Courseiva

Systems Security Certified Practitioner SSCP (SSCP) — Questions 226–300

971 questions total · 13pages · All types, answers revealed

Page 3

Page 4 of 13

Page 5
226
MCQeasy

A small accounting firm wants to ensure that if a laptop is lost, the data on its full-disk-encrypted drive cannot be recovered by an attacker who removes the drive and mounts it elsewhere. Which additional control is MOST important to meet this goal?

A.Install endpoint detection and response software on the laptop.
B.Enable a screen saver that locks the console after ten minutes of inactivity.
C.Enforce automatic backup of user documents to a cloud file-sharing service.
D.Configure a strong pre-boot authentication password or PIN that is not stored on the disk.
AnswerD

Full-disk encryption with a key protector that requires a secret known only to the user means the volume encryption key cannot be unwrapped without that secret. An attacker who extracts the drive still lacks the input needed to decrypt, so pre-boot authentication is the control that converts encryption at rest into meaningful protection for a lost device.

Why this answer

Encryption at rest only protects a lost device when the key is protected by a secret the attacker does not possess. Requiring pre-boot authentication with a PIN or password ensures the volume master key cannot be unwrapped offline, whereas screen locks, EDR, and backups operate on different threat models and cannot prevent offline decryption of a removed drive.

Exam trap

The trap here is assuming that enabling full-disk encryption by itself protects a stolen drive, when the protection depends entirely on how the encryption key is protected.

227
Multi-Selectmedium

Which TWO actions are part of the containment phase of incident response?

Select 2 answers
A.Restoring from backups
B.Analyzing root cause
C.Applying temporary patches
D.Isolating affected systems
E.Preserving evidence
AnswersC, D

Temporary patches close the exploited vulnerability on production systems, halting ongoing compromise without full remediation. This satisfies containment by stopping the attack's spread, whereas permanent patching belongs to eradication once the threat is fully removed.

Why this answer

During the containment phase of incident response, the immediate priority is to stop the incident from spreading or causing further damage. Applying temporary patches (C) can quickly close a vulnerability that is being exploited, while isolating affected systems (D) prevents lateral movement and further compromise. Both actions are short-term measures to contain the threat before eradication and recovery begin.

Exam trap

ISC2 often tests the distinction between containment actions (immediate stop-gap measures) and recovery or analysis actions, so candidates mistakenly select 'restoring from backups' or 'analyzing root cause' as containment steps.

228
MCQmedium

A security analyst is reviewing access controls for a database server. The database administrator has granted all users in the 'sales' role SELECT, INSERT, UPDATE, and DELETE permissions on the 'orders' table. Which access control principle is being violated?

A.Accountability
B.Separation of duties
C.Need to know
D.Least privilege
AnswerD

Granting every sales user full SELECT, INSERT, UPDATE and DELETE rights on orders exceeds what each user needs to perform their role. Least privilege requires only the minimum permissions necessary, so this blanket grant violates that principle as the stem describes.

Why this answer

Granting every user in the 'sales' role full SELECT, INSERT, UPDATE, and DELETE on the orders table violates least privilege, which requires granting only the minimum permissions needed for each user's job function. Most sales users likely need only SELECT (or limited INSERT), not DELETE or UPDATE. Broad role-wide grants exceed what any individual requires.

Exam trap

The trap is confusing least privilege with need to know — both are access principles, but least privilege is about the minimum permissions (CRUD scope) while need to know is about the minimum data (record/field scope).

How to eliminate wrong answers

Option A is wrong because accountability concerns traceability of actions to individuals (logging, unique IDs), not the scope of permissions granted. Option B is wrong because separation of duties requires splitting sensitive tasks among different people (e.g., one person creates a vendor, another approves payment) — it is not violated merely by over-granting permissions to a single role. Option C is wrong because need to know is closely related but typically applies to data classification and information access on a per-record basis; the more precise control principle violated by granting excessive CRUD permissions is least privilege.

229
Multi-Selectmedium

A security administrator is selecting security metrics for the organization. Which TWO metrics are most useful for measuring the effectiveness of patching? (Select TWO)

Select 2 answers
A.Help desk ticket volume
B.Number of security incidents
C.Average time to patch critical vulnerabilities
D.Number of users trained
E.Patch compliance rate
AnswersC, E

Average time to patch critical vulnerabilities directly quantifies remediation speed, the core objective of a patching programme. It satisfies the stem's effectiveness requirement by measuring elapsed duration from vulnerability disclosure to deployed fix, exposing process delays that raw patch counts conceal. Shorter averages indicate a responsive, well-functioning patch management capability.

Why this answer

Option C, average time to patch critical vulnerabilities, is correct because it directly measures the speed of the remediation process, showing how quickly the organization closes exposure windows for high-risk flaws. Option E, patch compliance rate, is correct because it quantifies the percentage of systems that have the required patches applied, directly reflecting how thoroughly patching is executed across the estate. Together these two metrics capture both timeliness and coverage, which are the core dimensions of patching effectiveness.

The unmarked options do not belong: help desk ticket volume (A) is a workload indicator that may be unrelated to patching, number of security incidents (B) is an outcome measure influenced by many controls beyond patching, and number of users trained (D) measures awareness activity rather than patch deployment performance.

Exam trap

The trap here is that candidates often confuse 'number of security incidents' (a reactive, outcome-based metric) with a proactive patching metric, or they mistakenly think 'help desk ticket volume' reflects patching problems rather than user support load.

230
MCQeasy

After a security incident, an organization's legal team requests documentation that shows who had possession of a hard drive at every point from seizure to analysis. Which document should the incident responder provide?

A.Vulnerability assessment report
B.Incident response plan
C.Forensic imaging log
D.Chain of custody form
AnswerD

A chain of custody form records the chronological history of evidence, including who collected it, when, and every transfer of possession. It ensures evidence integrity and admissibility in legal proceedings. The legal team's request for documentation of possession at every point directly matches the purpose of a chain of custody form, making it the correct answer.

Why this answer

A chain of custody form is the formal record that documents the seizure, transfer, and analysis of evidence. It includes dates, times, names, and signatures of everyone who handled the evidence. This ensures that evidence has not been tampered with and is admissible in court.

The legal team's request for possession history is precisely what a chain of custody form provides, so it is the correct document.

Exam trap

The trap here is assuming that any forensic documentation, like an imaging log, satisfies a chain of custody request, when only a chain of custody form tracks every transfer of possession.

231
MCQmedium

A network engineer is implementing a secure network design that requires separating the network into multiple segments to limit the scope of a potential breach. The engineer wants to ensure that even if one segment is compromised, the attacker cannot easily move laterally to other segments. Which of the following technologies should be implemented to achieve this?

A.Network Address Translation (NAT)
B.VLAN segmentation with ACLs
C.Demilitarized zone (DMZ)
D.Virtual Private Network (VPN)
AnswerB

VLANs logically separate network traffic at Layer 2, and ACLs on routers or Layer 3 switches can control traffic between VLANs. This creates distinct security zones and restricts lateral movement. If one VLAN is compromised, the attacker cannot freely access other VLANs without passing through the ACLs. This provides a strong segmentation strategy that meets the requirement. Therefore, VLAN segmentation with ACLs is the correct choice.

Why this answer

VLAN segmentation combined with ACLs allows the network to be divided into isolated logical segments with controlled traffic between them. This limits lateral movement because an attacker in one VLAN cannot access other VLANs without passing through the ACLs, which can be configured to deny unauthorized traffic. Other options like NAT, DMZ, and VPN do not provide the same level of internal segmentation and access control.

Exam trap

The trap here is assuming that any security technology that separates networks, such as a DMZ, provides the same internal segmentation as VLANs with ACLs.

232
Multi-Selectmedium

Which THREE of the following are valid methods for authenticating users in a web application? (Choose three.)

Select 3 answers
A.IP address whitelisting
B.SAML
C.OAuth 2.0
D.HTTP Basic Authentication
E.LDAP
AnswersB, C, D

SAML enables single sign-on across domains.

Why this answer

SAML (Security Assertion Markup Language) is a valid method for authenticating users in a web application because it is an XML-based open standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP). It enables single sign-on (SSO) by allowing the SP to trust the IdP's assertion of the user's identity, making it a widely adopted federated authentication protocol.

Exam trap

ISC2 often tests the distinction between authentication and authorization or access control, leading candidates to mistakenly select IP whitelisting (a network-layer access control) as an authentication method, or LDAP (a directory protocol) as a direct authentication protocol rather than a backend service.

233
Multi-Selectmedium

A company is designing a network with multiple security zones. Which TWO of the following are best practices for network segmentation? (Select TWO)

Select 2 answers
A.Place a firewall between each security zone to enforce traffic filtering.
B.Use a single flat network to reduce complexity.
C.Implement VLANs to logically separate traffic within a switch.
D.Disable logging on inter-zone firewalls to improve performance.
E.Place all servers in the same broadcast domain for easier management.
AnswersA, C

Placing a firewall between each zone enforces traffic filtering at every boundary, satisfying the segmentation requirement by preventing unrestricted lateral movement. Inter-zone traffic is inspected and permitted only per policy, containing breaches within a single zone.

Why this answer

Option A is correct because placing a firewall between each security zone enforces traffic filtering and access control at zone boundaries, which is the core principle of defense-in-depth segmentation — inter-zone traffic should be inspected and permitted only per policy rather than flowing freely. Option C is correct because VLANs (IEEE 802.1Q) logically separate traffic at Layer 2 within a switch, limiting broadcast domains and isolating hosts even when they share physical infrastructure, which is a standard segmentation technique. Option B is wrong because a single flat network removes all segmentation boundaries, allowing unrestricted lateral movement and broadcast propagation.

Option D is wrong because disabling logging on inter-zone firewalls destroys the audit trail and visibility needed to detect and investigate policy violations. Option E is wrong because putting all servers in one broadcast domain increases attack surface and broadcast traffic, directly contradicting segmentation best practices.

Exam trap

The trap here is confusing 'reducing complexity' with security best practice — flat networks are simpler but insecure, and candidates may pick them under time pressure.

234
MCQeasy

Which of the following is the correct order of steps in the change management process?

A.Change request, impact assessment, CAB approval, testing, implementation, post-implementation review
B.Change request, CAB approval, impact assessment, testing, implementation, post-implementation review
C.Impact assessment, change request, CAB approval, testing, implementation, post-implementation review
D.Change request, testing, impact assessment, CAB approval, implementation, post-implementation review
AnswerA

The sequence begins with a formal change request, followed by impact assessment, approval from the change advisory board, testing, implementation, and finally a post-implementation review to confirm the change achieved its objective without adverse effects.

Why this answer

The standard change management lifecycle begins with a formal change request, followed by an impact/risk assessment so the CAB has the information needed to evaluate the change. Only after that assessment does the CAB approve or reject, then testing occurs in a non-production environment, then implementation, and finally a post-implementation review to confirm success and capture lessons learned. This sequence ensures decisions are made with full information and that changes are validated before touching production.

Exam trap

The trap is that candidates reorder CAB approval before impact assessment because approval 'feels' like it should come early — but the CAB needs the impact assessment as its input, so assessment must precede approval.

How to eliminate wrong answers

Option B is wrong because it places CAB approval before impact assessment — the CAB cannot make an informed decision without first knowing the impact and risk, so this order is logically inverted. Option C is wrong because it starts with impact assessment before a change request exists; there is nothing to assess until the change has been formally requested and documented. Option D is wrong because it places testing before impact assessment and CAB approval — testing a change that has not been approved or risk-assessed wastes resources and bypasses governance.

235
MCQeasy

During which phase of the NIST SP 800-61 incident response lifecycle are lessons learned meetings conducted and metrics such as MTTD and MTTR tracked?

A.Containment, Eradication, and Recovery
B.Preparation
C.Detection and Analysis
D.Post-Incident Activity
AnswerD

Post-Incident Activity is the NIST SP 800-61 phase where the incident is reviewed after containment and recovery. Lessons learned meetings occur here, and metrics including MTTD and MTTR are tracked to improve future response. This directly satisfies the stem's requirement for the phase covering retrospective analysis and performance measurement.

Why this answer

The Post-Incident Activity phase (D) is where lessons learned meetings are conducted and metrics such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) are tracked. This phase focuses on reviewing the incident response process, identifying improvements, and documenting findings to enhance future response efforts, as defined in NIST SP 800-61 Revision 2.

Exam trap

ISC2 often tests the misconception that metrics like MTTD and MTTR are tracked during Detection and Analysis or Containment phases, but they are actually reviewed and analyzed only after the incident is resolved in the Post-Incident Activity phase.

How to eliminate wrong answers

Option A is wrong because Containment, Eradication, and Recovery focuses on stopping the incident, removing threats, and restoring operations, not on post-incident analysis or metric tracking. Option B is wrong because Preparation involves establishing policies, tools, and training before an incident occurs, not conducting lessons learned or tracking MTTD/MTTR after an incident. Option C is wrong because Detection and Analysis is the phase where incidents are identified and analyzed, but it does not include the retrospective review or metric collection that occurs in the Post-Incident Activity phase.

236
MCQmedium

A financial services firm runs a Security Information and Event Management (SIEM) platform that ingests Windows Security event logs, firewall syslog, and NetFlow records. The CISO asks the analyst to detect brute-force attacks against Active Directory domain accounts. Which approach should the analyst implement to achieve this goal?

A.Enable NetFlow export on the core router and alert when a single source IP generates more than 500 flows per minute to any internal subnet.
B.Configure a SIEM correlation rule that counts Windows Security Event ID 4625 per source IP within a rolling window and triggers when the threshold is exceeded.
C.Deploy an inline intrusion prevention system in front of the domain controllers and enable signatures for the SMB and LDAP protocols.
D.Create a SIEM rule that alerts whenever Windows Security Event ID 4624 is written to the domain controller's security log more than ten times per minute.
AnswerB

Event ID 4625 is generated on failed logon attempts and includes the source workstation and account name. Counting these events per source IP in a rolling window directly reveals repeated failed authentications characteristic of brute-force activity against Active Directory, which is exactly what the CISO requested in this scenario.

Why this answer

Failed logon events are the authoritative indicator of brute-force authentication activity, and Windows Security Event ID 4625 records each failed attempt with source and account details. Correlating these events per source IP over a rolling time window produces a high-fidelity alert while keeping false positives manageable. Flow data and successful logon events do not capture authentication failures, so they cannot satisfy the detection requirement.

Exam trap

The trap here is assuming that any high-volume network or authentication event indicates brute-force activity, when only repeated failed logon events (Event ID 4625) reveal it.

237
MCQmedium

A company is implementing a PKI for internal use. What is the primary purpose of a Certificate Revocation List (CRL)?

A.To validate certificate chains
B.To encrypt certificate requests
C.To store all issued certificates
D.To publish revoked certificates
AnswerD

A CRL is a signed, timestamped list issued by the certificate authority enumerating serial numbers of certificates revoked before their expiry. Validators check it during path validation so revoked certificates are rejected, satisfying the PKI requirement to publish revocation status.

Why this answer

The primary purpose of a Certificate Revocation List (CRL) is to publish a list of certificates that have been revoked by the Certificate Authority (CA) before their scheduled expiration. This allows relying parties to verify that a certificate is still valid and has not been compromised, ensuring trust in the PKI.

Exam trap

The trap here is that candidates confuse the CRL's purpose with certificate validation or storage, mistakenly thinking it validates chains or stores all certificates, when in fact it only publishes revoked certificates for status checking.

How to eliminate wrong answers

Option A is wrong because validating certificate chains is performed using the CA's public key and checking signatures, not by consulting a CRL; CRLs are used only to check revocation status. Option B is wrong because encrypting certificate requests is the role of protocols like PKCS#10 or CMP, not the CRL, which is a signed list of revoked certificates. Option C is wrong because storing all issued certificates is the function of a certificate repository or database, whereas a CRL only contains certificates that have been revoked, not all issued ones.

238
MCQeasy

A security analyst is reviewing vulnerability scan results and finds a critical vulnerability on a web server. The patch is available but requires a reboot. What should the analyst do first?

A.Apply the patch immediately to reduce risk
B.Assess the exploitability and impact to determine remediation priority
C.Re-scan the server to confirm the vulnerability
D.Ignore the vulnerability because the patch is available
AnswerB

Assessing exploitability and impact first satisfies the stem's constraint that the patch requires a reboot, which may disrupt services. This risk-based triage determines whether emergency remediation or a scheduled maintenance window is appropriate, rather than rebooting a production web server immediately.

Why this answer

The first step in vulnerability management is to assess the exploitability and business impact of the vulnerability before taking action. Even though a patch is available, the analyst must determine if the vulnerability is actively exploitable in the current environment and what the potential impact would be, as a reboot may cause service disruption. This aligns with the risk-based prioritization approach required by frameworks like NIST SP 800-40 and the SSCP's focus on balancing security with operational continuity.

Exam trap

ISC2 often tests the misconception that a critical vulnerability must be patched immediately regardless of operational impact, tempting candidates to choose 'apply the patch immediately' without considering the risk assessment and change management steps required by the SSCP's risk identification domain.

How to eliminate wrong answers

Option A is wrong because applying the patch immediately without assessing impact could cause unnecessary downtime or break dependencies, especially if the web server hosts critical applications; patching should follow a change management process. Option C is wrong because re-scanning to confirm the vulnerability is redundant—the scan already identified it, and the priority is to evaluate risk, not re-validate the scanner's findings. Option D is wrong because ignoring a critical vulnerability simply because a patch exists is negligent; the patch's availability is a reason to act, not to ignore, but action must be prioritized based on risk.

239
MCQhard

A security architect is reviewing cloud security for a SaaS application used by the company. According to the shared responsibility model, which security controls are PRIMARILY the customer's responsibility?

A.Data classification and user access management
B.Network infrastructure security
C.Physical security of data centers
D.Operating system patching
AnswerA

In SaaS, the provider secures the application, runtime and infrastructure, while the customer retains responsibility for its own data classification and managing which users may access that data. These controls sit above the provider's boundary, satisfying the stem's shared responsibility constraint.

Why this answer

In SaaS, the customer is responsible for data classification and managing user access (IAM).

240
MCQeasy

A security analyst is reviewing logs and notices that an application log shows an error message indicating 'unhandled exception' followed by a stack trace. This log is most likely categorized as which type?

A.System log
B.Security log
C.Audit log
D.Application log
AnswerD

An unhandled exception with a stack trace is generated by the application's own runtime error handling, so it belongs in the application log. Operating system, security and network logs record different event sources and would not capture this application-level failure.

Why this answer

Application logs are generated by software applications and record application-specific events, including errors like 'unhandled exception' and stack traces. Since the log entry originates from an application and contains a stack trace (a developer-oriented diagnostic), it is categorized as an application log, not a system, security, or audit log.

Exam trap

The trap here is that candidates confuse 'unhandled exception' with a security event (like a crash due to an exploit) and incorrectly select Security log, but the question explicitly states the log contains a stack trace, which is a hallmark of application-level debugging output, not a security or system event.

How to eliminate wrong answers

Option A is wrong because system logs (e.g., /var/log/syslog or Windows System event log) record OS-level events such as driver failures, kernel panics, or service start/stop, not application-specific unhandled exceptions with stack traces. Option B is wrong because security logs (e.g., Windows Security log or /var/log/auth.log) track authentication attempts, privilege use, and policy violations, not application runtime errors. Option C is wrong because audit logs (e.g., Windows Audit log or Linux auditd logs) record compliance-relevant events like file access or user actions per predefined audit policies, not unhandled exceptions from application code.

241
MCQmedium

A security analyst reviews the TLS configuration of a web server and notices that the cipher suite TLS_RSA_WITH_AES_128_CBC_SHA is enabled. The analyst recommends disabling RSA key exchange and enabling ECDHE. Which security property does ECDHE provide that RSA key exchange lacks?

A.ECDHE provides perfect forward secrecy.
B.ECDHE is faster than RSA key exchange.
C.ECDHE is required by PCI DSS for all web transactions.
D.ECDHE uses smaller key sizes for equivalent security.
AnswerA

ECDHE performs an ephemeral Diffie-Hellman exchange per session, so the session key is never derivable from the server's long-term private key. RSA key exchange encrypts the premaster secret with that static key, so recorded traffic can be decrypted retroactively if it leaks.

Why this answer

ECDHE (Elliptic Curve Diffie-Hellman Ephemeral) provides Perfect Forward Secrecy (PFS), meaning that if the server's long-term private key is compromised, past session keys cannot be derived. RSA key exchange does not provide PFS because the session key is encrypted with the server's static RSA public key; if the private key is later exposed, all recorded sessions can be decrypted.

Exam trap

The trap here is that candidates confuse the general benefits of elliptic curve cryptography (smaller keys, speed) with the specific security property of Perfect Forward Secrecy, which is the unique advantage of ephemeral Diffie-Hellman over static RSA key exchange.

How to eliminate wrong answers

Option B is wrong because ECDHE is not inherently faster than RSA key exchange; while ECDHE can have lower computational overhead in some contexts, performance depends on implementation and key sizes, and speed is not the primary security property. Option C is wrong because PCI DSS does not require ECDHE specifically; it requires the use of strong cryptography and may recommend PFS, but it does not mandate ECDHE for all web transactions. Option D is wrong because while ECDHE does use smaller key sizes for equivalent security compared to RSA, this is a property of elliptic curve cryptography in general, not the specific security property that RSA key exchange lacks—the key distinction is PFS.

242
Multi-Selecteasy

Which TWO of the following are key components of the risk identification process?

Select 2 answers
A.Identifying assets and their value
B.Prioritizing risks based on impact
C.Selecting risk treatment options
D.Identifying threats and vulnerabilities
E.Calculating the annualized loss expectancy
AnswersA, D

Identifying assets and their value underpins risk identification because threats and vulnerabilities only matter in relation to something worth protecting. Asset valuation establishes the impact baseline against which likelihood is assessed, directly satisfying the stem's requirement for a key component of the risk identification process.

Why this answer

Option A (Identifying assets and their value) is correct because risk identification must first establish what needs protection; you inventory assets (hardware, software, data, people, facilities) and assign value so that later risk analysis can gauge the potential impact of loss or compromise. Option D (Identifying threats and vulnerabilities) is correct because risk is fundamentally the combination of a threat exploiting a vulnerability against an asset, so enumerating plausible threats (e.g., malware, insider misuse, natural events) and weaknesses (e.g., unpatched software, weak access controls) is the core activity of risk identification. Option B (Prioritizing risks based on impact) belongs to risk analysis/evaluation, where identified risks are assessed and ranked, not to identification itself.

Option C (Selecting risk treatment options) is part of risk response/treatment planning (avoid, mitigate, transfer, accept), which occurs after risks are identified and evaluated. Option E (Calculating the annualized loss expectancy) is a quantitative risk analysis technique (ALE = SLE × ARO), so it follows identification rather than being a component of it.

Exam trap

ISC2 often tests the distinction between risk identification and risk analysis, so candidates mistakenly select options like prioritizing risks (B) or calculating ALE (E) as part of identification, when they actually belong to later stages of the risk management process.

243
Multi-Selectmedium

Which THREE are effective controls against internal network threats?

Select 3 answers
A.Network segmentation
B.Employee security awareness training
C.Intrusion detection system (IDS)
D.Single sign-on (SSO)
E.Data loss prevention (DLP)
AnswersA, B, E

Network segmentation divides the internal network into isolated zones, limiting lateral movement when an insider or compromised host attempts to reach other systems. This constrains internal threats by enforcing boundaries, directly satisfying the requirement for an effective control against internal network threats.

Why this answer

Network segmentation (A) is correct because dividing the internal network into isolated zones (e.g., VLANs, subnets, or microsegmentation) limits lateral movement, so a compromised host cannot freely reach other internal systems. Employee security awareness training (B) is correct because many internal threats—such as phishing, social engineering, and accidental data mishandling—originate from insiders, and trained users are a primary preventive control. Data loss prevention (DLP) (E) is correct because DLP tools inspect and block sensitive data (e.g., PII, credit card numbers) from leaving or being exfiltrated across endpoints, email, and network channels, directly mitigating insider data theft or leakage.

An IDS (C) is not among the correct answers because it is primarily a detective control that alerts on suspicious traffic rather than preventing internal threats. Single sign-on (D) is not among the correct answers because SSO is a convenience/authentication mechanism that centralizes access, and while it can aid auditing, it does not by itself control internal threats and can even widen exposure if credentials are compromised.

Exam trap

ISC2 often tests the distinction between detection and prevention, so candidates mistakenly choose IDS (C) as a control against internal threats, but it only detects, not blocks, unlike network segmentation or DLP which actively prevent or contain threats.

244
MCQmedium

A system administrator notices a high number of half-open TCP connections to the company's web server. The server is becoming unresponsive. Which attack is likely occurring, and which mitigation is effective?

A.ARP spoofing; mitigation: static ARP entries.
B.Smurf attack; mitigation: disable IP broadcasts.
C.SYN flood; mitigation: enable SYN cookies.
D.Ping of death; mitigation: block fragmented ICMP packets.
AnswerC

A SYN flood exhausts the connection table with half-open handshakes, matching the observed symptom. SYN cookies remove that state by encoding the handshake in the sequence number, so the server no longer allocates resources before completion.

Why this answer

A SYN flood attack exploits the TCP three-way handshake by sending many SYN packets with spoofed source addresses, leaving the server with numerous half-open connections that exhaust the backlog queue. Enabling SYN cookies allows the server to avoid allocating state until the handshake completes, mitigating the flood. This matches the symptom of high half-open TCP connections and an unresponsive web server.

Exam trap

SSCP often tests the mapping between attack symptoms and mitigations — candidates see 'half-open connections' and may incorrectly associate it with ICMP-based attacks like Smurf or Ping of Death instead of TCP SYN flooding.

How to eliminate wrong answers

Option A is wrong because ARP spoofing is a Layer 2 man-in-the-middle attack that does not produce half-open TCP connections; static ARP entries mitigate spoofing, not SYN floods. Option B is wrong because a Smurf attack uses ICMP echo requests to a broadcast address with a spoofed source, amplifying traffic — it does not create half-open TCP connections. Option D is wrong because a Ping of Death relies on oversized or malformed ICMP fragments to crash a host, not on TCP handshake exhaustion.

245
MCQmedium

A security administrator is reviewing the organization's backup strategy for a database server that must meet a recovery point objective (RPO) of 15 minutes. The server currently uses a full backup every Sunday and differential backups every night. The administrator finds that the current strategy cannot meet the RPO. Which backup method should the administrator implement to meet the RPO while minimizing backup storage consumption?

A.Differential backups every 15 minutes
B.Transaction log backups every 15 minutes
C.Full backups every 15 minutes
D.Snapshot backups every 15 minutes
AnswerB

Transaction log backups capture all committed transactions since the last log backup, enabling point-in-time recovery with an RPO as low as the backup interval. Scheduling them every 15 minutes directly meets the 15-minute RPO. They also consume far less storage than full backups because they contain only the log records, not the entire database.

Why this answer

Transaction log backups capture every committed transaction since the previous log backup, so a 15-minute schedule delivers an RPO of 15 minutes. They are also far more storage-efficient than full or differential backups because they contain only log records. This combination of frequent recovery points and low storage overhead makes them the correct choice for meeting the stated RPO.

Exam trap

The trap here is assuming that any frequent backup type satisfies an RPO, when only transaction log backups provide the granular, low-overhead recovery points required for a database with a 15-minute RPO.

246
MCQhard

During a code review, you discover that an application stores passwords in plaintext. What is the most secure remediation?

A.Hash passwords with MD5
B.Use bcrypt with a unique salt per password
C.Use AES encryption of passwords
D.Store passwords in a database with restricted access
AnswerB

Bcrypt applies an adaptive, deliberately slow hashing algorithm with a per-password salt, defeating rainbow tables and brute-force attacks. This directly satisfies the remediation requirement by replacing reversible plaintext storage with one-way, computationally expensive verification, ensuring a breach exposes no recoverable passwords.

Why this answer

Bcrypt with a unique salt is designed for password storage; it is slow and resistant to brute force. MD5 is fast and weak. AES encryption is reversible if the key is compromised.

Database access control does not protect if the database is breached.

247
MCQhard

A company runs containerized applications in a Kubernetes cluster. They need to ensure that containers run with the least privilege and cannot escalate privileges. Which configuration change is MOST effective?

A.Set the container to run as non-root user
B.Drop all Linux capabilities from the container
C.Mount the container root filesystem as read-only
D.Enable SELinux enforcing mode on the host
AnswerB

Dropping all Linux capabilities removes the kernel privileges a container could abuse, directly enforcing least privilege and blocking privilege escalation. This satisfies the stem's requirement that containers cannot escalate, unlike seccomp or read-only filesystems which restrict different attack surfaces.

Why this answer

Dropping all Linux capabilities is the most effective because capabilities are the granular privileges that allow a process to perform privileged operations (e.g., CAP_NET_ADMIN, CAP_SYS_ADMIN). Even a non-root user can escalate privileges if it retains capabilities. By dropping all capabilities, the container loses the ability to perform any privileged action, directly enforcing least privilege and preventing privilege escalation.

This is a fundamental Kubernetes securityContext setting that aligns with the principle of least privilege.

Exam trap

SSCP often tests the misconception that running as non-root is sufficient for least privilege, but the exam expects you to recognize that capabilities are the granular privileges that must be dropped to prevent escalation.

How to eliminate wrong answers

Option A is wrong because running as a non-root user alone does not remove capabilities; a non-root user can still have capabilities that allow privilege escalation (e.g., CAP_SETUID to become root). Option C is wrong because a read-only root filesystem prevents writes to the filesystem but does not restrict privileged operations; an attacker could still exploit capabilities or kernel vulnerabilities. Option D is wrong because SELinux enforcing mode on the host provides mandatory access control but does not directly limit the container's capabilities; it is a host-level control that may not be configured per-container and can be bypassed if the container has excessive capabilities.

248
MCQeasy

You are the security analyst at a mid-sized retail company with 500 employees. The company recently experienced a ransomware attack that encrypted files on a file server. The infection was traced to a phishing email opened by an employee in accounting. The company has antivirus software, a firewall, and daily backups. After the incident, management wants to improve risk identification to prevent future attacks. Which of the following is the MOST effective first step to improve risk identification?

A.Implement a data loss prevention (DLP) solution to monitor email traffic
B.Conduct a risk assessment that includes threat modeling and vulnerability scanning
C.Deploy a SIEM system to aggregate logs from all systems
D.Review the logs of the compromised file server for forensic details
AnswerB

A risk assessment combining threat modelling and vulnerability scanning systematically identifies weaknesses across people, process, and technology, satisfying management's goal of improving risk identification after the phishing-led ransomware incident rather than merely reacting to it.

Why this answer

A risk assessment with threat modeling and vulnerability scanning is the foundational, proactive step that identifies, quantifies, and prioritizes risks across the environment — including the phishing vector that caused this incident. Threat modeling maps attack paths (e.g., email → endpoint → file server), while vulnerability scanning surfaces unpatched systems and misconfigurations. Together they produce the risk register and treatment plan that all subsequent controls (DLP, SIEM) should be justified against.

Exam trap

The trap here is confusing reactive detection/response tools (SIEM, DLP, forensic log review) with the proactive risk-identification discipline the question asks for — candidates gravitate to the 'shiny' security product instead of the process step.

How to eliminate wrong answers

Option A is wrong because DLP is a preventive/detective control that addresses one specific data-loss channel and does nothing to systematically identify the broader risk landscape. Option C is wrong because a SIEM aggregates and correlates logs for detection and response — it is a monitoring tool, not a risk-identification methodology, and deploying it without a prior risk assessment means you don't know what to log or alert on. Option D is wrong because reviewing the compromised server's logs is reactive forensic analysis of a past event, not a forward-looking risk identification process.

249
MCQmedium

Refer to the exhibit. A user reports being unable to remote desktop (RDP) into a Windows server. Given the event log, what is the most likely cause?

A.The user does not have the 'Allow log on through Remote Desktop Services' user right
B.The user account is locked out
C.The server is not a member of the domain
D.The user's Kerberos ticket has expired
AnswerA

The event log records a logon-rights failure, meaning authentication succeeded but authorisation to establish an RDP session was denied. Granting the 'Allow log on through Remote Desktop Services' user right resolves this, unlike credential or network faults.

Why this answer

The event log shows an 'An account failed to log on' event (ID 4625) with a failure reason indicating 'The user has not been granted the requested logon type at this machine.' For Remote Desktop connections, the required logon type is 'Remote Interactive' (logon type 10). This specific error means the user lacks the 'Allow log on through Remote Desktop Services' user right, which is assigned via Local Security Policy or Group Policy. Without this right, the RDP session is denied at the authentication stage, even if the username and password are correct.

Exam trap

The trap here is that candidates often assume RDP failures are due to network issues, firewall rules, or account lockouts, when the event log's specific failure reason (logon type denial) directly points to a missing user right assignment.

How to eliminate wrong answers

Option B is wrong because a locked-out account would produce a different failure reason, such as 'Account locked out' (sub-status 0xC0000234), not a logon type denial. Option C is wrong because domain membership is not required for RDP; a standalone server can accept RDP connections if the user has local credentials and the appropriate user right. Option D is wrong because an expired Kerberos ticket would cause a specific Kerberos-related error (e.g., 0xC0000381 or 0xC000006D), not a logon type restriction, and Windows would typically fall back to NTLM if Kerberos fails.

250
Drag & Dropmedium

Drag and drop the steps for setting up a certificate authority (CA) in Windows Server into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Setting up a Certificate Authority on Windows Server involves installing the Active Directory Certificate Services role, then configuring the CA type (e.g., Enterprise Root CA), specifying storage locations for the certificate database and log files, completing the installation, and finally testing the CA by requesting a certificate. The steps must follow this order because each step depends on the previous one; for instance, you cannot configure the CA type before the role is installed, and storage settings are part of the configuration phase.

251
MCQhard

A security engineer is implementing a digital signature scheme to ensure non-repudiation. Which process correctly describes how a digital signature is created and verified?

A.Sign with private key, verify with public key
B.Sign with public key, verify with private key
C.Sign with symmetric key, verify with asymmetric key
D.Sign with hash, verify with private key
AnswerA

The signer hashes the message and encrypts that digest with their private key; the verifier decrypts it with the signer's public key and compares digests. Only the private-key holder could produce it, so this binds identity and delivers non-repudiation.

Why this answer

A digital signature is created by hashing the message and then encrypting that hash with the signer's private key. Verification is performed by decrypting the signature with the signer's public key and comparing the result to a freshly computed hash of the message. This asymmetric process ensures non-repudiation because only the private key holder could have created the signature, while anyone with the public key can verify it.

Exam trap

ISC2 often tests the misconception that the public key is used for signing because it is 'publicly available,' but the trap is that signing requires the private key to ensure only the claimed signer could have produced the signature.

How to eliminate wrong answers

Option B is wrong because signing with a public key would allow anyone to create a signature, destroying non-repudiation; the public key is used only for verification, not signing. Option C is wrong because symmetric keys are shared secrets and cannot provide non-repudiation—both parties could create the same signature, making it impossible to prove origin. Option D is wrong because signing with a hash is meaningless without a key; the hash is an intermediate step, and verification uses the public key, not the private key.

252
MCQmedium

An organization decides to outsource its data center operations to a cloud provider. The cloud provider is responsible for physical security and hardware maintenance. This is an example of which risk response strategy?

A.Risk acceptance
B.Risk transfer
C.Risk avoidance
D.Risk mitigation
AnswerB

Transferring data centre operations shifts physical security and hardware maintenance obligations to the cloud provider, moving that risk off the organisation's books via contract. This satisfies the stem's description precisely: the provider assumes responsibility, though residual accountability for data and compliance remains with the outsourcing organisation.

Why this answer

Risk transfer involves shifting the financial impact of a risk to a third party, typically through insurance or outsourcing. By outsourcing data center operations to a cloud provider, the organization transfers the risks associated with physical security and hardware maintenance to the provider, making this a classic example of risk transfer.

Exam trap

SSCP often tests the confusion between risk transfer and risk mitigation, so candidates must recognize that outsourcing to a cloud provider is a transfer of operational risk, not an internal mitigation.

How to eliminate wrong answers

Option A is wrong because risk acceptance means acknowledging the risk and taking no action to mitigate it, which is not the case here. Option C is wrong because risk avoidance means eliminating the activity that introduces the risk entirely, whereas here the organization still operates in the cloud. Option D is wrong because risk mitigation means reducing the likelihood or impact of a risk through controls, but the organization is shifting the risk to a third party rather than reducing it internally.

253
MCQeasy

A company implements a policy that requires all employees to change their passwords every 60 days. Which of the following is the PRIMARY security benefit of this requirement?

A.Ensuring compliance with data privacy laws.
B.Reducing the risk of password reuse across multiple sites.
C.Limiting the window of opportunity for a compromised password.
D.Simplifying the account lockout process.
AnswerC

A 60-day rotation shortens the period during which a stolen or cracked credential remains valid, so any compromise is usable only until the next change. This directly limits the exposure window, which is the primary benefit of enforced password ageing.

Why this answer

Password expiration policies limit the exposure window for compromised credentials. If an attacker obtains a password, the 60-day rotation ensures that the stolen credential becomes invalid after that period, reducing the time an attacker can maintain unauthorized access. This is a fundamental security control to mitigate the risk of undetected credential theft.

Exam trap

ISC2 often tests the distinction between a primary security benefit and a secondary compliance or administrative convenience; the trap here is that candidates see 'compliance' (Option A) and assume it is the main goal, but the actual security rationale is limiting the window of opportunity for a compromised password.

How to eliminate wrong answers

Option A is wrong because while password policies may help meet certain regulatory requirements (e.g., PCI DSS, HIPAA), the primary security benefit is not compliance itself—compliance is a secondary outcome, not the core security goal. Option B is wrong because password expiration does not directly prevent password reuse across different sites; that is addressed by password managers, unique password requirements, or blocklists, not rotation frequency. Option D is wrong because password expiration has no direct relationship with the account lockout process; lockout is triggered by failed login attempts, not password age.

254
MCQhard

During a post-implementation review of a change, it is discovered that the change introduced a configuration deviation from the baseline. The deviation was not detected during testing. What is the BEST way to prevent this in the future?

A.Increase the number of testers
B.Require CAB approval for all future changes
C.Implement automated configuration scanning in the staging environment
D.Use a different change management process
AnswerC

Automated configuration scanning in staging compares deployed settings against the approved baseline before production release, catching drift that functional testing misses. This satisfies the stem's constraint that the deviation escaped testing, because scanning detects configuration variance rather than relying on test cases.

Why this answer

Automated configuration scanning in the staging environment detects deviations from the baseline before production, catching issues that manual testing missed. This provides continuous, repeatable verification against the approved configuration baseline, which is the most reliable preventive control.

Exam trap

SSCP often tests preventive vs. detective controls — candidates pick CAB approval (governance) or more testers (manual) instead of automated configuration scanning, which is the actual technical preventive control.

How to eliminate wrong answers

Option A is wrong because adding testers increases manual effort but does not guarantee detection of configuration deviations — it is not a systematic control. Option B is wrong because CAB approval is a governance gate, not a technical detection mechanism; it does not verify configuration compliance. Option D is wrong because changing the change management process does not address the root cause (lack of automated configuration verification) and is vague.

255
Multi-Selecthard

A security consultant is reviewing an organization's identity and access management (IAM) architecture. The organization wants to implement a system where users can authenticate once and access multiple independent systems without re-entering credentials, while also enabling centralized session termination. Which TWO of the following are appropriate components or protocols to meet these requirements? (Choose two.)

Select 2 answers
A.Security Assertion Markup Language (SAML)
B.OAuth 2.0
C.Remote Authentication Dial-In User Service (RADIUS)
D.Lightweight Directory Access Protocol (LDAP)
E.OpenID Connect (OIDC)
AnswersA, E

SAML is an XML-based standard for exchanging authentication and authorization data between an identity provider and service providers. It enables single sign-on across independent systems and supports centralized session management through the identity provider. When a user authenticates once, SAML assertions can be used to access multiple service providers, and terminating the session at the identity provider can invalidate access.

Why this answer

SAML and OpenID Connect are both federation protocols that enable single sign-on across independent systems. SAML uses XML assertions, while OIDC uses JSON Web Tokens and builds on OAuth 2.0. Both support centralized session management, allowing an identity provider to terminate sessions.

OAuth 2.0 is for authorization, and RADIUS and LDAP are not designed for web-based SSO or centralized session termination.

Exam trap

The trap here is assuming that OAuth 2.0 provides authentication, when it is actually an authorization framework; OpenID Connect is the authentication layer built on top of it.

256
MCQmedium

A financial services company runs a customer-facing mobile banking API on Linux containers. A penetration test reveals that when the API receives an oversized JSON payload, the application returns a stack trace containing internal file paths and database connection strings. The developer wants to prevent this information disclosure without changing the API's core business logic. Which control should the security practitioner recommend FIRST?

A.Deploy a web application firewall in blocking mode with signatures for known stack trace patterns.
B.Configure the application to return generic error messages and log detailed exceptions server-side only.
C.Increase the maximum allowed request body size in the API gateway to reject oversized payloads.
D.Enable full verbose logging in the API and ship logs to a centralized SIEM for alerting.
AnswerB

Generic client-facing errors with detailed server-side logging prevent attackers from learning internal file paths and connection strings while preserving diagnostic data for developers. This directly addresses the information disclosure observed in the stack trace without altering business logic. It is a standard secure coding practice aligned with SSCP guidance on error handling and preventing sensitive data exposure in application responses.

Why this answer

The core issue is an information disclosure vulnerability caused by improper error handling. Returning generic messages to clients while logging details internally removes the sensitive data from the response path and preserves troubleshooting capability. WAFs and logging are useful compensating or detective controls, but they do not eliminate the root cause, which is the application revealing internal implementation details.

Exam trap

The trap here is assuming that a perimeter control such as a WAF or expanded logging eliminates the disclosure, when the flaw actually lives in how the application constructs its error responses.

257
MCQeasy

Which protocol is used for secure web browsing and operates on TCP port 443?

A.HTTPS
B.HTTP
C.SSH
D.FTP
AnswerA

HTTPS wraps HTTP inside TLS, encrypting web traffic and authenticating the server, and by convention listens on TCP port 443. That combination delivers the confidentiality and integrity required for secure browsing over the specified port.

Why this answer

HTTPS (HTTP over TLS) uses TCP port 443 and provides encrypted communication for websites.

258
MCQmedium

A security analyst discovers that an attacker has set up a fake wireless access point with the same SSID as the corporate network. Users are unknowingly connecting to it. What is this attack called?

A.KRACK
B.Rogue AP
C.Evil twin
D.PMKID attack
AnswerC

An evil twin is a rogue access point broadcasting the same SSID as the legitimate corporate network, often with a stronger signal, luring users into connecting so the attacker can intercept their traffic. This matches the stem's fake access point scenario exactly.

Why this answer

An evil twin is a rogue access point that impersonates a legitimate AP by broadcasting the same SSID (and often cloning the BSSID and security settings) to trick users into associating with it. Because clients auto-connect to known SSIDs, the attacker can harvest credentials, perform on-path (MITM) interception, or serve captive-portal phishing pages. The distinguishing feature is the deliberate imitation of a trusted network, which is exactly what the scenario describes.

Exam trap

The trap here is confusing the broad category 'rogue AP' with the specific impersonation attack 'evil twin' — the exam expects you to recognize that the matching SSID and user deception are the differentiators.

How to eliminate wrong answers

Option A is wrong because KRACK (Key Reinstallation Attack, CVE-2017-13077 and related) exploits the WPA2 4-way handshake to force nonce reuse and decrypt traffic — it does not involve standing up a fake AP with a matching SSID. Option B is wrong because 'rogue AP' is the broader umbrella term for any unauthorized AP on the network (e.g., an employee's personal hotspot); it does not specifically require spoofing a legitimate SSID to lure victims, which is the defining trait of the evil twin. Option D is wrong because a PMKID attack captures the PMKID from the RSN IE of the first EAPOL message to crack WPA2/WPA3 passphrases offline — it is a credential-cracking technique, not an AP impersonation attack.

259
MCQmedium

During a vulnerability scan, a security analyst discovers that several workstations are missing critical security patches. The organization decides to implement a compensating control by restricting network access to these workstations until patches are applied. Which risk response strategy is being used?

A.Avoidance
B.Mitigation
C.Transfer
D.Acceptance
AnswerB

Mitigation reduces risk likelihood or impact through controls, and restricting network access to unpatched workstations does exactly that by shrinking their exposure while patching is pending. It satisfies the stem's compensating-control constraint, since the underlying vulnerability remains until patches are applied, but the residual risk is lowered.

Why this answer

Restricting network access to vulnerable workstations reduces the likelihood of exploitation by limiting their exposure to potential threats. This is a classic mitigation strategy because it does not eliminate the vulnerability (missing patches) but instead implements a compensating control to reduce the risk to an acceptable level until the patches can be applied. Mitigation focuses on reducing the impact or probability of a risk event, which is exactly what network access restrictions achieve.

Exam trap

The trap here is that candidates often confuse 'mitigation' with 'avoidance' because both involve taking action, but mitigation reduces risk without eliminating the root cause, while avoidance removes the risk entirely by eliminating the activity or asset.

How to eliminate wrong answers

Option A is wrong because avoidance would require eliminating the vulnerability entirely (e.g., removing the workstations from the network permanently or replacing them), not just restricting access temporarily. Option C is wrong because transfer would involve shifting the risk to a third party (e.g., purchasing cyber insurance or outsourcing patch management), which is not happening here. Option D is wrong because acceptance would mean acknowledging the risk and taking no action, whereas the organization is actively implementing a compensating control to reduce risk.

260
MCQeasy

A small business wants to implement single sign-on so employees can authenticate once and reach several internal web applications without re-entering credentials. The applications support SAML 2.0. Which component issues the signed assertion that the applications consume to establish the user's identity?

A.The user agent (browser)
B.The service provider
C.The certificate authority
D.The identity provider
AnswerD

In SAML 2.0, the identity provider authenticates the user and issues a signed assertion containing authentication and attribute statements. The service provider trusts that signature and uses the assertion to establish a session. Since the business wants one authentication event to serve multiple applications, the identity provider is the component that generates the assertion the applications consume.

Why this answer

SAML 2.0 separates the identity provider, which authenticates users and issues signed assertions, from the service provider, which consumes and trusts them. The business needs one authentication event to reach multiple applications, so the identity provider is the issuing component. Certificate authorities and browsers support the exchange but do not create assertions.

Exam trap

The trap here is assuming the application or browser issues the identity assertion, when SAML places assertion issuance with the identity provider and consumption with the service provider.

261
Multi-Selectmedium

A company is conducting a disaster recovery test. Which TWO types of tests involve minimal risk to production operations?

Select 2 answers
A.Tabletop exercise
B.Simulation test
C.Parallel test
D.Walkthrough
E.Full interruption test
AnswersA, D

A tabletop exercise poses minimal risk because participants discuss disaster recovery roles and procedures verbally, without touching production systems or activating failover. This satisfies the stem's constraint of testing readiness while avoiding any operational impact, unlike full interruption or parallel tests that consume resources or disrupt live services.

Why this answer

A tabletop exercise (A) is correct because it is a discussion-based test in which stakeholders talk through disaster recovery roles, procedures, and decision points without touching or reconfiguring any production systems, so it carries essentially no operational risk. A walkthrough (D) is also correct because participants verbally trace each step of the DR plan against documentation and expected actions, again without executing failover or activating alternate sites, keeping production untouched. By contrast, a simulation test (B) can involve activating recovery mechanisms or alternate processing in a controlled but still potentially disruptive manner, and a parallel test (C) runs the recovery site alongside production, which introduces cost, data-synchronization, and configuration risks.

A full interruption test (E) is the riskiest option because it actually shuts down or takes production offline to fail over completely, which is unacceptable when minimal risk is required.

Exam trap

A common misconception is that 'simulation' or 'parallel' tests are low-risk because they are 'controlled,' but the key distinction is that tabletop and walkthrough involve zero execution of technical recovery steps, while any test that touches production systems carries inherent risk.

262
MCQhard

A security administrator is implementing a new file integrity monitoring (FIM) solution on critical servers. The administrator needs to ensure that the solution can detect unauthorized changes to system binaries and configuration files. Which of the following should the administrator configure to establish a trusted baseline for the FIM solution?

A.Generate cryptographic hashes of the files and store them in a secure, offline location.
B.Schedule a daily full backup of the critical servers and store the backups on a separate network share.
C.Configure the FIM solution to monitor the Windows Registry for changes to critical keys.
D.Enable auditing of file access events in the operating system's security log.
AnswerA

FIM works by comparing current file hashes against a known good baseline. Storing the baseline hashes offline prevents an attacker who compromises the server from altering the baseline to hide their changes. This ensures the integrity of the comparison and allows detection of unauthorized modifications. Cryptographic hashes provide a unique fingerprint for each file, so any change will be detected.

Why this answer

To establish a trusted baseline for FIM, the administrator must capture the current state of critical files, typically by generating cryptographic hashes. Storing these hashes securely offline prevents tampering. File access auditing, backups, and registry monitoring do not provide a file content baseline.

Therefore, the correct action is to generate and securely store file hashes.

Exam trap

The trap here is confusing file access auditing or backups with file integrity baseline creation, when the key is to capture and protect a cryptographic hash of file contents.

263
MCQmedium

A security analyst is investigating a potential attack on a web application. The analyst observes that an attacker is sending specially crafted requests that cause the application to execute unintended commands on the underlying operating system. Which type of attack is this?

A.SQL injection
B.Cross-site scripting (XSS)
C.Command injection
D.Cross-site request forgery (CSRF)
AnswerC

Command injection occurs when an application passes unsafe user input to a system shell, allowing an attacker to execute arbitrary commands on the host operating system. The scenario describes crafted requests causing unintended OS command execution, which is the definition of command injection. This vulnerability often arises when applications use functions like system() or exec() without proper input sanitization.

Why this answer

Command injection is the correct answer because the scenario describes an attacker causing the application to execute unintended operating system commands. This occurs when user input is passed to a system shell without proper sanitization. XSS targets the browser, SQL injection targets the database, and CSRF tricks the user's browser into making requests.

None of these directly result in OS command execution as described.

Exam trap

The trap here is confusing command injection with SQL injection, as both involve injecting malicious input, but only command injection leads to OS command execution.

264
MCQeasy

A security administrator needs to store sensitive customer data in a database. To protect the data at rest, which encryption method should be used?

A.RSA-2048
B.Blowfish in CTR mode
C.AES-256 in CBC mode
D.DES in ECB mode
AnswerC

AES-256 in CBC mode is a symmetric block cipher providing strong confidentiality for data at rest, and 256-bit keys resist brute-force attack. CBC chains each block to the previous ciphertext, hiding patterns in stored records, which suits database encryption where data is written and read over time.

Why this answer

AES-256 in CBC mode is the correct choice because it is a strong, widely accepted symmetric encryption algorithm that provides confidentiality for data at rest. AES-256 uses a 256-bit key, making it resistant to brute-force attacks, and CBC mode adds an initialization vector (IV) to ensure that identical plaintext blocks produce different ciphertext, preventing pattern leakage. This combination is recommended by standards such as NIST SP 800-38A for protecting sensitive stored data.

Exam trap

The trap here is that candidates often confuse asymmetric encryption (RSA) with symmetric encryption for data at rest, or they overlook the weaknesses of legacy algorithms like DES and Blowfish, assuming any encryption is sufficient without considering key size and mode of operation.

How to eliminate wrong answers

Option A is wrong because RSA-2048 is an asymmetric encryption algorithm used for key exchange and digital signatures, not for encrypting large volumes of data at rest; it is computationally expensive and impractical for database encryption. Option B is wrong because Blowfish in CTR mode is a legacy cipher with a 64-bit block size, which is vulnerable to birthday attacks and not recommended for modern data-at-rest protection; CTR mode also turns the cipher into a stream cipher, which can introduce risks if the IV is reused. Option D is wrong because DES in ECB mode uses a 56-bit key that is easily brute-forced with modern hardware, and ECB mode encrypts identical plaintext blocks into identical ciphertext blocks, revealing patterns in the data.

265
MCQmedium

In a forensic investigation, a hash of a suspect file is computed. Which of the following is the primary purpose of hashing in this context?

A.To compress the file
B.To decrypt the file
C.To identify the file owner
D.To verify file integrity
AnswerD

Hashing produces a fixed-length digest that changes if even one bit of the file alters. Comparing the computed hash against a known reference value verifies the file has not been modified, satisfying the forensic need to demonstrate integrity of evidence.

Why this answer

In forensic investigations, hashing (using algorithms like SHA-256 or MD5) produces a unique fixed-size digest of the file's contents. The primary purpose is to verify file integrity by comparing the hash before and after analysis, ensuring the evidence has not been altered. This provides a cryptographic chain of custody, as any change to the file results in a completely different hash value.

Exam trap

ISC2 often tests the misconception that hashing is used for encryption or compression, leading candidates to confuse its integrity-checking role with data transformation or security functions.

How to eliminate wrong answers

Option A is wrong because hashing is not a compression algorithm; compression (e.g., ZIP, gzip) reduces file size for storage or transmission, while hashing produces a fixed-length digest regardless of file size and does not reduce the original data. Option B is wrong because hashing is a one-way function that cannot decrypt data; decryption requires a reversible cipher and a key, whereas hashing is irreversible by design. Option C is wrong because hashing identifies the file's content integrity, not the owner; file ownership is determined by metadata (e.g., NTFS security identifiers or Unix UID/GID) or digital signatures, not by a hash of the file's data.

266
Multi-Selectmedium

A company is migrating to the cloud and wants to understand the shared responsibility model. For an IaaS deployment, which THREE are customer responsibilities? (Select THREE.)

Select 3 answers
A.Managing application security (e.g., patching web app code)
B.Configuring the host-based firewall on VMs
C.Patching the guest operating system
D.Physical security of the data center
E.Securing the hypervisor
AnswersA, B, C

Under IaaS the provider manages the platform beneath the VM, leaving everything above the operating system to the tenant. Application security, including patching web app code, therefore falls to the customer, satisfying the stem's customer-responsibility constraint rather than the provider's managed scope.

Why this answer

In IaaS, customer manages OS, applications, and network traffic controls (guest OS firewall).

267
MCQeasy

An organization is developing its incident response plan. According to NIST SP 800-61, which phase should include establishing a communication plan, acquiring necessary tools, and conducting exercises?

A.Preparation
B.Post-Incident Activity
C.Detection and Analysis
D.Containment, Eradication, and Recovery
AnswerA

Preparation covers building incident response capability before incidents occur, including developing the communication plan, procuring tools and resources, and running exercises to validate readiness. NIST SP 800-61 places all three activities in this phase, preceding detection, containment, and post-incident work.

Why this answer

According to NIST SP 800-61, the Preparation phase is where the organization establishes a communication plan, acquires necessary tools (e.g., forensic workstations, imaging software, network monitoring tools), and conducts exercises (e.g., tabletop exercises or full-scale simulations) to ensure readiness. This phase lays the foundation for all subsequent incident response activities by ensuring resources and procedures are in place before an incident occurs.

Exam trap

A common misconception is that Detection and Analysis includes proactive preparation activities, but NIST SP 800-61 clearly separates the proactive Preparation phase from the reactive Detection phase, which only begins after an incident is suspected.

How to eliminate wrong answers

Option B is wrong because the Post-Incident Activity phase focuses on lessons learned, evidence retention, and report generation after containment and recovery, not on proactive preparation like tool acquisition or exercises. Option C is wrong because Detection and Analysis involves identifying and validating incidents through log analysis, alerts, and threat intelligence, not establishing communication plans or acquiring tools. Option D is wrong because Containment, Eradication, and Recovery are reactive phases that execute actions to stop the incident, remove threats, and restore systems, relying on the tools and plans already set up in Preparation.

268
MCQmedium

A company is implementing a new access control system and wants to ensure that users are granted only the minimum permissions necessary to perform their job functions. Which principle is being applied?

A.Need to know
B.Defense in depth
C.Least privilege
D.Separation of duties
AnswerC

Least privilege is the principle that users should be granted only the minimum permissions necessary to perform their job functions. This directly matches the company's goal. By applying least privilege, the organization reduces the attack surface and limits potential damage from compromised accounts or insider threats.

Why this answer

The principle of least privilege states that users should be given only the minimum access rights required to perform their job functions. This exactly matches the company's goal of granting minimum necessary permissions. The other options represent different security concepts: separation of duties divides tasks, need to know focuses on information access, and defense in depth layers controls.

Exam trap

The trap here is confusing least privilege with need to know, since both involve restricting access, but need to know is specifically about information access, not general permissions.

269
MCQmedium

A company is implementing a new access control system for its data center. Which physical security control is best for preventing tailgating?

A.Mantrap
B.Biometric reader
C.Security guard
D.CCTV cameras
AnswerA

A mantrap uses two interlocking doors with an enclosed vestibule, admitting one person at a time and preventing an unauthorised individual from following closely behind. This interlock mechanism directly defeats tailgating, unlike turnstiles, guards or cameras that detect but do not physically stop it.

Why this answer

A mantrap is specifically designed to prevent tailgating by using a small vestibule with two interlocking doors. Only one door can open at a time, and the system typically requires authentication (e.g., badge or biometric) to proceed, ensuring that only one authorized person enters per cycle. This physical barrier directly blocks unauthorized individuals from following an authorized user through a single entry point.

Exam trap

SSCP candidates often mistake authentication methods like biometric readers or key cards as preventive controls for tailgating. However, these are identification/authentication controls; preventing tailgating requires a physical barrier such as a mantrap that enforces one-at-a-time entry.

How to eliminate wrong answers

Option B is wrong because a biometric reader authenticates identity but does not physically prevent multiple people from entering together; tailgating can still occur if an authorized user opens the door and an unauthorized person follows. Option C is wrong because while a security guard can deter tailgating, they are not a mechanical or automated control and can be distracted, overwhelmed, or bypassed, making them less reliable than a mantrap. Option D is wrong because CCTV cameras only provide surveillance and recording of tailgating incidents after they occur; they do not actively prevent the act of tailgating in real time.

270
MCQhard

An organization using cloud IAM wants to grant a compute instance permissions to access a cloud storage bucket without storing long-term credentials on the instance. Which IAM feature should be used?

A.IAM role assigned to the compute instance
B.Service-level access policies
C.Long-term user access keys
D.Resource-based policies on the storage bucket
AnswerA

An IAM role attached to the compute instance issues short-lived, automatically rotated credentials through the instance metadata service, so no long-term secret is stored on disk. This satisfies the requirement of granting bucket access without embedding persistent credentials on the instance.

Why this answer

IAM roles for compute instances allow the instance to assume a role and obtain temporary credentials from a security token service, avoiding the need for long-term keys.

271
MCQhard

A security administrator at a software company is reviewing the organization's security assessment strategy. The administrator must select an assessment method that evaluates the effectiveness of implemented controls through direct observation and testing, rather than relying on interviews or documentation review alone. Which assessment method should the administrator choose?

A.An independent security assessment that includes interviews, documentation review, and control testing.
B.A compliance review of the organization's written security policies and standards.
C.A self-assessment questionnaire completed by each department manager.
D.A vulnerability scan of all internet-facing systems using an automated scanner.
AnswerA

An independent security assessment combines multiple evidence-gathering techniques, including interviews, documentation review, observation, and direct testing of controls. Because it validates that controls operate as intended rather than merely existing on paper, it satisfies the requirement to evaluate effectiveness through observation and testing. The independence of the assessor also reduces bias compared with self-reported results.

Why this answer

Evaluating control effectiveness requires evidence beyond what people say or what policies state. An independent assessment that performs control testing through observation, sampling, and technical verification provides that evidence and reduces bias. Self-assessments, policy reviews, and vulnerability scans each address only part of the picture and cannot confirm that controls operate as designed across the organization.

Exam trap

The trap here is equating a vulnerability scan or a policy review with a full control effectiveness assessment, when only direct testing and observation validate that controls actually work.

272
MCQhard

A security administrator is reviewing network traffic logs and notices a large number of TCP SYN packets from various source IP addresses to a single destination IP address on port 443. The destination server is unresponsive. Which type of attack is most likely occurring?

A.Teardrop attack
B.SYN flood
C.Ping flood
D.Smurf attack
AnswerB

A SYN flood is a type of denial-of-service attack where an attacker sends a succession of SYN requests to a target's system in an attempt to consume enough server resources to make the system unresponsive. The server allocates resources for each half-open connection, and when the attacker never completes the handshake, those resources are exhausted. The scenario describes many SYN packets from spoofed sources to one destination, which is characteristic of a SYN flood.

Why this answer

The scenario describes a large volume of TCP SYN packets from various sources to a single destination, resulting in an unresponsive server. This is indicative of a SYN flood attack, where the attacker sends numerous SYN requests but does not complete the TCP handshake, causing the server to exhaust its resources on half-open connections. Other attacks like Smurf, ping flood, or Teardrop involve different protocols or mechanisms and do not match the described traffic pattern.

Exam trap

The trap here is confusing a SYN flood with other volumetric attacks that also cause unresponsiveness but use different protocols, such as ICMP-based floods.

273
MCQmedium

A developer wants to ensure that a web application is protected against cross-site request forgery (CSRF). Which mitigation technique is most commonly recommended?

A.Implement a Content Security Policy (CSP).
B.Enable HTTP Strict Transport Security (HSTS).
C.Sanitize all user input.
D.Use anti-CSRF tokens in forms.
E.Implement Cross-Origin Resource Sharing (CORS) headers.
AnswerD

Anti-CSRF tokens are unique, unpredictable values embedded in forms and validated server-side against the user's session. A forged cross-site request cannot supply the matching token, so the server rejects it, satisfying the requirement to protect the web application against CSRF.

Why this answer

Anti-CSRF tokens (synchronizer token pattern) are the canonical defense because they bind a form submission to the user's authenticated session: the server issues a random, unpredictable token stored in the session and embedded in the form, and rejects any state-changing request lacking a matching token. A cross-origin attacker cannot read the token due to the same-origin policy, so forged requests fail. This directly addresses CSRF's core weakness—browsers automatically attaching session cookies to cross-site requests.

Exam trap

The trap is confusing CSRF with XSS: candidates pick CSP or input sanitization because both are 'web security' answers, but CSRF is defeated by proving the request originated from your own page (tokens), not by filtering content.

How to eliminate wrong answers

Option A is wrong because CSP mitigates XSS and content-injection by restricting resource origins, but it does not prevent a browser from sending an authenticated cross-site request. Option B is wrong because HSTS only forces HTTPS and prevents protocol downgrade/SSL-stripping; it has no bearing on forged requests. Option C is wrong because input sanitization addresses injection flaws (XSS, SQLi) but CSRF exploits the browser's automatic credential attachment, not malicious input content.

Option E is wrong because CORS governs which origins may read responses via JavaScript; permissive CORS can actually worsen exposure and does not stop CSRF form posts.

274
MCQhard

A security operations center (SOC) analyst is investigating a series of alerts from the intrusion detection system (IDS) indicating possible command-and-control (C2) traffic. The analyst examines network flow logs and notices periodic outbound connections from an internal server to an external IP address every 30 minutes, with each connection transferring exactly 512 bytes. The external IP address has a low reputation score. Which of the following is the MOST likely explanation for this traffic pattern?

A.The server is infected with malware that is beaconing to a C2 server.
B.The server is exfiltrating data in small chunks to avoid detection.
C.The server is performing legitimate software updates from a vendor's server.
D.The server is sending heartbeat signals to a load balancer for high availability.
AnswerA

Periodic outbound connections at regular intervals with fixed small payloads are characteristic of malware beaconing. The low reputation of the external IP further supports this. Beaconing allows attackers to maintain command and control while blending into normal traffic. The consistent 30-minute interval and 512-byte size suggest automated communication, which is typical for malware checking in with its C2 infrastructure.

Why this answer

The correct answer is the one identifying malware beaconing. The combination of periodic connections, fixed small payload size, and low-reputation external IP is a classic indicator of command-and-control beaconing. Malware often uses regular intervals to check in with its C2 server, and the small, consistent payload size helps evade detection by not transferring large amounts of data.

This pattern is distinct from legitimate traffic like updates or heartbeats, which typically have different characteristics.

Exam trap

The trap here is assuming that any periodic outbound traffic is benign, such as software updates, without considering the fixed small payload and low-reputation destination that indicate malicious beaconing.

275
MCQeasy

An organization wants to ensure that a software update has not been tampered with during download. Which cryptographic technique should be used?

A.Compute a SHA-256 hash of the update
B.Sign the update with the developer's private key
C.Encrypt the update with AES
D.Append a MAC (Message Authentication Code)
AnswerB

Signing the update with the developer's private key lets recipients verify it using the corresponding public key. Any modification during download invalidates the signature, and only the private-key holder could have produced it, satisfying the integrity and authenticity requirement the stem describes.

Why this answer

Signing the update with the developer's private key provides both integrity and authenticity. When the user verifies the signature using the developer's public key, they can confirm that the update has not been tampered with and that it originated from the claimed developer. This is the standard approach for ensuring trust in software distribution, as used in code signing certificates (e.g., Authenticode, GPG).

Exam trap

The trap here is that candidates confuse integrity-only mechanisms (hash, MAC) with the combined integrity and authenticity provided by digital signatures, or they mistakenly think encryption (AES) prevents tampering when it only provides confidentiality.

How to eliminate wrong answers

Option A is wrong because computing a SHA-256 hash alone provides integrity but no authentication; an attacker could replace both the update and its hash, and the user would have no way to detect the substitution. Option C is wrong because encrypting the update with AES ensures confidentiality but does not prevent tampering; an attacker could modify the ciphertext, and decryption would produce garbage, but the user would not know if the original plaintext was altered. Option D is wrong because appending a MAC (Message Authentication Code) provides integrity and authenticity only if both parties share a secret key; in a public download scenario, the user cannot verify the MAC without the shared secret, making it impractical for verifying the update's origin.

276
MCQeasy

A security analyst notices repeated failed login attempts from a single IP address on the VPN gateway. The analyst adjusts the threshold for account lockout and enables geo-ip blocking. This activity is part of which risk management process?

A.Risk identification
B.Risk assessment
C.Risk reporting
D.Risk monitoring
AnswerD

Risk monitoring involves continuously tracking identified risks and evaluating control effectiveness. Adjusting the lockout threshold and enabling geo-ip blocking in response to observed failed logins treats the VPN gateway as an ongoing monitored risk, refining controls rather than performing initial assessment or identification.

Why this answer

The analyst is actively monitoring the VPN gateway for security events (failed logins) and then adjusting controls (lockout threshold, geo-IP blocking) in response to observed threats. This continuous observation and adjustment is the essence of risk monitoring, which is the ongoing process of tracking identified risks and evaluating the effectiveness of controls. The actions taken are not about identifying new risks, assessing their likelihood/impact, or formally reporting them, but rather about reacting to real-time data to maintain an acceptable risk posture.

Exam trap

The trap here is that candidates confuse 'monitoring' (ongoing observation and adjustment) with 'risk assessment' (quantitative/qualitative analysis), because adjusting thresholds feels like evaluating risk, but the question explicitly describes a reactive, operational action rather than a formal assessment process.

How to eliminate wrong answers

Option A is wrong because risk identification is the initial step of discovering and documenting potential risks (e.g., 'failed logins could indicate a brute-force attack'), but the analyst has already identified the risk and is now adjusting controls based on observed events. Option B is wrong because risk assessment involves evaluating the likelihood and impact of a risk (e.g., calculating the annualized loss expectancy), not implementing or tuning technical controls like lockout thresholds or geo-IP blocking. Option C is wrong because risk reporting is the formal communication of risk findings to stakeholders (e.g., via a risk register or executive summary), not the real-time operational adjustment of security configurations.

277
Multi-Selecthard

A financial institution is deploying a hardware security module (HSM) to protect cryptographic keys used for payment transactions. The security team must ensure that the HSM provides strong logical and physical protection. Which two of the following characteristics are MOST important to validate when selecting the HSM? (Choose two.)

Select 2 answers
A.The HSM enforces role-based access control and requires multiple physical or logical credentials for administrative actions.
B.The HSM includes a built-in UPS to maintain power during outages.
C.The HSM firmware can be updated automatically over the network without manual intervention.
D.The HSM has a FIPS 140-2 or FIPS 140-3 validation at an appropriate security level.
E.The HSM supports the largest possible number of symmetric key slots to avoid future purchases.
AnswersA, D

Strong access control, especially multi-person integrity (split knowledge) for sensitive operations, prevents a single insider from extracting or misusing keys. This directly supports logical protection. Combined with physical tamper safeguards, role-based access with dual control is a critical capability to validate, because it limits the attack surface from authorized users and satisfies common audit requirements.

Why this answer

Validating a FIPS 140-2/140-3 certificate at an appropriate level confirms that the HSM meets stringent security requirements, including tamper resistance and key protection. Enforcing role-based access with multi-person control ensures that no single individual can compromise keys. Together, these characteristics provide the logical and physical safeguards needed for payment transaction keys, whereas capacity, automatic updates, and power backup do not directly address security.

Exam trap

The trap here is confusing operational features such as scalability, automatic updates, or power redundancy with the core security validations that actually protect cryptographic keys.

278
MCQeasy

What is the primary purpose of establishing a chain of custody for digital evidence?

A.To reduce the size of evidence for storage
B.To encrypt evidence for secure transmission
C.To maintain evidence integrity and track handling
D.To prioritize which evidence to analyze first
AnswerC

Chain of custody documents who collected, accessed and transferred each artefact, with timestamps and signatures. This unbroken audit trail preserves evidence integrity and admissibility, proving the data was not altered or substituted between seizure and presentation, which satisfies the requirement to track handling throughout the investigation.

Why this answer

The primary purpose of establishing a chain of custody for digital evidence is to maintain evidence integrity and track every person who handled the evidence from collection through presentation in court. This process ensures that the evidence has not been tampered with, altered, or corrupted, which is critical for admissibility under legal standards such as the Federal Rules of Evidence (FRE) Rule 901. By documenting each transfer with timestamps, signatures, and hash values (e.g., MD5 or SHA-256), the chain of custody provides a verifiable audit trail that supports the evidence's authenticity and reliability.

Exam trap

The trap here is that candidates confuse chain of custody with data preservation techniques like encryption or compression, but the exam specifically tests that its core purpose is to ensure integrity and provide an unbroken audit trail of handling, not to secure or reduce the data.

How to eliminate wrong answers

Option A is wrong because reducing the size of evidence for storage is not a purpose of chain of custody; that is typically achieved through compression algorithms like ZIP or deduplication, and it has no bearing on legal admissibility. Option B is wrong because encrypting evidence for secure transmission is a separate security measure (e.g., using AES-256 or TLS), not a function of chain of custody, which focuses on documenting handling rather than protecting confidentiality. Option D is wrong because prioritizing which evidence to analyze first is a triage decision made during incident response based on impact or volatility (e.g., memory over disk), not a goal of chain of custody, which applies equally to all evidence items.

279
MCQmedium

A network administrator configured the above port security on an access port connected to a VoIP phone and a PC. A third device is connected to the phone's passthrough port. What will happen when the third device attempts to communicate?

A.The third device will be allowed to communicate because the phone's MAC is not counted.
B.The third device's traffic will be dropped, and a syslog message will be generated.
C.The port will be error-disabled.
D.The port will remain up but all traffic will be dropped.
AnswerB

'Restrict' drops excess traffic and logs the violation.

Why this answer

The port security configuration on the access port has a maximum MAC address count that includes the VoIP phone's MAC address. When a third device connects to the phone's passthrough port, it introduces an additional MAC address, exceeding the configured limit. The switch will then drop traffic from the third device and generate a syslog message, as the default violation mode is 'restrict' (or 'protect' depending on the configuration), which does not error-disable the port but discards offending frames and logs the event.

Exam trap

ISC2 often tests the misconception that the VoIP phone's MAC address is not counted toward port security limits, leading candidates to incorrectly choose that the third device is allowed, when in fact the phone's MAC is always counted unless a specific 'voice VLAN' exception is configured (which is not the case here).

How to eliminate wrong answers

Option A is wrong because the VoIP phone's MAC address is indeed counted toward the port security limit, as the phone is a network device with its own MAC; the statement that it is not counted is a common misconception. Option C is wrong because the default violation mode for port security is 'restrict' or 'protect', not 'shutdown'; 'shutdown' would error-disable the port, but the question implies a violation mode that drops traffic without disabling the port (as indicated by the correct answer generating a syslog message). Option D is wrong because while the port remains up, not all traffic is dropped; only traffic from the third device (the violating MAC) is dropped, while traffic from the phone and PC continues normally.

280
MCQhard

Based on the exhibit, which of the following best describes the firewall configuration?

A.The firewall allows only loopback traffic.
B.The firewall allows all traffic from the internal subnet.
C.The firewall allows SSH, HTTP, and HTTPS from the internal subnet and drops all other traffic.
D.The firewall allows all traffic from external sources.
AnswerC

The rule set explicitly permits TCP ports 22, 80, and 443 sourced from the internal subnet, satisfying the requirement to allow SSH, HTTP, and HTTPS from that segment. A terminal deny-any rule then discards all remaining traffic, matching the default-deny posture the exhibit demonstrates.

Why this answer

The exhibit shows an access control list (ACL) that explicitly permits TCP traffic on ports 22 (SSH), 80 (HTTP), and 443 (HTTPS) from the internal subnet (e.g., 192.168.1.0/24) to any destination, followed by an implicit deny all rule. This configuration allows only SSH, HTTP, and HTTPS from the internal subnet and drops all other traffic, matching option C.

Exam trap

The trap here is that candidates often overlook the implicit deny at the end of an ACL, assuming that only the listed permits exist and that all other traffic is allowed by default, rather than understanding that any traffic not explicitly permitted is dropped.

How to eliminate wrong answers

Option A is wrong because loopback traffic (127.0.0.0/8) is not explicitly permitted or denied in the ACL; the ACL focuses on the internal subnet, not loopback. Option B is wrong because the ACL does not allow all traffic from the internal subnet; it specifically permits only SSH, HTTP, and HTTPS, and denies everything else via the implicit deny. Option D is wrong because the ACL does not allow any traffic from external sources; it only permits traffic from the internal subnet, and external traffic would be subject to the implicit deny unless explicitly permitted.

281
Multi-Selecteasy

Which THREE of the following are data loss prevention (DLP) controls that can be implemented to protect sensitive data?

Select 3 answers
A.Require strong passwords for all user accounts
B.Encrypt sensitive data both at rest and in transit
C.Deploy endpoint DLP agents to monitor and block unauthorized data transfers
D.Classify data based on sensitivity and apply appropriate labels
E.Implement network firewalls to block all outbound traffic
AnswersB, C, D

Encrypting sensitive data at rest and in transit renders intercepted or exfiltrated content unreadable, acting as a DLP control that limits exposure even when other safeguards fail. This satisfies the requirement to protect sensitive data across both storage and transmission states.

Why this answer

Option B is correct because encryption of sensitive data at rest (e.g., AES-256 on disks/databases) and in transit (e.g., TLS 1.2+) is a core DLP control that renders intercepted or exfiltrated data unreadable, directly preventing unauthorized disclosure. Option C is correct because endpoint DLP agents enforce policies at the source by inspecting and blocking unauthorized transfers via channels such as USB, email, clipboard, and cloud uploads, which is a primary DLP enforcement mechanism. Option D is correct because data classification with sensitivity labels (e.g., Public, Internal, Confidential, Restricted) is the foundational DLP step that identifies what needs protection and drives which handling, encryption, and blocking policies apply.

Option A does not belong because strong passwords are an access-control/authentication measure (identity protection), not a control that detects or prevents sensitive data from leaving the organization. Option E does not belong because blocking all outbound traffic via firewalls is a blunt network availability control, not a data-aware DLP control, and it would break legitimate business communications rather than selectively protect sensitive data.

282
Multi-Selectmedium

Which TWO of the following are key components of a Security Information and Event Management (SIEM) system? (Select two.)

Select 2 answers
A.Vulnerability scanning
B.Centralized log collection and storage
C.Correlation and analysis engine
D.Intrusion detection system (IDS)
E.Data loss prevention (DLP)
AnswersB, C

Centralised log collection and storage underpins every SIEM function: agents and syslog forwarders aggregate events from disparate sources into one searchable repository. Without this normalised, retained data pool, no correlation, alerting or forensic review is possible, so it is a defining architectural component.

Why this answer

Option B (Centralized log collection and storage) is correct because a SIEM's foundational function is to aggregate logs and event data from disparate sources—firewalls, servers, applications, network devices—into a single repository where they can be retained and searched. Option C (Correlation and analysis engine) is correct because the SIEM's core value lies in correlating events across multiple sources and applying rules, signatures, or behavioral analytics to detect patterns that indicate security incidents, then generating alerts. Option A (Vulnerability scanning) is incorrect because vulnerability scanners are separate tools that identify weaknesses in systems rather than collect and correlate event data, though they may feed findings into a SIEM.

Option D (Intrusion detection system) is incorrect because an IDS is a distinct monitoring technology that detects malicious traffic or host activity; it can send alerts to a SIEM but is not itself a SIEM component. Option E (Data loss prevention) is incorrect because DLP is a separate control focused on preventing exfiltration of sensitive data, not on log aggregation or event correlation.

Exam trap

ISC2 often tests the misconception that SIEM includes active security controls like IDS or DLP, when in fact SIEM is a passive analysis and management platform that aggregates data from those tools.

283
MCQeasy

A company's incident response plan includes a step to preserve evidence. Which action BEST ensures the integrity of forensic evidence?

A.Turn off the system immediately
B.Copy files to a network share
C.Run a checksum on the live system
D.Create a forensic image with write blocker and hash
AnswerD

Creating a forensic image through a write blocker prevents any modification of the original drive, while hashing produces a verifiable value confirming the copy matches the source byte-for-byte. This satisfies the stem's integrity constraint, since any later alteration becomes detectable through hash comparison, preserving evidential value for incident response.

Why this answer

Creating a forensic image with a write blocker ensures that the original data is not altered during acquisition, and hashing (e.g., SHA-256) provides a cryptographic integrity check that can later verify the image is an exact bit-for-bit copy. This preserves the chain of custody and admissibility of evidence in legal proceedings.

Exam trap

The trap here is that candidates confuse 'preserving evidence' with 'preserving system availability' or 'quick data capture,' leading them to choose turning off the system or copying files, which actually destroy or alter forensic integrity.

How to eliminate wrong answers

Option A is wrong because turning off the system immediately can cause loss of volatile data (e.g., RAM contents, network connections) and may trigger anti-forensic mechanisms or corrupt the file system. Option B is wrong because copying files to a network share alters file metadata (e.g., timestamps, access times) and does not capture deleted or hidden data, nor does it provide a verifiable hash of the original media. Option C is wrong because running a checksum on the live system modifies the system state (e.g., reading files changes access times) and the hash is taken from a potentially altered source, so it cannot guarantee the integrity of the original evidence.

284
MCQmedium

A company uses AWS for critical workloads. An analyst notices unauthorized API calls from an IP address outside the company. The logs show that the attacker used stolen access keys belonging to an IAM user with administrative privileges. The incident response team must contain the breach as quickly as possible. The analyst has access to the AWS Management Console and can use the CLI. The team is following the incident response plan. Which action should be taken FIRST to prevent further unauthorized actions?

A.Create a new security group to block the attacker's source IP at the network level.
B.Disable the compromised access keys using the IAM dashboard or CLI.
C.Delete the compromised IAM user immediately.
D.Rotate all IAM user access keys across the entire AWS account.
AnswerB

Disabling the compromised access keys immediately invalidates the stolen credentials, halting the attacker's unauthorised API calls. This contains the breach fastest, satisfying the stem's priority, whereas deleting the IAM user or reviewing logs leaves the active keys usable in the interim.

Why this answer

The immediate priority in an access key compromise is to invalidate the stolen credentials to stop the attacker from making further API calls. Disabling the compromised access keys via the IAM dashboard or CLI (using `aws iam update-access-key --status Inactive`) is the fastest containment action that directly revokes the attacker's authentication token without disrupting other legitimate users or services.

Exam trap

ISC2 often tests the principle of least disruption during containment — candidates may choose to delete the user or block the IP, but the correct first step is to disable the specific compromised credential to stop the attack without breaking other dependencies.

How to eliminate wrong answers

Option A is wrong because creating a security group to block the attacker's source IP at the network level does not prevent the attacker from using the stolen keys from a different IP address, and AWS API calls are not filtered by security groups (which apply only to VPC network traffic, not to the AWS API endpoint). Option C is wrong because deleting the compromised IAM user immediately could cause unintended disruption to any services or automation relying on that user, and it is a more destructive action than simply disabling the keys; the incident response plan typically recommends disabling keys first to preserve the user for forensic analysis. Option D is wrong because rotating all IAM user access keys across the entire account is an overly broad and time-consuming action that could break legitimate operations and is not the first step; the priority is to contain the specific compromised keys, not to rotate every key in the account.

285
MCQmedium

A biometric system has a high false rejection rate (FRR). Which of the following is a likely consequence?

A.The system will require less frequent calibration
B.Unauthorized users are more likely to gain access
C.Legitimate users may be denied access, leading to frustration
D.The system's crossover error rate (CER) will be very low
AnswerC

A high false rejection rate means the system wrongly refuses genuine users whose biometrics fail to match the stored template. The consequence is denied access for authorised individuals, causing frustration and extra helpdesk load. This directly satisfies the stem's FRR constraint, since FRR measures valid-user rejections, not impostor acceptance.

Why this answer

A high false rejection rate (FRR) means the biometric system incorrectly rejects legitimate users. This leads to frustration and potential productivity loss as authorized individuals are denied access. FRR is a key performance metric; a high FRR indicates the system is too strict.

Exam trap

SSCP often tests the confusion between FAR and FRR; candidates may incorrectly associate high FRR with unauthorized access (which is FAR) or with low CER, so remembering that FRR affects legitimate users is key.

How to eliminate wrong answers

Option A is wrong because a high FRR does not imply less frequent calibration; in fact, it may indicate the need for recalibration or threshold adjustment. Option B is wrong because unauthorized users gaining access is related to the false acceptance rate (FAR), not FRR. Option D is wrong because a low crossover error rate (CER) indicates a balanced system with low FRR and FAR; a high FRR would likely correspond to a higher CER, not lower.

286
Drag & Dropmedium

Drag and drop the steps for properly disposing of a hard drive containing sensitive data into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The proper order for disposing of a hard drive with sensitive data is: first, backup any data that needs to be retained; second, overwrite the entire drive to sanitize it; third, verify that the overwrite was successful using a tool; fourth, physically destroy the drive (e.g., shredding or crushing); and finally, document the process for audit trails and compliance. This sequence ensures data confidentiality and availability of necessary data.

287
MCQhard

A security analyst is investigating a potential data exfiltration incident. The logs show a large number of outbound DNS queries to a domain that resolves to an IP address in a foreign country. The queries contain encoded strings in the subdomain. Which type of attack is MOST likely occurring?

A.DNS poisoning
B.DNS amplification attack
C.DNS rebinding
D.DNS tunneling
AnswerD

DNS tunneling encodes data in DNS queries and responses for covert exfiltration.

Why this answer

DNS tunneling encodes data within DNS queries and responses to bypass network security controls. The large volume of outbound queries to a foreign IP, combined with encoded subdomain strings, is the classic signature of data exfiltration via DNS tunneling, as the protocol is often allowed through firewalls.

Exam trap

The trap here is that candidates confuse DNS tunneling with DNS amplification because both involve high query volumes, but amplification focuses on response size and reflection, not on encoding data in subdomains for exfiltration.

How to eliminate wrong answers

Option A is wrong because DNS poisoning corrupts the cache of a resolver to redirect traffic to malicious sites, not to exfiltrate data via encoded queries. Option B is wrong because a DNS amplification attack uses open resolvers to flood a victim with large responses, not to send outbound queries with encoded payloads. Option C is wrong because DNS rebinding manipulates DNS responses to bypass same-origin policy for browser-based attacks, not to exfiltrate data through subdomain strings.

288
MCQeasy

A company is implementing a new file-sharing application for employees. Which of the following is the most important security control to prevent unauthorized access to shared files?

A.Schedule regular backups.
B.Implement access control lists (ACLs) on shared folders.
C.Install antivirus software on all endpoints.
D.Enable detailed audit logging.
E.Encrypt files with AES-256.
AnswerB

ACLs enforce per-user and per-group permissions directly on shared folders, so only explicitly authorised identities can read or modify files. This satisfies the stem's requirement to prevent unauthorised access at the resource itself, rather than relying on perimeter controls that leave files exposed once a share is reached.

Why this answer

Implementing access control lists (ACLs) on shared folders is the most direct and effective control to prevent unauthorized access to shared files. ACLs define which users or groups have permissions to read, write, or execute files, thereby enforcing the principle of least privilege.

Exam trap

The SSCP exam often tests the misconception that encryption or audit logging prevents unauthorized access, when actually access control mechanisms like ACLs are the primary preventive control.

How to eliminate wrong answers

Option A is wrong because regular backups ensure data availability and recovery, not access control. Option C is wrong because antivirus software protects against malware, not unauthorized access by legitimate users. Option D is wrong because audit logging detects and records access but does not prevent it.

Option E is wrong because encryption protects data confidentiality if accessed, but does not control who can access the files.

289
MCQmedium

A security analyst is evaluating the cryptographic settings for a new application that requires both confidentiality and integrity for data in transit. The analyst needs to choose a symmetric cipher that provides authenticated encryption. Which of the following is the best choice?

A.RC4 stream cipher
B.AES in ECB mode
C.AES in GCM mode
D.AES in CBC mode
AnswerC

AES in GCM mode provides authenticated encryption, combining confidentiality with an authentication tag that detects tampering, which meets both stated requirements for data in transit. Other AES modes such as CBC supply confidentiality only and need a separate MAC.

Why this answer

AES in GCM mode provides authenticated encryption, offering both confidentiality and integrity/authenticity in a single operation. GCM (Galois/Counter Mode) is an AEAD (Authenticated Encryption with Associated Data) mode, making it the best choice for data in transit requiring both properties.

Exam trap

The trap is assuming that any AES mode provides integrity; candidates may pick CBC or ECB thinking they are secure, but only GCM (and other AEAD modes like CCM) provide authenticated encryption natively.

How to eliminate wrong answers

Option A is wrong because RC4 is a stream cipher that provides confidentiality but not integrity; it is also deprecated due to vulnerabilities. Option B is wrong because AES in ECB mode provides confidentiality but not integrity, and it is insecure due to pattern leakage. Option D is wrong because AES in CBC mode provides confidentiality but not integrity; it requires a separate MAC for authentication and is vulnerable to padding oracle attacks if not implemented correctly.

290
MCQhard

Refer to the exhibit. An organization's incident response policy defines these actions. In what sequence should these phases be applied?

A.Isolate, reimage, restore from backup
B.Reimage, isolate, restore
C.Restore, isolate, reimage
D.Isolate, restore, reimage
AnswerA

Isolating the compromised host first contains the threat and prevents lateral spread, reimaging then removes any persistent malware or backdoors, and restoring from backup returns the system to a known-good state. This sequence satisfies containment before eradication before recovery, matching standard incident response phase ordering.

Why this answer

The correct sequence is Isolate, reimage, restore from backup because containment (isolation) must occur first to prevent the incident from spreading, followed by eradication (reimaging) to remove the threat, and finally recovery (restoring from backup) to return the system to a known good state. This aligns with the NIST SP 800-61 incident response lifecycle, where containment, eradication, and recovery are performed in that order.

Exam trap

The trap here is that candidates mistakenly think restoration can occur before eradication, but in practice, restoring from backup without reimaging leaves the system vulnerable if the backup itself is compromised or if the root cause (e.g., a persistent rootkit) remains in the system firmware or boot sector.

How to eliminate wrong answers

Option B is wrong because reimaging before isolation could allow the threat to spread to other systems during the reimage process, violating the containment principle. Option C is wrong because restoring from backup before isolating and reimaging would reintroduce the threat if the backup is compromised, and the system remains vulnerable. Option D is wrong because restoring from backup before reimaging fails to eradicate the root cause; the threat may persist in the restored data or system state.

291
MCQmedium

In X.509 certificate format, which field is used to specify the fully qualified domain name(s) for which the certificate is valid?

A.Key Usage
B.Issuer
C.Subject
D.Subject Alternative Name
AnswerD

The Subject Alternative Name extension lists the DNS names, and optionally IP addresses, for which the certificate is valid. Modern clients validate identity against SAN rather than the Common Name, making it the field that specifies fully qualified domain names.

Why this answer

The Subject Alternative Name (SAN) extension in an X.509 certificate explicitly lists the fully qualified domain names (FQDNs), IP addresses, or other identifiers for which the certificate is valid. Modern browsers and TLS libraries primarily check the SAN field to validate a server's identity, ignoring the Common Name (CN) in the Subject field. The SAN is defined in RFC 5280 and is critical for multi-domain (SAN) certificates and wildcard certificates.

Exam trap

SSCP often tests the misconception that the Common Name (CN) in the Subject field is still used for hostname verification, but modern standards and browsers rely exclusively on the Subject Alternative Name extension.

How to eliminate wrong answers

Option A is wrong because Key Usage specifies the cryptographic purposes of the public key (e.g., digital signature, key encipherment) and does not contain domain names. Option B is wrong because Issuer identifies the Certificate Authority (CA) that signed and issued the certificate, not the domain it protects. Option C is wrong because Subject contains the entity's distinguished name (DN), including the Common Name (CN), but the CN is deprecated for hostname verification and does not reliably list all valid FQDNs.

292
Multi-Selecthard

An organization is designing a secure email system using S/MIME. Which of the following are essential components of the PKI that must be in place? (Select THREE)

Select 3 answers
A.A symmetric key distribution center (KDC)
B.X.509 digital certificates for each user
C.A method to check certificate revocation (e.g., CRL or OCSP)
D.A timestamp authority (TSA)
E.A certificate authority (CA) to sign certificates
AnswersB, C, E

S/MIME binds each user's public key to their email identity through an X.509 certificate, satisfying the PKI requirement for verified sender and recipient identities. Without per-user certificates, signing and encryption cannot be tied to a trusted identity.

Why this answer

Option B is correct because S/MIME binds each user's public key to their identity through an X.509 digital certificate, which is required for encrypting messages and verifying digital signatures. Option C is correct because the PKI must provide a way to check certificate revocation status, typically via CRL or OCSP, so recipients can reject messages signed with compromised or expired certificates. Option E is correct because a certificate authority (CA) is needed to issue and digitally sign the X.509 certificates that S/MIME relies on for trust.

Option A is not correct because a symmetric key distribution center (KDC) is associated with Kerberos-style symmetric key management, not with S/MIME's certificate-based public key infrastructure. Option D is not correct because a timestamp authority (TSA) supports trusted time-stamping for non-repudiation and is not an essential PKI component for basic S/MIME encryption and signing.

Exam trap

In the SSCP exam, candidates often mistakenly select a KDC or TSA as essential for S/MIME, but these are auxiliary services, not core PKI components.

293
Drag & Dropmedium

Drag and drop the steps for conducting a security incident response under the NIST framework into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

NIST incident response follows: Preparation, Detection & Analysis, Containment/Eradication/Recovery, Post-Incident Activity, and Reporting.

294
MCQmedium

A financial institution uses a risk management framework based on ISO 31000. During a quarterly risk review, the risk manager identifies that the residual risk for a critical trading application remains high despite multiple controls. The application's risk score has not decreased after implementing two-factor authentication and encryption. The risk appetite statement says 'no high residual risk for systems processing transactions over $10M.' What should the risk manager do next?

A.Reduce the risk by disabling non-essential features of the application.
B.Transfer the risk by purchasing cyber insurance.
C.Escalate to senior management for a decision on additional controls or risk acceptance.
D.Accept the risk because controls are already in place.
AnswerC

Residual risk still breaches the stated risk appetite, which the risk manager cannot accept unilaterally. ISO 31000 requires escalation so senior management decides whether to fund further treatment or formally accept the exposure, preserving accountability for the trading application.

Why this answer

When residual risk exceeds the organization's risk appetite, standard risk management frameworks (like ISO 31000) require escalation to senior management to decide on additional controls or formal risk acceptance. Option A is incorrect because disabling non-essential features may not sufficiently reduce the risk to within appetite and could harm business operations. Option B is incorrect because cyber insurance transfers financial loss but does not reduce the residual risk itself; the risk appetite statement addresses residual risk, not just financial impact.

Option D is incorrect because the risk appetite explicitly prohibits high residual risk for this system, so acceptance would violate policy.

295
MCQmedium

An organization allows employees to use personal smartphones to access corporate email and data. Which control is MOST important to protect corporate data if a device is lost or stolen?

A.Require device encryption
B.Require strong passwords with complexity requirements
C.Implement remote wipe capability
D.Enforce a screen lock timeout of 1 minute
AnswerC

Remote wipe lets administrators erase corporate email and data from a lost or stolen personal smartphone, addressing the BYOD confidentiality risk directly. It satisfies the stem's requirement to protect corporate data when the device is outside organisational physical control.

Why this answer

Remote wipe capability is the most important control because it allows the organization to remotely erase corporate data from a lost or stolen device, directly mitigating the risk of unauthorized access. While encryption, strong passwords, and screen locks provide defense-in-depth, they do not guarantee data destruction if the device falls into the wrong hands. Remote wipe is the only control that ensures corporate data is removed from the device, addressing the specific threat of loss or theft.

Exam trap

SSCP often tests the difference between preventive and corrective controls; candidates may choose encryption or strong passwords as they are preventive, but the question asks for the MOST important control when a device is already lost or stolen, which requires a corrective control like remote wipe.

How to eliminate wrong answers

Option A is wrong because device encryption protects data at rest but does not prevent access if the device is unlocked or if the encryption key is compromised; it does not remove data from a lost device. Option B is wrong because strong passwords can be bypassed through brute force, shoulder surfing, or malware, and they do not erase data when the device is lost. Option D is wrong because a screen lock timeout only reduces the window of opportunity for unauthorized access; it does not delete data and can be circumvented if the device is kept unlocked or the timeout is bypassed.

296
MCQhard

Refer to the exhibit. A network administrator is reviewing the VPN configuration on a site-to-site VPN hub. Which of the following is the most significant security vulnerability in this configuration?

A.The encryption algorithm AES-256 is too weak
B.The pre-shared key is applied to all potential peers due to the wildcard address
C.The hash algorithm SHA is insecure
D.The pre-shared key is too short and easily guessable
AnswerB

A wildcard peer address combined with one shared pre-shared key means any remote endpoint matching that wildcard can authenticate using the same secret. This collapses peer identity into a single credential, so compromise of one site's key grants access to every tunnel, defeating per-peer authentication.

Why this answer

The most significant security vulnerability is that the pre-shared key is applied to all potential peers due to the wildcard address. This means any peer with the correct PSK can establish a VPN connection, potentially allowing unauthorized access. The wildcard address (0.0.0.0/0) in the peer configuration is overly permissive and should be restricted to specific IP addresses.

Exam trap

SSCP often tests the identification of misconfigurations that lead to security vulnerabilities, and candidates may focus on encryption algorithms or key length while missing the overly permissive peer address.

How to eliminate wrong answers

Option A is wrong because AES-256 is a strong encryption algorithm and not considered weak. Option C is wrong because SHA (likely SHA-1 or SHA-2) is a secure hash algorithm; while SHA-1 is deprecated, the option doesn't specify, and it's not the most significant vulnerability here. Option D is wrong because the length of the PSK is not mentioned; the vulnerability is about the wildcard peer, not the PSK strength.

297
MCQhard

An organization is setting up a site-to-site VPN between two branch offices. They require encryption of the entire IP packet, including the original IP header, and plan to use IPsec. Which mode should they configure?

A.Transport mode
B.Tunnel mode
C.ESP mode
D.AH mode
AnswerB

Tunnel mode encapsulates the entire original IP packet inside a new IPsec packet, encrypting the original header as required. This satisfies the stem's whole-packet encryption constraint, whereas transport mode encrypts only the payload and leaves the original IP header intact.

Why this answer

Tunnel mode in IPsec encapsulates the entire original IP packet, including the original IP header, within a new IP packet with a new IP header. This provides confidentiality and integrity for the entire packet and is typically used for site-to-site VPNs between gateways. Transport mode only encrypts the payload, leaving the original IP header intact, which does not meet the requirement.

Exam trap

The trap is confusing IPsec modes (transport vs. tunnel) with protocols (ESP vs. AH). Candidates may select ESP or AH thinking they are modes, but the question specifically asks for the mode that encrypts the entire IP packet, which is tunnel mode.

How to eliminate wrong answers

Option A is wrong because Transport mode only protects the payload (e.g., TCP/UDP) and not the original IP header, so it does not encrypt the entire IP packet. Option C is wrong because ESP (Encapsulating Security Payload) is a protocol that can be used in either transport or tunnel mode; it is not a mode itself. Option D is wrong because AH (Authentication Header) provides authentication and integrity but not encryption, and it also can be used in transport or tunnel mode.

298
MCQeasy

After an incident, what is the primary purpose of a lessons learned meeting?

A.Update security policies
B.Assign blame
C.Improve future response
D.Document findings for litigation
AnswerC

A lessons learned meeting examines the incident response to identify what worked and what failed, producing corrective actions that strengthen future detection, containment and recovery. Its primary output is improved future response, not blame allocation or immediate system restoration.

Why this answer

The primary purpose of a lessons learned meeting after an incident is to identify what worked well and what did not during the response, enabling the team to refine procedures, update playbooks, and improve future incident response effectiveness. This aligns with the continuous improvement cycle in incident management, as outlined in NIST SP 800-61 and ISO 27035, where the focus is on process enhancement rather than punitive measures.

Exam trap

The trap here is that candidates confuse the primary purpose of a lessons learned meeting (process improvement) with secondary outcomes like policy updates or legal documentation, leading them to select A or D instead of C.

How to eliminate wrong answers

Option A is wrong because updating security policies is a possible outcome of a lessons learned meeting, but it is not the primary purpose; the meeting focuses on response process improvement, and policy changes are a secondary action that may follow. Option B is wrong because assigning blame is counterproductive and explicitly discouraged in incident response frameworks; the goal is to foster a blame-free culture to encourage honest reporting and learning. Option D is wrong because documenting findings for litigation is a separate legal activity that may occur after an incident, but it is not the core objective of a lessons learned meeting, which is centered on operational improvement.

299
MCQmedium

Which type of disaster recovery test involves running the DR systems alongside the production systems to validate functionality without impacting live operations?

A.Simulation test
B.Full interruption test
C.Tabletop exercise
D.Parallel test
AnswerD

A parallel test runs DR systems concurrently with production, letting recovery capabilities be validated under realistic load without disrupting live operations. Unlike full interruption, it confirms functionality while production continues serving users, satisfying the non-impact constraint.

Why this answer

A parallel test runs the disaster recovery systems concurrently with the production systems to verify that the DR environment can handle the workload without disrupting live operations. This approach validates data replication, application functionality, and failover readiness while keeping production untouched, making it the correct choice for non-disruptive validation.

Exam trap

The trap here is that candidates often confuse 'parallel test' with 'simulation test' because both sound non-disruptive, but a simulation test is purely theoretical while a parallel test actually runs DR systems with live data.

How to eliminate wrong answers

Option A is wrong because a simulation test involves a controlled, often tabletop-style walkthrough of disaster scenarios without actually activating DR systems or processing live data. Option B is wrong because a full interruption test (also called a full-scale test) requires shutting down production systems to fail over to the DR site, which directly impacts live operations. Option C is wrong because a tabletop exercise is a discussion-based review of roles and procedures, not a technical validation of DR system functionality.

300
MCQmedium

Refer to the exhibit. The analyst sees this IDS alert. What is the most likely outcome if the target web application is vulnerable?

A.Buffer overflow and remote code execution
B.Authentication bypass or data extraction
C.Cross-site scripting (XSS) attack
D.Privilege escalation on the database server
AnswerB

An SQL injection payload in the alert indicates the attacker is probing for database manipulation flaws. If the web application fails to sanitise input, the injected query executes, allowing authentication bypass or extraction of stored data. This directly satisfies the stem's vulnerability condition, making database compromise the likely outcome.

Why this answer

The IDS alert indicates a SQL injection attempt (e.g., '1=1' or similar pattern). If the web application is vulnerable, the attacker can manipulate SQL queries to bypass authentication (e.g., logging in without valid credentials) or extract data from the database (e.g., dumping user tables). This is the most direct outcome of a successful SQL injection.

Exam trap

ISC2 often tests the distinction between SQL injection and other web attacks (like XSS or buffer overflows), and the trap here is that candidates may confuse the outcome of SQL injection with remote code execution or privilege escalation, when the primary and most likely result is authentication bypass or data extraction.

How to eliminate wrong answers

Option A is wrong because buffer overflow and remote code execution are typically associated with memory corruption vulnerabilities (e.g., stack overflows), not SQL injection. Option C is wrong because cross-site scripting (XSS) exploits client-side script injection into web pages, not server-side SQL query manipulation. Option D is wrong because privilege escalation on the database server is a secondary effect that may follow data extraction, but the immediate and most likely outcome of a SQL injection is authentication bypass or data extraction, not direct privilege escalation.

Page 3

Page 4 of 13

Page 5