Secret, the subject's clearance is lower than the object's classification, so read access is denied per the Bell-LaPadula model's Simple Security Property (no read up).

Exam trap

The trap here is that candidates often confuse mandatory access control with discretionary access control, assuming that ownership or need-to-know can override classification labels, but in MAC, clearance level is the primary and non-negotiable gate for read access.

How to eliminate wrong answers

Option B is wrong because write permission is irrelevant in a MAC read operation; the Bell-LaPadula model enforces the *-property (no write down) for write, but read access is governed solely by clearance vs. classification. Option C is wrong because MAC overrides discretionary ownership; even if the user owns the file, the system enforces the classification label, so ownership does not grant read access when clearance is insufficient. Option D is wrong because need-to-know is a separate discretionary control (e.g., via compartments or roles) and does not override the mandatory clearance requirement; without the proper clearance level, need-to-know cannot grant access.

178
MCQhard

An organization uses mandatory access control (MAC) with the Bell-LaPadula model. A subject has a clearance of 'Secret' and an object has a classification of 'Top Secret'. What is the result if the subject attempts to read the object?

A.Write denied
B.Write allowed
C.Read denied
D.Read allowed
AnswerC

Under Bell-LaPadula's no-read-up rule, a Secret-cleared subject cannot read a Top Secret object, so access is denied. This satisfies the mandatory access control constraint: clearance must dominate the object's classification. The simple security property blocks reads to higher classifications regardless of need, preventing unauthorised disclosure.

Why this answer

In the Bell-LaPadula model, the Simple Security Property (no read up) prohibits a subject from reading an object with a higher classification. Since the subject has a clearance of 'Secret' and the object is classified as 'Top Secret', the read attempt is denied. This enforces mandatory access control (MAC) by preventing information flow from higher to lower security levels.

Exam trap

The trap here is that candidates often confuse the Bell-LaPadula model with the Biba model (which focuses on integrity) or misapply the *-property to read operations, leading them to incorrectly select 'Read allowed' or 'Write allowed' when the actual rule is 'no read up'.

How to eliminate wrong answers

Option A is wrong because the operation in question is a read, not a write, and the Bell-LaPadula model's *-property (no write down) applies to write operations, not reads. Option B is wrong because write operations are not being attempted, and even if they were, a write from a Secret subject to a Top Secret object would be allowed under the *-property (write up), but the question asks about a read. Option D is wrong because the Simple Security Property explicitly forbids reading an object with a higher classification (Top Secret) than the subject's clearance (Secret), so read allowed is incorrect.

179
MCQmedium

An organization is required to maintain audit logs for at least one year for compliance purposes. Which log management practice best ensures the integrity of these logs?

A.Encrypting logs during transmission only
B.Compressing logs to save space
C.Storing logs on a standard file server with restricted permissions
D.Using write-once storage and digitally signing each log entry
AnswerD

Write-once storage prevents alteration or deletion of log records for the full retention period, while digital signatures let auditors verify each entry's authenticity and detect tampering. Together they satisfy the one-year integrity requirement, unlike practices that merely centralise, encrypt, or back up logs without guaranteeing immutability.

Why this answer

Write-once storage (e.g., WORM media or append-only filesystems) prevents any modification or deletion of log entries after they are written. Digitally signing each log entry ensures that any tampering can be detected by verifying the signature against the log data. Together, these provide non-repudiation and integrity, meeting compliance requirements for immutable audit logs.

Exam trap

The trap here is that candidates often choose restricted permissions (Option C) thinking access control is sufficient, but the SSCP exam emphasizes that integrity requires cryptographic proof and immutability, not just authorization.

How to eliminate wrong answers

Option A is wrong because encrypting logs only during transmission protects confidentiality in transit but does nothing to prevent alteration or deletion once the logs are stored. Option B is wrong because compressing logs reduces storage space but provides no integrity protection; compressed logs can still be modified or deleted. Option C is wrong because storing logs on a standard file server with restricted permissions relies on access controls, which can be bypassed by compromised accounts or insider threats, and does not guarantee immutability or detect tampering.

180
MCQmedium

An organization uses OAuth 2.0 for delegated access to a cloud storage API. A third-party application requests an access token to read user files. What is the primary purpose of the access token in OAuth?

A.To encrypt the user's data in transit
B.To store the user's credentials in the client application
C.To authorize the client to access the resource server on behalf of the user
D.To authenticate the user to the authorization server
AnswerC

The access token is a credential issued to the client after the user grants authorisation, and the resource server validates it to permit scoped access on the user's behalf. It carries granted permissions rather than the user's password or identity credentials.

Why this answer

The access token represents the authorized scope of access granted by the resource owner (user). It is used by the client to access the protected resource (e.g., API) without exposing user credentials.

181
MCQmedium

An incident responder is collecting evidence from a compromised Linux server. The responder uses the 'dd' command to create an image of the hard drive. Which of the following is the PRIMARY reason for using a write blocker during this process?

A.To prevent the operating system from mounting the drive and altering timestamps.
B.To ensure the imaging process does not modify the original evidence.
C.To increase the speed of the imaging process by bypassing file system checks.
D.To allow the responder to write notes directly to the evidence drive for documentation.
AnswerB

The primary purpose of a write blocker is to prevent any write commands from reaching the evidence drive during imaging. This ensures that the original evidence remains unaltered, preserving its integrity for forensic analysis and legal proceedings. Without a write blocker, the imaging tool or OS could inadvertently write to the drive, contaminating the evidence.

Why this answer

A write blocker is a hardware or software tool that allows read-only access to a storage device, preventing any write operations. Its primary purpose is to ensure that the original evidence is not modified during forensic imaging. This preservation of integrity is crucial for the evidence to be admissible in court and for accurate analysis.

Exam trap

The trap here is thinking that a write blocker is mainly for preventing timestamp changes or for speed, rather than for blocking all writes to preserve evidence.

182
MCQeasy

A security administrator is reviewing the organization's risk register and notices that a risk related to outdated antivirus signatures has been assigned a low risk score because the likelihood is considered low. However, the impact if realized would be severe. Which risk analysis approach is being used, and what is a potential limitation of this approach?

A.Quantitative analysis; it expresses risk in monetary terms but may be limited by data availability.
B.FAIR analysis; it quantifies risk in financial terms and would not assign a low score based solely on likelihood.
C.Semi-quantitative analysis; it uses numeric scales but still requires subjective interpretation.
D.Qualitative analysis; it relies on subjective judgment and may overlook high-impact low-likelihood risks.
AnswerD

Qualitative analysis uses descriptive scales such as low, medium, high for likelihood and impact. In this case, the low likelihood led to a low overall risk score despite severe impact, which is a common limitation. Subjectivity can cause important risks to be underprioritized, especially when likelihood is underestimated.

Why this answer

The use of descriptive terms like 'low' and 'severe' indicates a qualitative risk analysis, which relies on expert judgment and subjective scales. A common limitation is that high-impact, low-likelihood risks may be underprioritized because the low likelihood dominates the overall score. This can lead to inadequate controls for catastrophic but rare events.

Other options describe quantitative or semi-quantitative methods that use numerical values, which are not present in the scenario.

Exam trap

The trap here is assuming that a low likelihood automatically justifies a low risk score without considering the severity of impact, which is a classic pitfall of qualitative analysis.

183
MCQmedium

An IT auditor reports that firewall logs are not being reviewed regularly. Which control should be implemented to address this finding?

A.Archive logs to a read-only medium
B.Disable logging for low-priority events
C.Increase the log retention period to 12 months
D.Deploy a Security Information and Event Management (SIEM) system
AnswerD

A SIEM system centralises firewall logs and applies correlation rules to generate real-time alerts, directly satisfying the audit finding that logs are not reviewed regularly. Unlike manual review, automated monitoring provides continuous oversight and auditable evidence of detection, addressing the control gap the auditor identified.

Why this answer

A SIEM system centralizes log collection, correlation, and alerting, enabling regular review and automated detection of security events. It directly addresses the finding that firewall logs are not reviewed regularly by providing continuous monitoring and analysis. Unlike simple archiving or retention changes, a SIEM actively processes logs to generate actionable insights.

Exam trap

SSCP often tests the difference between log retention, archiving, and active monitoring; candidates may confuse preserving logs with reviewing them, leading to selection of options A or C.

How to eliminate wrong answers

Option A is wrong because archiving logs to read-only media only preserves them for later forensic use; it does not ensure regular review or real-time monitoring. Option B is wrong because disabling logging for low-priority events reduces visibility and does not address the lack of review; it may also violate compliance requirements. Option C is wrong because increasing retention to 12 months only extends storage duration; it does not provide a mechanism for regular review or alerting.

184
MCQhard

A vulnerability scan identifies a critical vulnerability on a web server with a CVSS score of 9.8. The server hosts a public-facing application. However, the patch would require a reboot that would cause downtime during business hours. What should the security administrator do FIRST?

A.Assess the risk and implement compensating controls if possible
B.Schedule the patch for the next maintenance window without further analysis
C.Apply the patch immediately during business hours
D.Document the exception and ignore the vulnerability
AnswerA

Assessing risk and applying compensating controls, such as a web application firewall rule or network segmentation, addresses the exposure without rebooting. This satisfies the stem's constraint of avoiding business-hours downtime while the critical 9.8 CVSS vulnerability remains unpatched on the public-facing server.

Why this answer

Assessing the risk and implementing compensating controls if possible is the first step because it balances the need to address the critical vulnerability with the business impact of downtime. This approach follows risk management principles: evaluate the severity, exploitability, and potential impact, then apply mitigations such as virtual patching, network segmentation, or increased monitoring until a patch can be safely applied. It is not prudent to ignore or immediately disrupt business operations without analysis.

Exam trap

SSCP often tests the tendency to prioritize immediate patching over business continuity, but the correct first step is always risk assessment and compensating controls when downtime is a concern.

How to eliminate wrong answers

Option B is wrong because scheduling the patch without further analysis ignores the possibility of compensating controls that could reduce risk in the interim, and it does not consider the criticality of the vulnerability. Option C is wrong because applying the patch immediately during business hours could cause unplanned downtime, affecting business operations and potentially violating SLAs. Option D is wrong because documenting the exception and ignoring the vulnerability leaves the organization exposed to a critical risk, which is unacceptable for a public-facing server with a CVSS score of 9.8.

185
Multi-Selecthard

A forensic investigator is collecting evidence from a compromised Windows server. According to the order of volatility, which THREE pieces of evidence should be collected FIRST? (Select THREE)

Select 3 answers
A.System event logs
B.Hard drive image
C.Network connections and open ports
D.Contents of RAM (memory dump)
E.List of running processes
AnswersC, D, E

Network connections and open ports reside in memory and change or disappear within seconds, placing them near the top of the order of volatility. Collecting them first satisfies the stem's requirement to gather the most perishable evidence before it is lost.

Why this answer

According to the order of volatility, the most perishable data must be captured first because it disappears when the system is powered off or changes rapidly. Option C (Network connections and open ports) is correct because active TCP/UDP sessions, listening sockets, and ARP/routing state exist only in memory and vanish immediately on shutdown, so tools like netstat, ss, or Get-NetTCPConnection must run first. Option D (Contents of RAM (memory dump)) is correct because physical memory holds encryption keys, injected code, and uncommitted data that is irretrievably lost once power is removed, making it the highest-priority acquisition.

Option E (List of running processes) is correct because the process table, PIDs, parent-child relationships, and loaded modules are volatile kernel structures that change second by second and cannot be recovered from a later disk image. Option A (System event logs) is not among the first tier because, although logs are valuable, they are typically persisted to disk (.evtx files) and survive until overwritten, so they are collected after memory-resident artifacts. Option B (Hard drive image) is not among the first tier because disk contents are the least volatile and remain intact while live memory and network state are captured beforehand.

Exam trap

ISC2 SSCP often tests the misconception that event logs are volatile because they are 'system state' data, but logs are written to disk and persist; the trap is confusing 'important' with 'volatile'.

186
MCQeasy

Which protocol and port combination is commonly used for secure remote administration of a server?

A.HTTPS on TCP 443
B.Telnet on TCP 23
C.RDP on TCP 3389
D.SSH on TCP 22
AnswerD

SSH on TCP 22 encrypts the entire remote administration session, including credentials and commands, satisfying the requirement for secure remote server management. Unlike Telnet on port 23, which transmits data in cleartext, SSH provides confidentiality and integrity through cryptographic tunnelling, making it the standard choice for hardened administrative access.

Why this answer

SSH on TCP port 22 is the standard protocol for secure remote administration of Linux/Unix servers, providing encrypted authentication and session traffic. It replaces insecure protocols like Telnet and rlogin by encrypting the entire session, including credentials, using strong ciphers and key exchange.

Exam trap

SSCP often tests the confusion between secure web management (HTTPS) and secure command-line administration (SSH) — candidates pick HTTPS because it is 'secure' but it is not the remote shell protocol.

How to eliminate wrong answers

Option A is wrong because HTTPS on TCP 443 is used for secure web traffic and web-based management consoles, not for command-line remote administration of a server. Option B is wrong because Telnet on TCP 23 transmits credentials and data in cleartext and is considered insecure — it is not a secure remote administration protocol. Option C is wrong because RDP on TCP 3389 is a graphical remote desktop protocol for Windows systems; while it can be secured with TLS, it is not the commonly cited secure remote administration protocol in the SSCP context, and SSH is the canonical answer.

187
MCQmedium

A security administrator at a financial services firm is reviewing the organization's data retention practices. The legal team has mandated that certain transaction records be kept for exactly seven years and then destroyed. The administrator must ensure records are deleted automatically after seven years. Which of the following should be implemented to enforce this requirement?

A.A data loss prevention (DLP) solution that blocks exfiltration of transaction records
B.A backup schedule that archives transaction records every quarter to tape
C.A data classification scheme that labels transaction records as confidential
D.A retention policy with automated deletion after the seven-year period
AnswerD

A retention policy defines how long data must be kept and automates its destruction when the period expires. This directly enforces the legal mandate without relying on manual intervention, ensuring records are deleted exactly at seven years and reducing the risk of non-compliance or accidental over-retention.

Why this answer

A retention policy is the formal control that specifies how long records must be kept and triggers their destruction when the period ends. It aligns legal requirements with operational procedures and can be automated. Classification, backups, and DLP address different concerns and do not enforce time-based deletion.

Exam trap

The trap here is confusing data protection controls like classification or DLP with lifecycle management controls that actually enforce retention and destruction.

188
MCQmedium

An organization uses AWS IAM to manage access. Which best practice ensures least privilege?

A.Use a single shared admin account
B.Use root account for administrative tasks
C.Create individual users and assign only necessary permissions
D.Grant all users full access to S3 buckets
AnswerC

Granting each identity only the permissions its role requires enforces least privilege at the IAM policy level, rather than sharing credentials or attaching broad managed policies. Individual accounts also preserve accountability through distinct audit trails.

Why this answer

Least privilege means granting each identity only the permissions required to perform its job. Creating individual IAM users (or roles) and attaching narrowly scoped policies that grant only necessary actions on specific resources enforces this principle and provides accountability through unique credentials.

Exam trap

SSCP often tests the misconception that administrative convenience (shared admin account, root usage) is acceptable — candidates must recognize that least privilege requires unique identities and minimal scoped permissions, not just 'admin for everyone.'

How to eliminate wrong answers

Option A is wrong because a single shared admin account eliminates individual accountability, makes auditing impossible, and grants far more permissions than any single task requires — the opposite of least privilege. Option B is wrong because the root account has unrestricted access to all AWS resources and billing; AWS best practice is to lock away root credentials, enable MFA, and use it only for the few tasks that require it. Option D is wrong because granting all users full access to S3 buckets violates least privilege by giving every user read/write/delete permissions on all buckets regardless of their role.

189
MCQeasy

A network administrator is configuring a firewall rule to allow inbound HTTPS traffic to a web server. Which protocol and port should be allowed?

A.UDP port 80
B.UDP port 443
C.TCP port 443
D.TCP port 80
AnswerC

HTTPS uses TCP port 443, so permitting that protocol and port allows encrypted inbound web traffic to reach the server. TCP provides the reliable, connection-oriented transport TLS requires, unlike UDP, and port 80 would only serve unencrypted HTTP.

Why this answer

HTTPS (HTTP over TLS) uses TCP as its transport protocol because it requires reliable, connection-oriented delivery for secure web traffic. The default port for HTTPS is 443, as defined in RFC 2818. Therefore, allowing TCP port 443 is the correct firewall rule.

Exam trap

The trap here is that candidates often confuse HTTP (TCP 80) with HTTPS (TCP 443) or mistakenly think HTTPS can use UDP, but the SSCP exam expects you to know that standard HTTPS uses TCP port 443.

How to eliminate wrong answers

Option A is wrong because UDP port 80 is used for HTTP (not HTTPS) and UDP is not the transport protocol for standard web traffic; HTTP uses TCP. Option B is wrong because UDP port 443 is not a standard protocol; HTTPS uses TCP, not UDP, for reliable delivery. Option D is wrong because TCP port 80 is used for unencrypted HTTP traffic, not HTTPS.

190
MCQmedium

During a security audit, it is found that several employees have written their passwords on sticky notes attached to their monitors. Which policy is being violated?

A.Social Media Policy
B.Clean Desk Policy
C.Data Handling Policy
D.Password Policy
AnswerB

A Clean Desk Policy requires sensitive information, including written credentials, to be secured or removed when workspaces are unattended. Sticky notes exposing passwords on monitors directly breach that requirement, since the policy explicitly covers physical artefacts left in plain view.

Why this answer

The Clean Desk Policy is violated because it requires employees to keep their workspaces free of sensitive information, including passwords, when not in use. Writing passwords on sticky notes and attaching them to monitors leaves credentials exposed, directly contravening this policy. The Clean Desk Policy aims to reduce the risk of unauthorized access to information.

Exam trap

SSCP often tests the confusion between Password Policy and Clean Desk Policy, but the physical exposure of passwords is a clean desk violation, not a password complexity issue.

How to eliminate wrong answers

Option A is wrong because a Social Media Policy governs employee use of social media platforms, not the physical security of passwords. Option C is wrong because a Data Handling Policy defines how data should be classified, stored, and transmitted, but the specific act of leaving passwords on monitors is a clean desk issue. Option D is wrong because a Password Policy typically dictates password complexity, rotation, and storage, but the violation here is the physical exposure of the password, which falls under clean desk rather than password construction rules.

191
MCQeasy

A university IT department manages a lab of 50 computers running Windows 10 that are used by students for coursework. The computers are joined to a domain and have Group Policy applied to restrict administrative access. Recently, several students were able to install unauthorized software by using the built-in Administrator account, which had the same password on all lab computers. The IT department wants to prevent this without affecting the students' ability to run required academic software. Which of the following is the most effective solution?

A.Configure the computers to only allow standard user accounts.
B.Disable the local Administrator account on all lab computers.
C.Use a tool to assign a unique, random password to the local Administrator account on each computer.
D.Implement Software Restriction Policies to block unauthorized executables.
AnswerC

Assigning a unique random password per machine via Local Administrator Password Solution removes the shared-credential weakness, so compromising one lab computer cannot grant administrative access to all 50. This satisfies the constraint of blocking unauthorised installs without restricting students' required academic software.

Why this answer

Assigning a unique, random password to the local Administrator account on each computer (often via Microsoft's Local Administrator Password Solution, LAPS) neutralizes the shared-credential attack vector while leaving the account available for legitimate local administrative tasks. Because each machine now has a distinct password, a student who discovers the password on one lab PC cannot reuse it on the other 49. This directly addresses the root cause — identical local admin credentials — without removing the students' ability to run required academic software.

Exam trap

SSCP often tests the difference between mitigating a symptom (blocking executables) and eliminating the root cause (shared local admin credentials); candidates frequently choose the more visible technical control instead of the identity-focused fix.

How to eliminate wrong answers

Option A is wrong because restricting computers to only standard user accounts would prevent legitimate local administrative tasks and does not by itself remove the existing Administrator account or its shared password. Option B is wrong because disabling the local Administrator account can break recovery and maintenance scenarios and does not address the underlying issue of shared credentials if the account is later re-enabled. Option D is wrong because Software Restriction Policies block unauthorized executables but do not stop students from using the Administrator account to install software through other means (e.g., scripts, MSI packages, or modifying system settings).

192
MCQmedium

A security manager is assessing the risk of insider threat for a healthcare organization. Which of the following is the most appropriate way to categorize a malicious insider who intentionally exfiltrates patient data?

A.Natural threat
B.Technical threat
C.Human threat
D.Environmental threat
AnswerC

A malicious insider is a human threat source because the action is deliberate and carried out by a person. Human threats can be internal or external, and they include both intentional and unintentional acts. In this scenario, the insider intentionally exfiltrates data, which clearly falls under the human threat category, making this the correct classification.

Why this answer

Threat sources are commonly categorized as natural, human, and environmental. A malicious insider who intentionally exfiltrates data is a human threat because the act is deliberate and performed by a person. This classification directs risk managers to apply controls such as background checks, least privilege, separation of duties, and continuous monitoring, which are effective against human threats.

Exam trap

The trap here is focusing on the technical method of exfiltration and misclassifying the threat source as technical, when the actor is human.

193
MCQeasy

A security administrator is tasked with ensuring that only authorized software can run on company workstations. Which security control should be implemented?

A.Antivirus software
B.Patch management
C.Host-based firewall
D.Application whitelisting
AnswerD

Application whitelisting maintains an approved-software list and blocks execution of anything not on it, directly enforcing the stem's constraint that only authorised software runs on workstations. Blacklisting and antivirus signatures cannot guarantee this, since unknown or newly installed programs remain executable.

Why this answer

Application whitelisting is the correct control because it explicitly defines a list of approved software that is allowed to execute on workstations. This prevents unauthorized or malicious software from running, even if it bypasses other defenses, by enforcing a default-deny policy at the operating system level (e.g., via Windows AppLocker or Software Restriction Policies). Unlike antivirus, which relies on signatures to detect known threats, whitelisting blocks unknown or unapproved executables by default.

Exam trap

The trap here is that candidates often confuse 'preventing unauthorized software' with 'detecting malware,' leading them to choose antivirus software, but the question specifically asks for a control that ensures only authorized software can run, which requires a default-deny approach like application whitelisting rather than a detection-based tool.

How to eliminate wrong answers

Option A is wrong because antivirus software uses signature-based or heuristic detection to identify known malware, but it cannot prevent execution of unauthorized or custom-coded software that is not yet in its database. Option B is wrong because patch management ensures software is up-to-date with security fixes, but it does not control which applications are allowed to run; it only addresses vulnerabilities in already-installed software. Option C is wrong because a host-based firewall controls network traffic to and from the workstation based on ports and protocols, but it does not restrict which applications can execute locally on the system.

194
MCQmedium

A company detects ransomware on a file server. The ransomware is currently encrypting files. Which containment strategy should be implemented FIRST?

A.Run antivirus to remove the ransomware
B.Notify all users to change passwords
C.Disconnect the server from the network
D.Restore files from backup
AnswerC

Severing the network link halts the ransomware's propagation and command-and-control traffic immediately, satisfying the need to stop active encryption before eradication. Isolating the host preserves volatile evidence and prevents lateral spread, whereas powering off may destroy memory artefacts and leave shares reachable.

Why this answer

The immediate priority in ransomware containment is to isolate the compromised server from the network to prevent the encryption process from spreading to other systems. Disconnecting the network cable or disabling the network interface stops the ransomware from communicating with command-and-control servers and blocks lateral movement via SMB or other protocols. This containment step must occur before any remediation like antivirus scans or file restoration.

Exam trap

The trap here is that candidates often choose to run antivirus first, thinking removal stops the attack, but the SSCP exam emphasizes that containment (stopping the spread) must precede eradication (removing the malware).

How to eliminate wrong answers

Option A is wrong because running antivirus on an actively encrypting server may trigger the ransomware to accelerate encryption or delete files, and removal does not stop the ongoing encryption process. Option B is wrong because notifying users to change passwords is a post-containment or post-incident step; it does not halt the active encryption or network propagation of the ransomware. Option D is wrong because restoring files from backup should only be performed after the ransomware is fully contained and removed; attempting restoration while the ransomware is active will result in immediate re-encryption of restored files.

195
MCQmedium

A company deploys a web application and wants to protect against SQL injection and XSS attacks. Which security control is specifically designed to inspect HTTP traffic and block such attacks?

A.Intrusion Detection System (IDS)
B.Network segmentation
C.Web Application Firewall (WAF)
D.Host-based firewall
AnswerC

A Web Application Firewall inspects inbound HTTP/HTTPS requests at layer 7, matching signatures and rules to block SQL injection and cross-site scripting payloads before they reach the application. This directly satisfies the stem's requirement for a control specifically designed to inspect HTTP traffic.

Why this answer

A Web Application Firewall (WAF) operates at the application layer (HTTP/HTTPS) and inspects request and response payloads for attack signatures such as SQL injection and cross-site scripting (XSS). It can block or filter malicious requests before they reach the web application, making it the control specifically designed for this purpose.

Exam trap

The trap is confusing detection with prevention — candidates may pick IDS because it 'monitors attacks,' but only a WAF is designed to inspect HTTP traffic and actively block SQLi and XSS.

How to eliminate wrong answers

Option A is wrong because an IDS detects and alerts on suspicious traffic but does not sit inline to block application-layer attacks — it is passive and focused on detection, not prevention. Option B is wrong because network segmentation divides the network into zones to limit lateral movement; it does not inspect HTTP payloads or block SQLi/XSS. Option D is wrong because a host-based firewall filters traffic by IP, port, and protocol at the host level — it does not parse HTTP content to detect application-layer attacks like SQL injection or XSS.

196
MCQhard

Based on the exhibit, what is the most appropriate immediate action?

A.Schedule patching during the next change window in 30 days
B.Apply the vendor patch to the host as soon as possible
C.Run another vulnerability scan to confirm the finding
D.Ignore the vulnerability because it's a false positive
AnswerB

Patching directly addresses the exploited vulnerability on the affected host, satisfying the stem's demand for immediate containment. Unlike isolation or monitoring, which merely limit exposure, applying the vendor patch removes the underlying flaw, preventing further compromise. This makes it the most appropriate urgent action when the exhibit confirms an unpatched, actively targeted system.

Why this answer

The exhibit shows a critical remote code execution vulnerability with a CVSS score of 9.8, which poses an immediate threat to the host. Applying the vendor patch as soon as possible is the most appropriate action because it directly eliminates the risk without delay, aligning with the principle of timely remediation for high-severity vulnerabilities.

Exam trap

The trap here is that candidates may choose to rescan or delay patching due to change management policies, failing to recognize that critical remote code execution vulnerabilities require immediate out-of-cycle patching to prevent imminent compromise.

How to eliminate wrong answers

Option A is wrong because scheduling patching in 30 days for a critical remote code execution vulnerability (CVSS 9.8) leaves the host exposed to active exploitation, which violates the immediate response required for such high-risk findings. Option C is wrong because running another vulnerability scan would only reconfirm the already validated finding, wasting time that could be used for remediation; the scan result is assumed accurate based on the exhibit. Option D is wrong because ignoring the vulnerability as a false positive is dangerous given the critical severity and known exploitability of the CVE; false positives are rare for such well-documented remote code execution vulnerabilities.

197
MCQeasy

Refer to the exhibit. An AWS S3 bucket policy is defined as shown. Which statement about this policy is TRUE?

A.The company-public bucket objects are completely private
B.The Deny statement prevents all access to both buckets
C.Any user can read objects in the company-public bucket
D.The policy applies to all buckets in the account
AnswerC

The bucket policy grants a wildcard principal read permission on the company-public bucket's objects, so any unauthenticated or authenticated user can retrieve them. This permissive Principal and Action combination satisfies the condition that public read access is allowed, making the statement true.

Why this answer

The S3 bucket policy shown in the exhibit includes an Allow statement granting s3:GetObject to Principal '*' on the company-public bucket, which means any user (authenticated or anonymous) can read objects in that bucket. The Deny statement applies only to the company-private bucket, so it does not affect the public bucket. Therefore, the true statement is that any user can read objects in the company-public bucket.

Exam trap

SSCP often tests whether candidates conflate an explicit Deny on one resource with account-wide denial, or assume Principal '*' means only authenticated AWS users rather than truly anonymous access.

How to eliminate wrong answers

Option A is wrong because the policy explicitly grants public read access to the company-public bucket, so its objects are not private. Option B is wrong because the Deny statement is scoped to the company-private bucket's ARN, not both buckets, so it does not block access to the public bucket. Option D is wrong because the policy's Resource elements reference specific bucket ARNs (company-public and company-private), not a wildcard covering all buckets in the account.

198
MCQhard

A company has a policy requiring segregation of duties (SoD) for financial transactions. Which scenario represents a violation of this principle?

A.The system administrator performs backups, and the security officer reviews audit logs
B.The finance officer approves invoices and also reconciles the bank statements
C.Two managers must each approve any expenditure over $10,000
D.The purchasing manager creates purchase orders, and the accounts payable clerk processes payments
AnswerB

Segregation of duties requires that one person cannot both authorise a transaction and verify it. Approving invoices and reconciling the resulting bank statements gives the finance officer control over both sides, enabling concealment of fraud.

Why this answer

Segregation of duties requires that no single individual controls all aspects of a transaction, especially those involving financial assets. Having the same finance officer both approve invoices and reconcile bank statements means one person can initiate and conceal a fraudulent payment, which is a classic SoD violation. The other scenarios either separate duties or add independent review.

Exam trap

SSCP often tests the misconception that any shared responsibility is an SoD violation, when in fact SoD is violated only when one person can both execute and conceal a transaction without independent oversight.

How to eliminate wrong answers

Option A is not a violation because the system administrator performing backups and the security officer reviewing audit logs are separate roles with independent oversight. Option C is not a violation because requiring two managers to approve expenditures over $10,000 enforces dual control, which strengthens SoD. Option D is not a violation because the purchasing manager creating purchase orders and the accounts payable clerk processing payments are separate duties, which is the correct SoD design.

199
MCQmedium

A company wants to deploy a network IDS that can analyze traffic patterns and detect anomalies. Where should the IDS sensor be placed to monitor all traffic on a network segment without introducing latency?

A.Inline between the router and the switch
B.At the core switch as a transparent bridge
C.On the same segment as the router
D.Connected to a switch SPAN port
AnswerD

A SPAN port mirrors copies of frames from the monitored segment to the sensor, so the IDS analyses traffic passively without sitting inline in the forwarding path. This satisfies the requirement to monitor all segment traffic without introducing latency.

Why this answer

A SPAN (Switched Port Analyzer) port mirrors traffic from one or more switch ports or VLANs to a dedicated monitoring port, allowing the IDS sensor to receive a copy of the traffic passively. Because the sensor is not in the forwarding path, it introduces zero latency to production traffic while still seeing all frames on the monitored segment. This is the canonical out-of-band IDS deployment.

Exam trap

SSCP often tests the confusion between inline (IPS, adds latency) and out-of-band (IDS, passive) deployments — candidates pick 'inline' thinking it guarantees visibility, but it violates the no-latency requirement.

How to eliminate wrong answers

Option A is wrong because placing the IDS inline between router and switch puts it in the traffic path, adding latency and creating a single point of failure — that is an IPS deployment pattern, not a passive IDS. Option B is wrong because a transparent bridge at the core switch still forwards traffic through the device, introducing latency and risking outages. Option C is wrong because simply being on the same segment as the router does not guarantee visibility into all traffic — modern switched networks isolate unicast frames, so the sensor would only see broadcast/multicast.

200
MCQhard

Which of the following best describes the difference between HMAC and a simple hash function like SHA-256 when used for message authentication?

A.HMAC is faster than SHA-256
B.SHA-256 produces a larger digest than HMAC
C.HMAC provides integrity and authentication; SHA-256 provides only integrity
D.HMAC is used for encryption, not hashing
AnswerC

HMAC applies a secret key within its construction, so verification proves both that the message was unaltered and that the sender held the key. A plain SHA-256 digest detects modification only, since anyone can recompute it without any shared secret.

Why this answer

HMAC incorporates a secret key into the hash process, providing authentication that a simple hash cannot.

201
Multi-Selecthard

Which of the following are considered secure cryptographic practices for key management? (Select THREE)

Select 3 answers
A.Storing keys in plaintext configuration files
B.Implementing regular key rotation
C.Using a Hardware Security Module (HSM) for key storage
D.Sharing keys over email for convenience
E.Securely destroying keys when no longer needed
AnswersB, C, E

Key rotation limits the impact of a key compromise.

Why this answer

Secure key management practices include: (B) implementing regular key rotation, which limits the amount of data protected by a single key and reduces the impact of a key compromise, consistent with guidance such as NIST SP 800-57; (C) using a Hardware Security Module (HSM) for key storage, since HSMs provide tamper-resistant hardware protection and keep keys out of general-purpose systems; and (E) securely destroying keys when they are no longer needed, so that retired or compromised keys cannot be recovered and misused. In contrast, storing keys in plaintext configuration files (A) and sharing keys over email (D) are insecure practices that expose keys to unauthorized disclosure.

Exam trap

In the SSCP exam, a common trap is the misconception that convenience (e.g., email sharing or plaintext storage) can be acceptable in secure environments, but the exam strictly enforces that keys must never be transmitted or stored in an insecure manner.

202
Multi-Selecthard

During a post-incident review, the incident response team identifies several areas for improvement. According to NIST SP 800-61, which THREE activities are typically part of the post-incident activity phase?

Select 3 answers
A.Patch all systems in the organization as a precaution
B.Update the incident response plan based on findings
C.Replace all affected hardware immediately
D.Conduct a lessons learned meeting
E.Track metrics such as MTTD and MTTR
AnswersB, D, E

NIST SP 800-61 places revising the incident response plan within post-incident activity, so lessons identified during review feed back into procedures, contact lists, and controls. This closes the improvement loop and better prepares the team for subsequent incidents.

Why this answer

Option B is correct because NIST SP 800-61's post-incident activity phase explicitly includes using the lessons learned and review findings to update the incident response plan, policies, and procedures so future responses improve. Option D is correct because holding a lessons learned meeting (post-incident review) with all involved parties is a core recommended activity in this phase, used to identify what happened, what was done well, and what needs improvement. Option E is correct because NIST SP 800-61 calls for using incident data to develop and track metrics, such as mean time to detect (MTTD) and mean time to recover/repair (MTTR), to measure and improve the incident response capability over time.

Option A is not part of the post-incident activity phase; patching is a remediation/eradication action performed during incident handling, not a blanket post-incident review activity. Option C is likewise incorrect because immediately replacing all affected hardware is a recovery/remediation decision made during the handling phase based on the specific incident, not a standard post-incident review activity.

Exam trap

The trap here is confusing operational recovery actions (like patching or hardware replacement) with the analytical and improvement-focused activities that define the post-incident phase per NIST SP 800-61.

203
MCQmedium

A security administrator at a hospital is configuring a server that processes electronic health records. The server runs a Linux-based operating system, and the administrator needs to select a mandatory access control (MAC) framework that can enforce granular, policy-based restrictions on how processes interact with files, network ports, and other system resources. Which of the following should the administrator choose?

A.Password complexity and account lockout policies
B.Role-based access control (RBAC) through group membership
C.Discretionary access control (DAC) via standard file permissions
D.SELinux
AnswerD

SELinux is a mandatory access control framework integrated into the Linux kernel that enforces security policies based on labels applied to processes, files, ports, and other objects. It restricts even root-level processes according to administrator-defined policy, which fits the hospital's need for granular, system-wide MAC enforcement on a Linux host handling sensitive health records.

Why this answer

SELinux provides mandatory access control by labeling subjects and objects and enforcing administrator-defined policy in the kernel, restricting processes regardless of user identity. The other choices describe authentication hardening or discretionary and role-based models that do not enforce system-wide mandatory policy. For a Linux server holding regulated health data, SELinux is the correct framework to meet the granular MAC requirement.

Exam trap

The trap here is assuming that any access-control model labeled as role-based or permission-based satisfies a mandatory access control requirement, when MAC specifically requires kernel-enforced policy independent of object ownership.

204
MCQhard

An organization experiences a ransomware attack that encrypts file servers. The annualized loss expectancy (ALE) for this risk is calculated as $150,000. The single loss expectancy (SLE) is $30,000. What is the annualized rate of occurrence (ARO)?

A.0.2
B.4.5
C.0.5
D.5
AnswerD

ARO is derived by dividing the annualised loss expectancy by the single loss expectancy: $150,000 ÷ $30,000 = 5. This means the ransomware event is expected to occur five times per year, satisfying the stem's given ALE and SLE values.

Why this answer

The annualized rate of occurrence (ARO) is calculated by dividing the annualized loss expectancy (ALE) by the single loss expectancy (SLE): ARO = ALE / SLE = $150,000 / $30,000 = 5. This means the ransomware attack is expected to occur five times per year, which is a key metric in quantitative risk analysis for prioritizing security controls.

Exam trap

The trap here is that candidates often confuse the formula and divide SLE by ALE instead of ALE by SLE, leading to the incorrect fractional answer (0.2) rather than the correct integer (5).

How to eliminate wrong answers

Option A (0.2) is wrong because it incorrectly inverts the formula, dividing SLE by ALE (30,000 / 150,000 = 0.2), which would imply the event occurs once every five years, not five times per year. Option B (4.5) is wrong because it likely results from a miscalculation, such as subtracting or misplacing a decimal, and does not correspond to any correct risk formula. Option C (0.5) is wrong because it represents half an occurrence per year, which would require an ALE of $15,000 (SLE × 0.5), not the given $150,000.

205
MCQmedium

An attacker sends a gratuitous ARP reply associating the attacker's MAC address with the default gateway's IP address. Which attack is being performed, and what is the primary risk?

A.DNS poisoning; risk is traffic redirection to malicious sites.
B.DHCP starvation; risk is denial of service.
C.SYN flood; risk is resource exhaustion.
D.ARP spoofing; risk is man-in-the-middle traffic interception.
AnswerD

Gratuitous ARP replies let the attacker poison victims' ARP caches, binding the gateway's IP to the attacker's MAC. Traffic destined for the gateway is then redirected through the attacker, enabling man-in-the-middle interception and potential modification of communications.

Why this answer

A gratuitous ARP reply that binds the attacker's MAC to the gateway's IP is the classic ARP spoofing (ARP poisoning) attack. The victim's ARP cache is poisoned so traffic destined for the gateway is sent to the attacker, enabling man-in-the-middle interception, modification, or denial of service.

Exam trap

The trap is that gratuitous ARP sounds like a DNS or DHCP concept to candidates unfamiliar with layer 2 attacks — the key discriminator is that the attack manipulates MAC-to-IP bindings in the ARP cache, which points to ARP spoofing, not DNS or DHCP attacks.

How to eliminate wrong answers

Option A is wrong because DNS poisoning corrupts DNS resolver caches to redirect domain name resolution, not ARP caches, and it does not involve MAC-to-IP binding at layer 2. Option B is wrong because DHCP starvation exhausts the DHCP pool by flooding DISCOVER requests with spoofed MACs, causing denial of service for legitimate clients — it does not involve gratuitous ARP or gateway impersonation. Option C is wrong because a SYN flood exhausts TCP connection state on a server by sending many half-open connections, which is a layer 4 DoS attack unrelated to ARP cache manipulation.

206
MCQmedium

A security analyst is reviewing logs and notices multiple failed login attempts for a user account, followed by a successful login from an unfamiliar IP address at 3:00 AM. Which type of risk is most directly indicated by this scenario?

A.Environmental risk
B.Human intentional risk
C.Human accidental risk
D.Technical risk
AnswerB

Repeated failed logins followed by a successful login from an unfamiliar IP at 3:00 AM indicates deliberate credential attack or account compromise. A person intentionally attempted unauthorised access, which is human intentional risk rather than accidental or environmental risk.

Why this answer

The scenario describes a successful login after multiple failed attempts from an unfamiliar IP address at an unusual time (3:00 AM). This pattern strongly indicates a deliberate brute-force or credential-stuffing attack, where an attacker intentionally attempts to gain unauthorized access. Therefore, the risk is human intentional, as it involves a malicious actor's purposeful actions.

Exam trap

ISC2 often tests the distinction between 'human intentional' and 'human accidental' by presenting a pattern of failed logins that could be mistaken for a user forgetting their password, but the successful login from an unfamiliar IP at an odd hour confirms malicious intent, not a mistake.

How to eliminate wrong answers

Option A is wrong because environmental risk refers to threats like natural disasters, power outages, or hardware failures, not to authentication anomalies. Option C is wrong because human accidental risk involves unintentional errors (e.g., mistyping a password or misconfiguring a firewall), not a pattern of repeated failed logins followed by a successful breach. Option D is wrong because technical risk relates to system vulnerabilities, software bugs, or protocol weaknesses (e.g., unpatched SSH flaws), not to the deliberate exploitation of credentials.

207
MCQmedium

A company's log management solution is overwhelmed by high-volume logs from network devices, causing storage and analysis delays. Which strategy would best improve the efficiency of the log management process?

A.Increase the storage capacity of the log server
B.Increase the frequency of log analysis cycles
C.Implement log filtering and prioritization rules
D.Reduce the number of devices sending logs
AnswerC

Filtering and prioritisation rules discard low-value events and route critical ones for prompt analysis, directly reducing the volume that overwhelms storage and delays processing. This addresses the stem's throughput constraint more effectively than simply adding capacity or retention.

Why this answer

Implementing log filtering and prioritization rules (Option C) directly addresses the root cause of the problem by reducing the volume of irrelevant or low-priority logs before they are stored or analyzed. This improves both storage efficiency and analysis speed, as the log management system processes only meaningful events, such as those matching security or performance thresholds, rather than being overwhelmed by high-frequency noise like repeated informational syslog messages.

Exam trap

ISC2 often tests the misconception that adding more resources (storage or processing frequency) is the solution to data overload, when in fact the correct approach is to reduce the data volume through intelligent filtering and prioritization.

How to eliminate wrong answers

Option A is wrong because simply increasing storage capacity does not solve the analysis delay; it only postpones the storage issue while the system continues to process and store the same high volume of logs, potentially worsening performance. Option B is wrong because increasing the frequency of log analysis cycles would further strain the already overwhelmed system, leading to greater delays and resource contention, not efficiency. Option D is wrong because reducing the number of devices sending logs is a drastic measure that compromises network visibility and security monitoring, and it does not address the underlying problem of inefficient log handling from the remaining devices.

208
MCQeasy

A company wants to ensure that employees understand the proper use of corporate email and internet. Which policy should they implement?

A.Data Handling Policy
B.Remote Access Policy
C.Acceptable Use Policy
D.Password Policy
AnswerC

An Acceptable Use Policy defines permitted employee behaviour for corporate email and internet resources, directly addressing the stated need. It specifies what staff may and may not do with these assets, unlike password or access policies that govern credentials.

Why this answer

An Acceptable Use Policy (AUP) defines the rules and guidelines for using corporate IT resources, including email and internet. It specifies permitted and prohibited activities, such as personal browsing, sending sensitive data, or accessing inappropriate content, ensuring employees understand their responsibilities. This policy directly addresses the company's goal of educating employees on proper usage, unlike other policies that focus on data classification, remote connectivity, or authentication.

Exam trap

The SSCP exam often tests the distinction between policies that are broad (like AUP) versus those that are narrowly focused on specific technical controls (like password or remote access), leading candidates to confuse a general usage guideline with a security control policy.

How to eliminate wrong answers

Option A is wrong because a Data Handling Policy governs how data is classified, stored, transmitted, and disposed of, not the general use of email and internet by employees. Option B is wrong because a Remote Access Policy specifies requirements for connecting to the corporate network from external locations (e.g., VPN protocols, multi-factor authentication), not day-to-day email and internet usage. Option D is wrong because a Password Policy defines password complexity, rotation, and management rules, not acceptable behaviors for email and internet use.

209
MCQmedium

A security administrator is building a Security Information and Event Management (SIEM) correlation rule to detect a specific attack pattern on a Linux web server. The rule must identify attempts where an attacker sends a single malicious HTTP request that causes the server to execute an arbitrary operating system command. Which of the following event sources would provide the most reliable and immediate evidence for this rule?

A.Apache access logs with the Combined Log Format enabled
B.NetFlow records exported from the network router
C.Linux auditd logs configured to monitor execve system calls
D.Syslog messages from the SSH daemon
AnswerC

auditd can monitor the execve system call, which is invoked whenever a new process is executed. By configuring a rule to watch execve, the SIEM will receive an event containing the full command line and the parent process. This directly detects the arbitrary command execution caused by the malicious HTTP request, providing immediate and reliable evidence.

Why this answer

Detecting arbitrary command execution requires visibility into process creation on the host. Linux auditd can monitor the execve system call, capturing the exact command line and parent process for every new program. This gives the SIEM immediate, high-fidelity evidence of the attack, unlike network flow or web access logs that lack process-level context.

Exam trap

The trap here is assuming that web server access logs alone can confirm command execution, when they only show the request, not the resulting process activity.

210
MCQeasy

What is the primary purpose of a baseline configuration in configuration management?

A.To provide a consistent, secure starting point for systems
B.To store configuration items in the CMDB
C.To detect malware infections
D.To track software licenses
AnswerA

A baseline configuration defines the approved, hardened settings — services, ports, registry values — that every system must match, giving configuration management a measurable reference for detecting drift. This satisfies the stem's purpose by establishing the consistent, secure starting point from which deviations are identified and corrected.

Why this answer

A baseline configuration in configuration management defines a known, secure, and consistent state for a system at a specific point in time. This baseline serves as the foundation for all subsequent changes, ensuring that systems are deployed with hardened settings and that any deviations can be detected and remediated. It directly supports security operations by enforcing minimum security standards and simplifying compliance auditing.

Exam trap

ISC2 often tests the distinction between a baseline configuration (the desired secure state) and the CMDB (the database that stores configuration items), so candidates mistakenly select the CMDB option because they confuse the repository with the purpose of the baseline itself.

How to eliminate wrong answers

Option B is wrong because storing configuration items in the CMDB is a function of the Configuration Management Database, not the purpose of a baseline configuration; a baseline is a snapshot of configuration items, not the storage repository itself. Option C is wrong because detecting malware infections is the role of antivirus or endpoint detection and response (EDR) tools, not a baseline configuration; while a baseline can help identify unauthorized changes that may indicate malware, its primary purpose is not detection. Option D is wrong because tracking software licenses is a function of license management or asset management tools, not the primary purpose of a baseline configuration; baselines focus on system settings and security posture, not license compliance.

211
MCQeasy

Which of the following is the primary purpose of a chain of custody form in digital forensics?

A.To track the possession and handling of evidence from collection to presentation
B.To document the steps taken to contain an incident
C.To record the hash values of forensic images
D.To provide a list of approved forensic tools
AnswerA

The chain of custody form records every transfer, custodian, and handling action for evidence, creating an unbroken audit trail from seizure through analysis to courtroom presentation. This documentation lets the court verify that nothing was altered, supporting evidence admissibility.

Why this answer

A chain of custody form is used to document the chronological sequence of custody, control, transfer, analysis, and disposition of evidence. Its primary purpose is to track who had possession of the evidence and what was done with it from the moment of collection through to presentation in court. This ensures the evidence is admissible and has not been tampered with.

Exam trap

SSCP often tests the confusion between chain of custody and other forensic documentation like incident response forms or hash logs, causing candidates to choose an answer that describes a related but different artifact.

How to eliminate wrong answers

Option B is wrong because documenting containment steps is part of incident response procedures, not the chain of custody form, which focuses on evidence handling. Option C is wrong because recording hash values is a separate integrity verification step; while hashes may be noted on a chain of custody form, the form's primary purpose is tracking possession, not recording hashes. Option D is wrong because a list of approved forensic tools is maintained in tool validation documentation, not in the chain of custody form.

212
MCQmedium

A company wants to deploy a firewall that can track the state of active connections and make decisions based on the context of traffic flows. Which firewall type should they choose?

A.Stateless packet filter
B.Stateful firewall
C.Application proxy firewall
D.Next-generation firewall
AnswerB

A stateful firewall maintains a connection state table, tracking each flow's context so return traffic and established sessions are evaluated against recorded states rather than static rules alone. This satisfies the requirement to make decisions based on the context of active traffic flows.

Why this answer

A stateful firewall tracks the state of active connections using a state table, so it can allow return traffic for an established session without an explicit inbound rule. This context-aware decision-making — matching packets to existing flows — is exactly what the requirement describes.

Exam trap

SSCP often tests the distinction between stateful inspection and application proxy inspection — candidates pick NGFW or proxy because they sound more advanced, missing the specific 'connection state' wording.

How to eliminate wrong answers

Option A is wrong because a stateless packet filter evaluates each packet in isolation against static ACLs and has no concept of connection state, so it cannot make context-based decisions. Option C is wrong because an application proxy firewall terminates and inspects traffic at Layer 7, which is more than the requirement asks for and is typically slower; the requirement is about connection state tracking, which is Layer 3/4 stateful inspection. Option D is wrong because a next-generation firewall adds application awareness, IPS, and threat intelligence on top of stateful inspection — it is a superset, not the precise answer to a question about state tracking.

213
MCQmedium

A company needs to provide secure remote access for employees working from home. The security team wants to ensure the solution provides strong authentication and encryption, and supports a wide range of client devices without requiring proprietary software. Which technology should they implement?

A.Secure Shell (SSH) tunneling
B.Remote Desktop Protocol (RDP) with TLS
C.IPsec VPN with IKEv2
D.File Transfer Protocol Secure (FTPS)
AnswerC

IKEv2 is a robust VPN protocol that supports strong encryption and authentication, and is widely supported on many devices including mobile platforms. It can be used with various authentication methods such as certificates, EAP, and pre-shared keys. It does not require proprietary software, as it is built into most modern operating systems. Therefore, it meets the requirements for secure remote access with broad compatibility.

Why this answer

IKEv2 is a modern VPN protocol that offers strong security and is widely supported across devices without proprietary clients. It supports various authentication methods and is efficient in reconnecting after network changes, making it ideal for mobile workers. The other options are either not full VPN solutions or are limited in scope.

Therefore, IKEv2 IPsec VPN is the correct choice.

Exam trap

The trap here is assuming that any encrypted remote access method, such as SSH or RDP, provides the same level of network access and security as a full VPN solution.

214
MCQhard

During a post-incident review, the incident response team identifies that the mean time to detect (MTTD) was 14 days. Which improvement would most directly reduce MTTD?

A.Implementing stricter access control policies
B.Conducting more frequent tabletop exercises
C.Deploying additional endpoint detection and response (EDR) sensors with automated alerting
D.Increasing the frequency of full system backups
AnswerC

EDR sensors with automated alerting detect malicious endpoint behaviour in near real time, collapsing the 14-day detection gap. Faster telemetry and alert generation directly shorten the time between compromise and discovery, which is precisely what MTTD measures.

Why this answer

Deploying additional EDR sensors with automated alerting directly reduces the time between an incident's occurrence and its detection by providing continuous monitoring and immediate notification of suspicious activities. This shortens the MTTD because automated alerts eliminate the delay inherent in manual log review or periodic checks, enabling the incident response team to react within minutes rather than days.

Exam trap

The trap here is that candidates often confuse detection speed (MTTD) with prevention or recovery metrics, mistakenly thinking that improving backups (Option D) or access controls (Option A) will help detect incidents faster, when in fact they address different phases of the incident response lifecycle.

How to eliminate wrong answers

Option A is wrong because stricter access control policies primarily reduce the likelihood of an incident (prevention) or limit the blast radius, but they do not improve detection speed; MTTD is a detection metric, not a prevention or containment metric. Option B is wrong because tabletop exercises improve team preparedness and response procedures, but they do not directly affect the speed of detecting real incidents; they focus on reaction and coordination after detection, not on reducing detection latency. Option D is wrong because increasing the frequency of full system backups improves data recovery capabilities and reduces recovery time objectives (RTO), but backups do not provide real-time visibility into ongoing malicious activity and thus have no direct impact on MTTD.

215
MCQmedium

A security engineer is reviewing a network architecture that uses IPsec in tunnel mode between two site gateways. The engineer must verify that the design provides confidentiality for the entire original IP packet. Which component of the IPsec architecture is responsible for encrypting the payload and providing confidentiality?

A.Encapsulating Security Payload (ESP)
B.Security Association (SA)
C.Internet Key Exchange (IKE)
D.Authentication Header (AH)
AnswerA

ESP is the IPsec component that provides confidentiality by encrypting the payload. In tunnel mode, ESP encrypts the entire original IP packet and encapsulates it within a new IP packet. Thus, it meets the requirement to protect the original packet's contents from eavesdropping.

Why this answer

In IPsec, ESP is the protocol that provides confidentiality by encrypting the payload. In tunnel mode, it encrypts the entire original IP packet, ensuring that the contents are protected. AH only provides integrity and authentication without encryption, while IKE and SAs are supporting components that establish and define security parameters but do not perform encryption.

Exam trap

The trap here is assuming that AH provides encryption because it is part of IPsec, but AH only offers integrity and authentication, not confidentiality.

216
MCQmedium

An attacker sends a flood of DHCP request packets with spoofed MAC addresses to exhaust the DHCP server's IP address pool, preventing legitimate clients from obtaining IP addresses. This attack is known as:

A.ARP poisoning
B.MAC flooding
C.DHCP starvation
D.DHCP spoofing
AnswerC

DHCP starvation exhausts the server's address pool by flooding it with requests bearing spoofed MAC addresses, so no leases remain for legitimate clients. This matches the stem's constraint exactly: pool exhaustion via forged MAC addresses denying address assignment. Rogue DHCP servers and scope tampering describe different attacks, not pool depletion.

Why this answer

DHCP starvation exhausts the IP pool by sending many fake DHCP requests, leading to denial of service.

217
MCQmedium

Which wireless security standard introduced the Simultaneous Authentication of Equals (SAE) handshake to replace the pre-shared key (PSK) method?

A.802.11i
B.WEP
C.WPA3
D.WPA2
AnswerC

WPA3 introduced SAE, a dragonfly-based handshake providing forward secrecy and resisting offline dictionary attacks that PSK's four-way handshake permitted. SAE replaces the pre-shared key exchange while remaining compatible with password-based authentication, satisfying the requirement for a PSK replacement.

Why this answer

WPA3 replaced WPA2's PSK with SAE, which provides forward secrecy and is resistant to offline dictionary attacks.

218
Multi-Selecthard

Which THREE of the following are best practices for securely managing cryptographic keys in an enterprise environment?

Select 3 answers
A.Use the same key for encryption and decryption (symmetric) and also for signing.
B.Share keys via email encrypted with the recipient's public key.
C.Implement key escrow to allow recovery of encrypted data.
D.Rotate keys on a regular schedule or upon compromise.
E.Store keys in a hardware security module (HSM).
AnswersC, D, E

Key escrow stores a protected copy of decryption keys with a trusted third party or secure repository. If the original key is lost or an administrator departs, encrypted data remains recoverable, satisfying the enterprise requirement for continuity of access to encrypted information.

Why this answer

Option C is correct because key escrow provides a controlled recovery mechanism so that encrypted data remains accessible if the original key is lost or an authorized party leaves, which is a recognized enterprise best practice for business continuity. Option D is correct because regular key rotation limits the amount of data protected by any single key and reduces the impact of an undetected compromise, while immediate rotation upon suspected compromise is essential to contain exposure. Option E is correct because an HSM is a tamper-resistant hardware device that generates, stores, and performs cryptographic operations with keys in a protected boundary, preventing key extraction and satisfying strong key-protection requirements.

Option A is wrong because key separation is required: a symmetric key used for encryption/decryption should not also be used for signing, since reusing one key across different cryptographic purposes weakens security. Option B is wrong because emailing keys, even encrypted to the recipient's public key, exposes them to mail-server storage, forwarding, and endpoint compromise; keys should be distributed through secure out-of-band or automated key-management channels.

219
MCQmedium

A Linux administrator needs to configure access controls so that a specific user can run certain commands with root privileges without entering a password. Which configuration file should be modified?

A./etc/shadow
B./etc/passwd
C./etc/sudoers
D./etc/security/limits.conf
AnswerC

Editing /etc/sudoers lets you grant the named user targeted command privileges via a NOPASSWD entry, satisfying the passwordless requirement. The sudoers file maps users to permitted commands and their authentication rules, unlike /etc/passwd or /etc/shadow, which hold account and password data rather than privilege-escalation policy.

Why this answer

The /etc/sudoers file defines which users or groups may run which commands as root (or other users), and supports the NOPASSWD tag to allow passwordless execution. Editing it with visudo ensures syntax validation and prevents concurrent-edit corruption. This is the standard mechanism for granting granular, password-free privilege escalation on Linux.

Exam trap

SSCP often tests the misconception that /etc/passwd or /etc/shadow control command privileges — candidates must remember that sudoers is the sole file governing delegated command execution, and that visudo is the safe editing tool.

How to eliminate wrong answers

Option A (/etc/shadow) is wrong because it stores hashed user passwords and aging information — it has nothing to do with command-level privilege delegation. Option B (/etc/passwd) is wrong because it holds basic account attributes (UID, GID, home directory, shell) and does not control sudo command permissions. Option D (/etc/security/limits.conf) is wrong because it enforces resource limits (e.g., max open files, CPU time) via PAM, not command execution privileges.

220
MCQeasy

An organization wants to prevent unauthorized persons from entering a secure server room. Which control is the MOST effective?

A.Install a CCTV camera at the entrance
B.Require biometric authentication (fingerprint or retina scan) to unlock the door
C.Post a security guard at the entrance during business hours
D.Use a keypad with a unique code for each employee
AnswerB

Biometric authentication binds door access to a unique physical trait, satisfying the requirement to prevent unauthorised entry because fingerprints and retina patterns cannot be shared, guessed or borrowed like tokens. Unlike keypads or badges, it resists credential theft and tailgating-assisted impersonation, making it the strongest single-factor physical control for restricting server room access.

Why this answer

Biometric authentication (fingerprint or retina scan) is the most effective control because it verifies the unique physiological characteristics of an individual, making it extremely difficult to bypass, share, or forge. Unlike knowledge-based (keypad code) or possession-based (key card) factors, biometrics provide strong, non-repudiable proof of identity, which is critical for high-security areas like a server room.

Exam trap

The trap here is that candidates often choose a keypad with a unique code (Option D) thinking it is 'unique per employee' and therefore secure, but they overlook that codes can be easily shared or stolen via shoulder surfing, whereas biometrics are inherently tied to the individual and cannot be transferred.

How to eliminate wrong answers

Option A is wrong because a CCTV camera is a detective control that only records events; it does not prevent unauthorized entry, as it cannot stop a person from walking through the door. Option C is wrong because a security guard is a physical control that can be effective but is limited to business hours, leaving the server room vulnerable during off-hours, and guards can be distracted or bypassed. Option D is wrong because a keypad with a unique code relies on a knowledge factor that can be shared, observed (shoulder surfing), or guessed, and codes can be forgotten or written down, compromising security.

221
MCQeasy

An organization wants to ensure that only authorized devices can connect to its internal network. Which of the following should be implemented?

A.Intrusion detection system
B.Port security on switches
C.Network access control (NAC)
D.Virtual private network
AnswerC

Network access control enforces endpoint compliance and identity checks before granting a device access to the internal network, blocking unauthorised devices at the connection point. This directly satisfies the requirement that only authorised devices connect.

Why this answer

Network Access Control (NAC) is the correct choice because it enforces security policy by evaluating the identity, posture, and compliance of devices before granting network access. NAC solutions (e.g., Cisco ISE, Aruba ClearPass) can authenticate devices via 802.1X, check for antivirus updates or patch levels, and quarantine non-compliant endpoints, ensuring only authorized and healthy devices connect to the internal network.

Exam trap

The trap here is that candidates often confuse Port Security (a Layer 2 MAC-based control) with NAC, but Port Security lacks the authentication, posture assessment, and dynamic policy enforcement that NAC provides, making it insufficient for ensuring only authorized devices connect.

How to eliminate wrong answers

Option A is wrong because an Intrusion Detection System (IDS) monitors network traffic for malicious activity but does not control which devices can connect; it only alerts on threats after they appear. Option B is wrong because Port Security on switches limits MAC addresses per port but is a Layer 2 control that can be bypassed by MAC spoofing and does not authenticate device identity or check compliance. Option D is wrong because a Virtual Private Network (VPN) encrypts traffic between remote users and the network but does not restrict which devices can connect to the internal LAN; it assumes the device is already authorized or uses separate authentication.

222
MCQmedium

An organization is experiencing VM sprawl, with many unmanaged virtual machines running in the environment. Which of the following is the most significant security risk associated with VM sprawl?

A.Unpatched and misconfigured VMs
B.License compliance violations
C.Increased power consumption and cooling costs
D.VM escape attacks from older hypervisors
AnswerA

Unmanaged VMs are often forgotten, leading to security gaps.

Why this answer

Unmanaged VMs often lack proper patching and configuration management, leading to unpatched vulnerabilities that can be exploited.

223
MCQeasy

An e-commerce company runs its web application on a Windows Server 2019 with IIS 10. The security team runs a vulnerability scan and discovers that the server supports TLS 1.0 and several CBC-mode cipher suites, which are prohibited by the company's security policy. The policy requires disabling all versions of TLS below 1.2 and all cipher suites that do not use GCM mode. The administrator needs to implement the required changes without affecting the application's functionality, as it still needs to support a small number of legacy clients that require TLS 1.2 but not CBC. Which action should the administrator take?

A.Upgrade the server to Windows Server 2022, which automatically disables TLS 1.0.
B.Implement a reverse proxy with strong TLS configuration and route all traffic through it.
C.Disable TLS 1.0 via the registry and configure the cipher suite order in IIS to prefer GCM-based ciphers.
D.Apply a hotfix from Microsoft that removes TLS 1.0 support.
AnswerC

This directly implements the policy and only affects prohibited protocols and ciphers.

Why this answer

The administrator can disable TLS 1.0 via the Windows registry (e.g., by creating the 'Enabled' DWORD under 'HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Server' and setting it to 0) and then configure the cipher suite order in IIS using the 'SchUseStrongCrypto' registry key or the 'Cipher Suites' group policy to prioritize GCM-based ciphers (e.g., TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256). This directly enforces the policy—disabling TLS below 1.2 and non-GCM ciphers—while still allowing legacy clients that support TLS 1.2 with GCM to connect without breaking functionality.

Exam trap

The trap here is that candidates may assume a reverse proxy or an OS upgrade is required to enforce strong TLS settings, when in fact Windows Server 2019 fully supports disabling TLS 1.0 and configuring cipher suites natively through registry and IIS settings without additional hardware or software.

How to eliminate wrong answers

Option A is wrong because upgrading to Windows Server 2022 does not automatically disable TLS 1.0; it only changes default settings, and TLS 1.0 can still be enabled unless explicitly disabled via registry or group policy. Option B is wrong because implementing a reverse proxy adds unnecessary complexity and a potential single point of failure; the policy can be met directly on the IIS server without an additional component, and the question asks for an action the administrator should take, not a workaround. Option D is wrong because there is no Microsoft hotfix that removes TLS 1.0 support; TLS 1.0 is a protocol supported by the Schannel security package and is disabled only through registry configuration, not a hotfix.

224
MCQmedium

A company uses a backup strategy that backs up all data every Sunday and backs up only data that has changed since the last full backup on other days. This is an example of which backup type?

A.Full backup
B.Differential backup
C.Copy backup
D.Incremental backup
AnswerB

Differential backups copy every change made since the last full backup, so Sunday's full plus each day's cumulative changes matches this description. Incremental backups would capture only changes since the previous backup, which the stem explicitly excludes.

Why this answer

The described strategy backs up all data on Sunday (a full backup) and then on other days backs up only data that has changed since the last full backup. This is the defining characteristic of a differential backup: it always references the most recent full backup, not the previous day's backup. Unlike incremental backups, differential backups do not reset the archive bit after each run, so each differential backup grows in size until the next full backup.

Exam trap

The trap here is confusing 'changed since the last full backup' (differential) with 'changed since the last backup' (incremental), causing candidates to mistakenly select incremental backup when the key phrase 'since the last full backup' clearly indicates differential.

How to eliminate wrong answers

Option A is wrong because a full backup backs up all data every time, not just on Sundays with changes-only on other days. Option C is wrong because a copy backup backs up selected files without clearing the archive bit, but it does not follow a schedule of full-then-changes-only; it is a one-off copy. Option D is wrong because an incremental backup backs up only data changed since the last backup (full or incremental), not since the last full backup; it resets the archive bit after each run, resulting in smaller daily backups that require all previous incrementals to restore.

225
MCQeasy

A security administrator is implementing a defense-in-depth strategy for a new data center. Which of the following BEST describes the role of security awareness training within this strategy?

A.It enforces mandatory vacation policies to detect fraud.
B.It encrypts sensitive data at rest and in transit.
C.It reduces the likelihood of successful social engineering attacks by educating users.
D.It provides a technical control that blocks malware from executing on endpoints.
AnswerC

Security awareness training educates users about phishing, pretexting, and other social engineering tactics, making them less likely to fall victim. This directly reduces the risk of human-based attacks, which are a common initial access vector. It is a key administrative control in defense-in-depth.

Why this answer

Security awareness training is an administrative control that educates users on recognizing and avoiding social engineering attacks, thereby reducing the likelihood of successful phishing or pretexting attempts. It complements technical controls like firewalls and antivirus, forming a layer of defense that addresses the human element.

Exam trap

The trap here is confusing administrative controls like training with technical controls like encryption or malware blocking; training changes user behavior, not system behavior.

Page 2

Page 3 of 13

Page 4