Courseiva

Systems Security Certified Practitioner SSCP (SSCP) — Questions 301–375

971 questions total · 13pages · All types, answers revealed

Page 4

Page 5 of 13

Page 6
301
MCQhard

During the eradication phase of a malware incident, a security analyst removes malicious files and cleans registry persistence. What is the MOST critical additional step to prevent reinfection through the same vector?

A.Patching the vulnerability that was exploited
B.Running a full antivirus scan
C.Resetting all user passwords
D.Reimaging the system with a clean OS
AnswerA

Patching the exploited vulnerability closes the original entry vector, so the attacker cannot reinfect the host through the same flaw. Removing files and registry persistence alone leaves that vector open, allowing immediate recompromise during or after eradication.

Why this answer

Patching the exploited vulnerability (Option A) is the most critical additional step because it removes the root cause of the infection. Without patching, the same attack vector (e.g., an unpatched SMB vulnerability like EternalBlue) remains open, allowing the malware to reinfect the system immediately after cleanup. Eradication is incomplete if the underlying flaw is not addressed, as the attacker can simply re-exploit the same weakness.

Exam trap

ISC2 often tests the misconception that cleaning or reimaging alone is sufficient, but the trap here is that candidates overlook the need to address the root cause (the vulnerability) to prevent reinfection through the same vector.

How to eliminate wrong answers

Option B is wrong because running a full antivirus scan is a detection and cleanup step, not a preventive measure against reinfection through the same vector; it may miss zero-day or polymorphic malware. Option C is wrong because resetting user passwords addresses credential theft or lateral movement, but does not close the exploited vulnerability (e.g., a remote code execution flaw in a network service). Option D is wrong because reimaging the system with a clean OS removes the malware but does not patch the original vulnerability; the system will be reinfected if reconnected to the same unpatched network.

302
MCQmedium

A security administrator is reviewing log files and notices that a user logged in at 3:00 AM from an IP address in a foreign country. The user's manager confirms the user is not authorized for remote access. Which type of policy has likely been violated?

A.Remote access policy
B.Data handling policy
C.Password policy
D.Acceptable use policy (AUP)
AnswerA

A remote access policy defines who may connect remotely, from where, and under what conditions. The login from a foreign IP at 03:00 breaches the manager-confirmed restriction that this user lacks remote access authorisation, so the access control constraint in the stem is directly violated.

Why this answer

The scenario describes a user logging in from an unauthorized location (foreign country) at an unusual time (3:00 AM) without remote access authorization. This directly violates the remote access policy, which defines who can connect remotely, from where, and under what conditions. The policy typically specifies allowed authentication methods (e.g., VPN with multi-factor authentication), permitted IP ranges, and time-of-day restrictions to prevent unauthorized external connections.

Exam trap

SSCP candidates often confuse Acceptable Use Policy (AUP) with Remote Access Policy. While AUP covers general appropriate use of systems, this specific violation involves unauthorized remote logins from a foreign IP at an odd hour, which falls under Remote Access Policy restrictions.

How to eliminate wrong answers

Option B (Data handling policy) is wrong because it governs how data is classified, stored, transmitted, and disposed of, not the conditions under which remote logins occur. Option C (Password policy) is wrong because it specifies password complexity, expiration, and reuse rules, not the authorization for remote access or geographic restrictions. Option D (Acceptable use policy) is wrong because it defines permissible activities on company resources (e.g., browsing, email usage), not the specific rules for remote connectivity or location-based access control.

303
MCQmedium

A security administrator is configuring a network tap to monitor traffic between two switches. The tap is placed inline and must not disrupt network connectivity if it loses power. Which type of tap should be used?

A.Fail-to-wire tap
B.Span port
C.Aggregating tap
D.Network hub
AnswerA

A fail-to-wire tap, also known as a bypass tap, has a relay that closes and directly connects the two network segments if the tap loses power. This ensures that network traffic continues to flow uninterrupted, maintaining connectivity. This directly meets the requirement that the tap must not disrupt network connectivity if it loses power, making it the correct choice.

Why this answer

A fail-to-wire tap ensures that if the tap loses power, the connection between the two network segments is physically closed, allowing traffic to continue flowing. This maintains network availability. Other options like aggregating taps, SPAN ports, or hubs do not provide this fail-safe inline capability.

The requirement for non-disruption on power loss is specifically addressed by fail-to-wire functionality.

Exam trap

The trap here is confusing a SPAN port with an inline tap; SPAN ports are not inline and rely on switch resources, while fail-to-wire taps are inline and provide physical bypass.

304
MCQmedium

A security metric tracking the percentage of systems with critical patches applied within 48 hours is an example of which type of metric?

A.Service level agreement (SLA)
B.Key performance indicator (KPI)
C.Control objective
D.Key risk indicator (KRI)
AnswerB

A KPI measures progress toward a strategic objective, such as patch-management effectiveness, rather than raw operational volume. Tracking the percentage of systems meeting the 48-hour critical-patch window directly satisfies the stem's requirement for a performance-oriented metric, since it evaluates how well the patching process achieves its target, not merely how many patches were deployed.

Why this answer

A Key Performance Indicator (KPI) is a measurable value that demonstrates how effectively an organization is achieving key business objectives. The percentage of systems with critical patches applied within 48 hours is a performance metric that tracks the efficiency of the patch management process, making it a KPI. It indicates how well the security team is performing against a defined target.

Exam trap

The trap is confusing KPIs with KRIs or SLAs; candidates may think any security metric is a KRI, but KPIs measure performance of controls, while KRIs measure risk levels.

How to eliminate wrong answers

Option A is wrong because an SLA is a contractual agreement with defined service levels and penalties, not a metric itself; the metric could be used to measure SLA compliance but is not an SLA. Option C is wrong because a control objective is a statement of the desired outcome of a control, not a quantitative measure. Option D is wrong because a KRI measures risk exposure or likelihood, such as the number of unpatched critical vulnerabilities, rather than the performance of the patching process.

305
Multi-Selecthard

An organization is deploying a network-based intrusion detection system (NIDS). The security team must decide on placement and configuration. Which THREE considerations are critical for effective NIDS deployment?

Select 3 answers
A.Using a network tap or SPAN port to monitor traffic without introducing latency
B.Placing the NIDS inline to block malicious traffic immediately
C.Configuring the NIDS to drop packets that match attack signatures
D.Placing the NIDS on the internal network behind the firewall to detect insider threats
E.Tuning signatures to reduce false positives relevant to the environment
AnswersA, D, E

A tap or SPAN port copies traffic to the NIDS passively, so monitoring introduces no inline latency or single point of failure. This satisfies the deployment constraint of inspecting traffic without disrupting production forwarding paths.

Why this answer

Option A is correct because a NIDS is a passive monitoring technology, so it must receive a copy of traffic via a network TAP or a switch SPAN/mirror port; this preserves the monitored link's performance and avoids introducing latency or a failure point. Option D is correct because placing the NIDS behind the firewall on internal segments lets it inspect east-west traffic and detect insider threats or compromised hosts that perimeter filtering would miss. Option E is correct because signature tuning is essential: enabling only signatures relevant to the environment's OS, applications, and protocols reduces false positives and alert fatigue, keeping the IDS effective.

Option B is not correct because inline placement is characteristic of an intrusion prevention system (IPS), not a NIDS, and it adds a potential latency and availability risk. Option C is not correct because dropping packets is an IPS blocking action; a NIDS only detects and alerts and cannot drop traffic.

Exam trap

SSCP often tests whether candidates confuse NIDS (detect and alert) with IPS (detect and block), leading them to select inline placement or packet-dropping options that are IPS characteristics.

306
MCQeasy

Which term describes the process of verifying the identity of a user, system, or entity?

A.Authorization
B.Authentication
C.Identification
D.Accountability
AnswerB

Authentication establishes and verifies a claimed identity by validating credentials such as passwords, certificates or biometrics, directly satisfying the stem's requirement to verify a user, system or entity. It is distinct from authorisation, which grants access rights after identity is confirmed, and from identification, which merely presents an identity claim.

Why this answer

Authentication is the process of verifying a claimed identity — typically by validating credentials such as passwords, biometrics, or tokens against stored data. It answers the question 'Are you who you say you are?' Identification is the prior step of claiming an identity, and authorization determines what that identity can do.

Exam trap

SSCP often tests the distinction between identification, authentication, authorization, and accountability — candidates frequently confuse authentication (verifying identity) with authorization (granting permissions) or identification (claiming identity).

How to eliminate wrong answers

Option A is wrong because authorization determines what resources or actions an authenticated identity is permitted to access — it happens after authentication and does not verify identity. Option C is wrong because identification is the act of claiming an identity (e.g., entering a username), which precedes and is distinct from verifying it. Option D is wrong because accountability is the ability to trace actions to a specific identity through logging and auditing, not the verification process itself.

307
MCQmedium

An organization's security policy requires that all portable media containing sensitive data be encrypted. Which type of control does this requirement represent?

A.Detective control
B.Administrative control
C.Technical control
D.Physical control
AnswerB

Administrative controls are policy-level directives governing behaviour, and the stem's requirement is precisely a mandated rule rather than a technical mechanism. Encryption itself is the technical control; the policy compelling its use on portable media is administrative. It satisfies the constraint by defining expected practise without enforcing it through hardware or software.

Why this answer

This requirement is an administrative control because it is a policy mandate that defines rules and procedures for handling sensitive data. Administrative controls are management directives, such as security policies, standards, and guidelines, that govern behavior and processes. The encryption itself is a technical control, but the requirement to encrypt is a policy statement, which falls under administrative controls.

Exam trap

ISC2 SSCP exams test the distinction between administrative and technical controls. The requirement to encrypt is a policy (administrative control), while the encryption algorithm itself is a technical control. Candidates often select 'Technical control' because they focus on the encryption mechanism rather than the mandate.

How to eliminate wrong answers

Option A is wrong because detective controls are designed to identify and alert on security incidents after they occur (e.g., audit logs, intrusion detection systems), not to mandate encryption. Option C is wrong because technical controls are the actual mechanisms (e.g., BitLocker, AES-256 encryption software) that enforce the policy, not the policy requirement itself. Option D is wrong because physical controls protect assets through tangible means (e.g., locks, guards, safes), not through policy directives about data encryption.

308
MCQmedium

To prevent VM escape attacks in a virtualized environment, which of the following is the most critical security measure?

A.Disable unnecessary VM guest tools
B.Apply the latest patches to the hypervisor
C.Use VLAN segmentation for VM networks
D.Use snapshots for quick recovery
AnswerB

Hypervisor patches close the vulnerabilities that let guest code break out of its VM boundary and reach the host. Since the hypervisor is the isolation layer itself, keeping it patched directly addresses the VM escape constraint in the stem.

Why this answer

The hypervisor is the software layer that creates and runs virtual machines, and it is the primary target for VM escape attacks because it sits between the guest VMs and the host hardware. A vulnerability in the hypervisor (e.g., in its emulation of devices or in its memory management) can allow a guest VM to break out and execute code on the host. Applying the latest patches to the hypervisor directly addresses these vulnerabilities, making it the most critical measure to prevent VM escape.

Without patching, other measures like network segmentation or disabling guest tools do not fix the underlying exploitable flaw.

Exam trap

SSCP often tests the misconception that network segmentation or guest hardening alone can prevent VM escape, when the root cause is hypervisor vulnerabilities that require patching.

How to eliminate wrong answers

Option A is wrong because disabling unnecessary VM guest tools reduces the attack surface within the guest but does not address hypervisor vulnerabilities that enable escape; guest tools are not the primary vector for escape. Option C is wrong because VLAN segmentation is a network control that limits lateral movement between VMs but does nothing to prevent a VM from escaping to the host via a hypervisor exploit. Option D is wrong because snapshots provide recovery and rollback capabilities after an incident, but they do not prevent the escape from occurring in the first place.

309
MCQeasy

Which UDP port is used by the Dynamic Host Configuration Protocol (DHCP) for server communication?

A.161
B.69
C.53
D.67
AnswerD

DHCP servers listen on UDP port 67 for client requests, while clients use port 68 to receive replies. This satisfies the stem's requirement for the server-side communication port, distinguishing the server's listening socket from the client's response socket.

Why this answer

DHCP servers listen on UDP port 67 for client requests, while clients use UDP port 68. When a client broadcasts a DHCPDISCOVER message, it is sent from source port 68 to destination port 67. The server responds with a DHCPOFFER from port 67 to port 68.

Therefore, port 67 is the correct answer for server communication.

Exam trap

SSCP often tests the specific UDP port numbers for common protocols, and candidates frequently confuse DHCP server port 67 with client port 68 or with other well-known ports like 53 (DNS) or 69 (TFTP).

How to eliminate wrong answers

Option A is wrong because UDP port 161 is used by SNMP (Simple Network Management Protocol) for agent queries, not DHCP. Option B is wrong because UDP port 69 is used by TFTP (Trivial File Transfer Protocol) for file transfers, not DHCP. Option C is wrong because UDP port 53 is used by DNS (Domain Name System) for name resolution, not DHCP.

310
MCQmedium

A security analyst is reviewing a digital signature implementation. The signer uses their private key to encrypt the hash of a message. What does the recipient use to verify the signature?

A.The recipient's private key
B.The signer's private key
C.The recipient's public key
D.The signer's public key
AnswerD

The recipient decrypts the signature with the signer's public key, recovering the hash, then compares it against a hash they compute over the message. Matching hashes confirm integrity and that only the private key holder could have signed.

Why this answer

Digital signatures use asymmetric cryptography where the signer encrypts the message hash with their private key. The recipient decrypts that encrypted hash using the signer's public key, then compares it to a locally computed hash of the received message. If they match, the signature is verified, proving both authenticity and integrity.

Exam trap

Candidates often confuse the roles of keys in digital signatures, mistakenly thinking the recipient uses their own private key or the signer's private key for verification. In asymmetric cryptography, signature verification always uses the signer's public key.

How to eliminate wrong answers

Option A is wrong because the recipient's private key is used for decryption of data encrypted with the recipient's public key, not for verifying a signature from another party. Option B is wrong because the signer's private key is kept secret and used only by the signer to create the signature; sharing it would compromise the entire system. Option C is wrong because the recipient's public key is used by others to encrypt data for the recipient, not to verify a signature created by a different entity.

311
MCQeasy

An organization implements a new security policy requiring all portable storage devices to be encrypted. Which of the following is the MOST effective control to enforce this policy?

A.Distribute a memo to all employees about the policy.
B.Configure Group Policy to require BitLocker encryption on removable drives.
C.Enable auditing for removable drive usage.
D.Enable BitLocker on all laptops.
AnswerB

Group Policy's Removable Drive Encryption settings enforce BitLocker at the point of use, blocking write access to unencrypted devices and silently encrypting them on insertion. This satisfies the policy's requirement for mandatory encryption across all portable storage, rather than relying on user compliance or post-incident detection.

Why this answer

Configuring Group Policy to require BitLocker encryption on removable drives is the most effective control because it enforces the encryption policy automatically and centrally across all domain-joined systems, preventing users from bypassing the requirement. Unlike a memo or auditing, Group Policy provides a technical enforcement mechanism that blocks unencrypted removable media from being used, ensuring compliance without relying on user discretion.

Exam trap

The trap here is that candidates often confuse 'encrypting the system drive' (Option D) with 'encrypting removable drives,' or they assume auditing (Option C) is a preventive control rather than a detective one.

How to eliminate wrong answers

Option A is wrong because distributing a memo is an administrative control that relies on user compliance and provides no technical enforcement, making it ineffective against intentional or accidental policy violations. Option C is wrong because enabling auditing for removable drive usage only logs events for review after the fact, it does not prevent unencrypted drives from being used or enforce encryption. Option D is wrong because enabling BitLocker on all laptops encrypts the system drives, not removable storage devices, and does not address the policy requirement for portable storage devices.

312
MCQhard

A company's incident response plan includes a requirement to notify law enforcement within 24 hours of certain security incidents. Which regulation most likely mandates this requirement?

A.SOX
B.PCI DSS
C.GDPR
D.HIPAA
AnswerB

PCI DSS Section 12.10.2 requires notification to law enforcement within 24 hours of a suspected breach.

Why this answer

PCI DSS Requirement 12.10.1 mandates that the incident response plan includes specific procedures to notify law enforcement within 24 hours of detecting a breach involving cardholder data. This is because PCI DSS is a contractual security standard for entities that handle payment card information, and timely law enforcement notification is critical for forensic investigation and legal compliance in payment card fraud cases.

Exam trap

The trap here is that candidates confuse the 24-hour law enforcement notification requirement with GDPR's 72-hour breach notification to the supervisory authority, or assume HIPAA's 60-day rule applies to all healthcare data incidents, when PCI DSS is the only standard with a specific 24-hour law enforcement notification mandate for payment card breaches.

How to eliminate wrong answers

Option A is wrong because SOX (Sarbanes-Oxley Act) focuses on financial reporting accuracy and internal controls for publicly traded companies, not on specific incident notification timelines to law enforcement. Option C is wrong because GDPR requires notification to the supervisory authority within 72 hours of a personal data breach, but it does not mandate law enforcement notification within 24 hours. Option D is wrong because HIPAA requires notification to affected individuals and the Department of Health and Human Services within 60 days for breaches of protected health information, not law enforcement within 24 hours.

313
MCQmedium

A company wants to implement a security baseline for its Windows servers. Which of the following frameworks is most commonly used for this purpose?

A.CIS Benchmarks
B.ISO 27001
C.ITIL
D.COBIT
AnswerA

CIS Benchmarks publish consensus-derived, platform-specific secure configuration settings for Windows Server, covering registry, account and service hardening. They map directly to the stem's requirement for a commonly used Windows server baseline, unlike broader governance frameworks that prescribe no technical settings.

Why this answer

CIS Benchmarks are widely adopted security configuration guidelines for various systems, including Windows servers. They provide Level 1 (basic) and Level 2 (defense-in-depth) recommendations.

314
MCQhard

A network architect is designing a solution to protect against ARP spoofing attacks on a flat Layer 2 network. The architect wants to ensure that only valid IP-to-MAC address mappings are used by hosts. Which feature should be enabled on the switches?

A.802.1X authentication
B.DHCP snooping
C.Dynamic ARP Inspection (DAI)
D.Port security
AnswerC

Dynamic ARP Inspection (DAI) validates ARP packets on untrusted ports by comparing the IP-to-MAC binding against a trusted database, typically built by DHCP snooping. It drops ARP packets with invalid mappings, preventing ARP spoofing attacks. DAI is the specific feature designed to protect against ARP spoofing on Layer 2 switches, making it the correct choice for this scenario.

Why this answer

Dynamic ARP Inspection (DAI) is the switch feature specifically designed to prevent ARP spoofing by validating ARP packets against a trusted binding table. It drops packets with invalid IP-to-MAC mappings, ensuring that hosts only receive legitimate ARP information. The other options do not provide this capability, although DHCP snooping is often used to build the binding table that DAI relies on.

Exam trap

The trap here is confusing ARP spoofing mitigation with general Layer 2 security features like port security or DHCP snooping, which address different threats.

315
MCQmedium

An organization is implementing a secure software development lifecycle (SDLC). Which activity should be performed during the design phase to minimize security flaws?

A.Perform threat modeling to identify potential attack vectors.
B.Run dynamic application security testing (DAST) tools.
C.Apply security patches to the development environment.
D.Conduct a code review for security vulnerabilities.
AnswerA

Threat modelling systematically examines data flows and trust boundaries to expose attack vectors before code exists, satisfying the design-phase constraint of minimising flaws at their cheapest point of correction. Unlike testing or code review, it operates on architecture rather than implementation, so weaknesses are eliminated while changes remain inexpensive.

Why this answer

Threat modeling is a proactive security activity performed during the design phase to identify potential attack vectors, trust boundaries, and threats before any code is written. By analyzing the system architecture and data flows, teams can mitigate security flaws early, reducing the cost and effort of fixing vulnerabilities later in the SDLC.

Exam trap

ISC2 often tests the distinction between design-phase activities (like threat modeling) and implementation or testing-phase activities (like code review or DAST), so the trap is assuming that any security testing or patching belongs in the design phase.

How to eliminate wrong answers

Option B is wrong because dynamic application security testing (DAST) is a runtime testing activity performed after the application is built, not during the design phase. Option C is wrong because applying security patches to the development environment is an operational security task that maintains the integrity of the development infrastructure, not a design-phase activity to minimize flaws in the application itself. Option D is wrong because code review for security vulnerabilities is performed during the implementation phase, after code has been written, not during the design phase.

316
MCQhard

A hospital wants clinicians to reach patient records from any ward workstation without signing in repeatedly, but it also wants a single authoritative source of identity so that disabling an employee in the human resources system immediately removes clinical access. The identity team proposes using the Lightweight Directory Access Protocol (LDAP) as that authoritative store. Which statement best describes what LDAP provides in this design?

A.LDAP is a hierarchical directory that can serve as the authoritative identity store and support authentication binds, but it does not by itself provide single sign-on or session management
B.LDAP provides the ticket-granting service that lets users obtain service tickets for clinical applications
C.LDAP issues signed assertions that workstations present to each other to establish single sign-on sessions
D.LDAP synchronizes credentials to each workstation so that local validation removes the need for a central authority
AnswerA

LDAP defines a directory information tree and operations such as bind, search, and modify, so it can hold accounts and validate credentials across the hospital. It is not a session or token service, so single sign-on across wards still requires an additional component such as Kerberos or a federation protocol layered on top of the directory.

Why this answer

The design needs an authoritative account repository plus a separate mechanism for cross-workstation session continuity. LDAP supplies the hierarchical directory and the bind operation that validates credentials, and disabling an account in that directory can take effect immediately. Single sign-on and session handling must come from an additional service, so the option that separates those responsibilities is the accurate description.

Exam trap

The trap here is conflating directory services with authentication frameworks, assuming that because LDAP stores passwords it must also deliver single sign-on tokens.

317
MCQmedium

You are a risk analyst at a healthcare organization. The organization recently deployed a new electronic health records (EHR) system. During the first month of operation, the IT helpdesk received multiple reports from doctors that the system becomes unresponsive for 10-15 seconds several times a day. The EHR vendor attributes this to insufficient database connection pooling, but the organization's system administrator notes that the database server's CPU and memory utilization never exceed 30%. The organization has a risk management policy that requires any system with availability <99.5% to be treated as a high risk. Based on initial data, the system has been unavailable for about 0.1% of the time (excluding planned maintenance). However, doctors report that the brief unresponsiveness is causing frustration and potential misdiagnosis due to interrupted workflows. You need to recommend a risk treatment approach. What should you do?

A.Accept the current risk because the system meets the 99.5% availability threshold
B.Reduce the risk by implementing a load balancer and additional application servers
C.Document the system as high risk and require immediate remediation, such as upgrading the database server hardware
D.Conduct a deeper analysis to quantify the impact of these brief outages on clinical workflows and patient safety, then reassess risk
AnswerD

The reported unresponsiveness falls outside the availability metric, so its clinical impact is unquantified. Deeper analysis linking these brief outages to workflow disruption and patient safety, followed by reassessment, satisfies the policy's requirement to treat availability risk rigorously before selecting a treatment.

Why this answer

The risk management policy defines high risk based on availability <99.5%, and the system currently shows 99.9% availability (0.1% unavailability). However, the brief 10-15 second unresponsiveness may still pose a clinical safety risk that is not captured by a simple uptime metric. A deeper analysis is required to quantify the actual impact on clinical workflows and patient safety before deciding on risk treatment, as the policy may need to consider functional availability rather than just binary uptime.

Exam trap

The trap here is that candidates focus on the 99.5% availability threshold and assume the risk is acceptable (Option A) or immediately high (Option C), without recognizing that the policy requires a risk assessment that includes impact analysis, and that the technical symptom (connection pooling) may not be resolved by hardware upgrades or load balancers.

How to eliminate wrong answers

Option A is wrong because accepting the risk based solely on the 99.5% availability threshold ignores the qualitative reports of frustration and potential misdiagnosis; the policy may require a risk assessment that includes impact on patient safety, not just uptime percentage. Option B is wrong because implementing a load balancer and additional application servers addresses a different problem (scalability under load) while the vendor attributes the issue to insufficient database connection pooling, which is a database-tier configuration problem, not an application-tier capacity issue. Option C is wrong because documenting the system as high risk and requiring immediate hardware upgrade is premature without first quantifying the clinical impact; the database server CPU and memory are below 30%, indicating the bottleneck is likely connection pooling configuration, not hardware capacity.

318
MCQmedium

A security engineer is configuring an IPsec VPN between two offices to protect data in transit. The requirement is to ensure that packets cannot be modified or replayed by an attacker. Which security service should be enabled in the IPsec configuration?

A.Secure Hash Algorithm 2 (SHA-2) in tunnel mode
B.Authentication Header (AH)
C.Internet Key Exchange (IKE) version 2
D.Encapsulating Security Payload (ESP) with confidentiality only
AnswerB

AH provides data integrity and authentication for IP packets, including protection against replay attacks by using a sequence number. It ensures that packets cannot be modified without detection. In this scenario, the requirement is specifically to prevent modification and replay, making AH the appropriate choice. However, AH does not provide confidentiality, so if encryption were also required, ESP would be needed.

Why this answer

The Authentication Header (AH) provides data integrity and authentication, and includes a sequence number to prevent replay attacks. In an IPsec VPN, AH ensures that packets cannot be altered in transit without detection. While ESP can also provide integrity and replay protection when configured with authentication, the scenario specifically asks for a service to prevent modification and replay, and AH is the dedicated protocol for that purpose.

ESP is more commonly used because it also offers confidentiality, but AH alone meets the stated requirement.

Exam trap

The trap here is assuming that ESP always provides integrity and replay protection, but ESP can be configured with confidentiality only, which lacks those services.

319
MCQhard

A security auditor reviews a system that uses HMAC-SHA256 for message authentication. Which property does HMAC provide that a simple hash of the message does not?

A.Confidentiality
B.Non-repudiation
C.Integrity and authentication using a shared secret
D.Forward secrecy
AnswerC

HMAC mixes the message with a shared secret key before hashing, so it verifies both integrity and origin authenticity between parties holding that key. A plain hash provides integrity checking only, and anyone can recompute it, giving no authentication.

Why this answer

HMAC-SHA256 uses a shared secret key combined with the message before hashing, which provides both integrity (detecting tampering) and authentication (verifying the sender knows the secret). A simple hash of the message alone offers integrity but no authentication, because anyone can compute the same hash without a secret. Thus, HMAC adds authentication via the shared secret, making option C correct.

Exam trap

The trap here is that candidates confuse integrity (provided by any hash) with authentication (which requires a shared secret), leading them to think a simple hash is sufficient for message authentication, but HMAC specifically adds the keyed property.

How to eliminate wrong answers

Option A is wrong because HMAC does not provide confidentiality; it does not encrypt the message, only authenticates it. Option B is wrong because non-repudiation requires asymmetric cryptography (e.g., digital signatures) to bind a message to a specific entity, whereas HMAC uses a shared symmetric key and cannot prove which party created it. Option D is wrong because forward secrecy is a property of key exchange protocols (e.g., Diffie-Hellman ephemeral) that ensures session keys are not compromised if long-term keys are leaked; HMAC does not provide forward secrecy.

320
Multi-Selectmedium

A security engineer is hardening a Windows server. Which TWO actions should be taken to reduce the attack surface? (Select TWO.)

Select 2 answers
A.Increase the number of active user accounts for auditing
B.Enable auto-run for removable media to improve user convenience
C.Disable unnecessary services and accounts
D.Apply the latest security patches
E.Install additional third-party software for monitoring
AnswersC, D

Disabling unnecessary services and accounts removes unused listening ports and dormant credentials, directly shrinking exploitable entry points. This satisfies the hardening requirement by eliminating attack vectors that patching alone cannot address, since unused services still expose the Windows server.

Why this answer

Option C is correct because disabling unnecessary services and accounts directly shrinks the attack surface by removing exploitable entry points, listening ports, and credentials that attackers could abuse for privilege escalation or lateral movement. Option D is correct because applying the latest security patches remediates known vulnerabilities (e.g., remote code execution flaws) that malware and threat actors actively exploit, which is a foundational hardening step. Option A is wrong because creating more active user accounts expands the attack surface and increases credential-management risk rather than reducing it.

Option B is wrong because enabling AutoRun for removable media facilitates malware propagation via USB drives and should typically be disabled. Option E is wrong because installing additional third-party software adds new code, services, and potential vulnerabilities, enlarging rather than reducing the attack surface.

Exam trap

SSCP often tests whether candidates recognize that adding software, accounts, or convenience features increases attack surface — the trap is picking options that sound like monitoring or auditing improvements but actually expand risk.

321
MCQmedium

A system administrator needs to ensure that a Linux server is hardened against common attacks. Which configuration change is MOST effective in preventing privilege escalation via SUID binaries?

A.Enable auditd to log all SUID executions.
B.Set the umask to 077 for all users.
C.Mount the /tmp and /var partitions with the 'nosuid' option.
D.Remove all SUID binaries from the system.
AnswerC

Mounting /tmp and /var with nosuid blocks setuid execution on world-writable and service-writable filesystems, directly preventing attackers from dropping SUID binaries there to escalate privileges. This satisfies the hardening constraint by removing an entire privilege-escalation vector rather than merely restricting individual binaries.

Why this answer

Mounting partitions like /tmp and /var with the 'nosuid' option prevents SUID and SGID bits from taking effect on files stored there. Since attackers often place malicious SUID binaries in world-writable directories to escalate privileges, this configuration blocks the execution of such binaries regardless of their permissions. This is more effective than logging or removing all SUID binaries, as it proactively neutralizes a common attack vector without breaking system functionality.

Exam trap

The trap here is that candidates may think logging (auditd) or removing all SUID binaries is a viable solution, but the exam tests the understanding that 'nosuid' is a practical, targeted control that prevents exploitation without breaking legitimate system functionality.

How to eliminate wrong answers

Option A is wrong because enabling auditd to log all SUID executions only provides visibility into when SUID binaries are run; it does not prevent privilege escalation, as the binaries still execute with elevated privileges. Option B is wrong because setting the umask to 077 for all users restricts default file permissions for new files but does not affect existing SUID binaries or prevent their execution, nor does it remove the SUID bit from files already present. Option D is wrong because removing all SUID binaries from the system is impractical and often breaks essential system utilities (e.g., sudo, passwd, ping) that legitimately require the SUID bit to function; a more targeted approach like using 'nosuid' on specific partitions is preferred.

322
MCQeasy

Which physical security control is designed to prevent tailgating by allowing only one person to enter at a time?

A.CCTV camera
B.Security guard
C.Biometric reader
D.Mantrap
AnswerD

A mantrap uses two interlocking doors with an occupancy sensor, admitting one person into a holding vestibule before the second door releases. This directly enforces the single-person entry constraint that defeats tailgating, unlike turnstiles or access badges, which cannot verify that only one individual passes per authentication.

Why this answer

A mantrap (also called an access control vestibule or airlock) is a small enclosed space with two interlocking doors that allows only one person through at a time, directly preventing tailgating. The first door must close and the person must be authenticated before the second door opens, so an unauthorized follower cannot slip in behind an authorized user. This is the physical control explicitly designed for anti-tailgating.

Exam trap

SSCP often tests the distinction between preventive and detective physical controls — candidates pick CCTV or guards because they 'watch the door,' but only a mantrap physically enforces one-person-at-a-time entry.

How to eliminate wrong answers

Option A is wrong because CCTV cameras are detective controls that record activity for later review; they do not physically prevent a second person from entering. Option B is wrong because a security guard is a deterrent and detective control that relies on human vigilance, which can be bypassed or distracted, and does not mechanically enforce one-person-at-a-time entry. Option C is wrong because a biometric reader authenticates an individual but does not by itself stop a second person from walking through the same open door behind the authenticated user — tailgating remains possible without a physical barrier.

323
Multi-Selectmedium

Which THREE of the following are examples of detective controls?

Select 3 answers
A.Intrusion detection system (IDS)
B.Security information and event management (SIEM)
C.Data encryption at rest
D.Log monitoring and analysis
E.Firewall with default-deny rule
AnswersA, B, D

An IDS monitors network or host activity and raises alerts when it identifies malicious patterns, identifying events after they occur rather than blocking them. This detection-after-the-fact behaviour is what classifies it as a detective control rather than a preventive one.

Why this answer

An intrusion detection system (IDS) is a detective control because it monitors network or host activity and generates alerts when it identifies suspicious patterns or known attack signatures, without blocking the traffic itself. A security information and event management (SIEM) system is also detective: it aggregates and correlates logs from multiple sources and applies rules or analytics to identify and alert on security incidents. Log monitoring and analysis is detective by definition, since reviewing and correlating log data (e.g., via syslog, Windows Event Log, or audit trails) is how organizations discover that an event has occurred.

By contrast, data encryption at rest is a preventive control that renders stored data unreadable to unauthorized parties, and a firewall with a default-deny rule is a preventive control that blocks traffic not explicitly permitted, so neither detects incidents after the fact.

Exam trap

The trap here is that candidates often confuse preventive controls (like firewalls and encryption) with detective controls, mistakenly thinking that any security tool that 'stops' or 'protects' data also detects attacks, when in fact detective controls only identify and report incidents without blocking them.

324
MCQmedium

A company has deployed an intrusion detection system (IDS) that generates numerous false positives. Which approach would best reduce false positives while maintaining detection capability?

A.Increase the alert generation threshold
B.Replace the IDS with an intrusion prevention system (IPS)
C.Disable the IDS until a full review is completed
D.Tune the IDS signatures and rules
AnswerD

Signature and rule tuning adjusts thresholds and patterns to match the environment's legitimate traffic, suppressing noisy false positives while leaving genuine attack detection intact. Disabling signatures or broad exclusions would reduce detection capability, which the stem forbids.

Why this answer

Tuning IDS signatures and rules (option D) directly addresses the root cause of false positives by refining detection patterns to match legitimate traffic more accurately. This approach preserves the IDS's ability to detect genuine threats while eliminating noise, unlike threshold adjustments which can miss low-and-slow attacks.

Exam trap

The trap here is that candidates confuse 'increasing the threshold' (option A) with tuning, but threshold adjustments are a blunt instrument that can suppress true positives, whereas signature tuning refines detection granularity without sacrificing sensitivity.

How to eliminate wrong answers

Option A is wrong because increasing the alert generation threshold reduces sensitivity across all events, potentially causing true positives (e.g., stealthy attacks) to be missed, which compromises detection capability. Option B is wrong because replacing the IDS with an IPS does not inherently reduce false positives; an IPS uses the same detection mechanisms and may block legitimate traffic if false positives persist, introducing availability risks. Option C is wrong because disabling the IDS eliminates all detection capability, leaving the network blind to attacks during the review period, which is an unacceptable security gap.

325
MCQmedium

An organization's security policy requires that all data at rest be encrypted. A database administrator objects, stating that encryption will degrade performance. What is the best response?

A.Remove the encryption requirement for databases.
B.Encrypt only the backup files, not the live database.
C.Use column-level encryption on sensitive columns only.
D.Implement transparent data encryption (TDE) to minimize performance impact.
AnswerD

TDE encrypts data at rest at the database file level, with the database engine handling cryptographic operations transparently to applications. This satisfies the policy mandating encryption of data at rest while minimising the performance overhead the administrator raised.

Why this answer

Transparent Data Encryption (TDE) encrypts data at rest at the storage layer, automatically encrypting data before it is written to disk and decrypting it when read into memory. This minimizes performance impact because encryption/decryption occurs outside the application logic and does not require schema changes, making it the best response to the DBA's concern while still meeting the policy requirement.

Exam trap

The trap here is that candidates may choose column-level encryption (Option C) thinking it is more targeted and thus less impactful, but they overlook that TDE is designed specifically to minimize performance impact by operating at the storage layer without requiring application changes.

How to eliminate wrong answers

Option A is wrong because removing the encryption requirement violates the security policy and leaves data at rest unprotected, which is not an acceptable response. Option B is wrong because encrypting only backup files leaves the live database unencrypted, failing to meet the policy's requirement that all data at rest be encrypted, and does not address the DBA's performance concern for the live database. Option C is wrong because column-level encryption can still cause significant performance overhead due to per-row encryption/decryption operations and requires application or schema changes, whereas TDE provides a more efficient, system-level solution.

326
Multi-Selectmedium

A security analyst is configuring a SIEM to detect potential insider threats. Which TWO of the following data sources would be most relevant for detecting an employee exfiltrating sensitive data via email?

Select 2 answers
A.Physical access logs
B.Email gateway logs
C.Firewall logs
D.Data Loss Prevention (DLP) logs
E.DNS logs
AnswersB, D

Email gateway logs record sender, recipient, attachment, and message metadata, revealing anomalous outbound mail volumes or destinations. This makes them directly relevant to detecting an employee exfiltrating sensitive data through email, satisfying the insider-threat detection scenario.

Why this answer

Email gateway logs (B) are directly relevant because they record SMTP metadata such as sender, recipient, subject, attachment names, and message size, allowing the SIEM to spot an employee sending sensitive files to external or personal addresses. DLP logs (D) are equally relevant because DLP engines inspect email content and attachments against policies and generate alerts when classified data (e.g., PII, credit card numbers, source code) is transmitted outside the organization. Together these two sources give both the transport-level view and the content-level detection needed for insider exfiltration via email.

Physical access logs (A) only show building entry/exit events and cannot reveal email data movement, while firewall logs (C) capture IP/port connections but not email content or recipients, and DNS logs (E) only show domain name resolutions, none of which directly evidence data exfiltration through email.

Exam trap

The exam often tests the distinction between logs that show network-level activity (firewall, DNS) versus logs that inspect content or policy violations (email gateway, DLP), leading candidates to mistakenly choose firewall logs because they see 'outbound traffic' without considering content inspection.

327
MCQeasy

Refer to the exhibit. A security administrator notices repeated events with the same failure reason for the Administrator account. What is the MOST likely type of attack?

A.Spear phishing
B.Password spraying
C.Brute force
D.Denial of service
AnswerC

Repeated authentication failures against one account, all sharing an identical failure reason, indicate automated password guessing rather than a single mistyped credential. Sustained repetition against the Administrator account is the signature of brute force, distinguishing it from password spraying or credential stuffing.

Why this answer

A brute force attack is characterized by repeated authentication attempts against the same account (here, Administrator) with the same failure reason, indicating systematic password guessing. The exhibit shows multiple failed logons for a single account, which is the classic signature of brute force. Password spraying would show one or two attempts across many accounts, not repeated failures on one account.

Exam trap

The trap here is confusing brute force with password spraying; both involve failed logons, but brute force targets one account repeatedly while spraying targets many accounts with few attempts each.

How to eliminate wrong answers

Option A is wrong because spear phishing is a targeted social engineering email attack, not repeated authentication failures in logs. Option B is wrong because password spraying attempts a few common passwords across many accounts to avoid lockouts, producing failures across multiple usernames rather than repeated failures on one account. Option D is wrong because a DoS attack aims to disrupt availability through traffic flooding, not generate repeated logon failures for a single account.

328
MCQmedium

During a security assessment, it is discovered that a Linux server has unnecessary services running, including Telnet and FTP. The server is also missing critical security patches. Which of the following is the MOST effective approach to harden this server according to industry best practices?

A.Move the server to a more secure network segment and implement network access controls.
B.Enable SELinux and configure a host-based firewall using iptables.
C.Install a host-based intrusion detection system (HIDS) to monitor for attacks.
D.Disable Telnet and FTP services, and apply all critical security patches.
AnswerD

Disabling Telnet and FTP removes insecure cleartext protocols, while patching closes known vulnerabilities. Together they eliminate both the exposed attack surface and the exploitable flaws, satisfying the hardening requirement more completely than either measure alone.

Why this answer

The most effective hardening approach directly addresses the identified vulnerabilities: disabling insecure services (Telnet and FTP, which transmit credentials in cleartext) and applying critical security patches to close known exploitable flaws. This removes the actual attack vectors rather than merely monitoring or isolating them, aligning with CIS and NIST hardening guidance.

Exam trap

SSCP often tests whether candidates choose compensating or detective controls (segmentation, HIDS) over direct remediation — the trap is overlooking that the question asks for the most effective hardening action against the specific findings.

How to eliminate wrong answers

Option A is wrong because moving the server to a segmented network with access controls reduces exposure but does not remediate the insecure services or missing patches on the host itself — the vulnerabilities remain exploitable from within the segment. Option B is wrong because enabling SELinux and configuring iptables improves host security posture but does not remove Telnet/FTP or patch the system; these are complementary controls, not the primary remediation for the stated issues. Option C is wrong because a HIDS detects and alerts on attacks but does not prevent them or fix the underlying vulnerabilities — detection without remediation leaves the server exploitable.

329
MCQeasy

In Linux, which command is used to change file permissions to restrict access so that only the owner can read and write, and the group and others have no access?

A.chmod 600 file.txt
B.chown 600 file.txt
C.umask 077 file.txt
D.setfacl -m u::rw file.txt
AnswerA

chmod 600 file.txt sets the permission bits to rw-------, giving the owner read and write while group and others receive none. The octal 6 encodes read (4) plus write (2) for the owner, and the two trailing zeros deny all group and other access, satisfying the stem's restriction requirement.

Why this answer

chmod 600 file.txt sets permissions so the owner has read and write (6 = rw-), while group and others have no permissions (0 = ---). This matches the requirement that only the owner can read and write and no one else has access. The numeric (octal) mode 600 is the standard way to express owner rw, group none, others none.

Exam trap

SSCP often tests the confusion between chmod (change permissions), chown (change ownership), and umask (set default creation mask) — candidates pick umask or chown when the question asks to modify an existing file's permissions.

How to eliminate wrong answers

Option B is wrong because chown changes file ownership (user and/or group), not permissions, and '600' is not a valid chown argument. Option C is wrong because umask sets default permission bits for newly created files and directories; it does not modify an existing file's permissions and cannot be applied to a specific file like file.txt. Option D is wrong because setfacl manages access control lists for granular permissions; the syntax given only sets the owner's ACL entry to rw and does not explicitly remove group and other access, nor is it the standard command for the stated requirement.

330
Multi-Selectmedium

An organization wants to implement a hashing algorithm for integrity checks. Which of the following should be avoided due to known vulnerabilities? (Select TWO)

Select 2 answers
A.SHA-3
B.SHA-256
C.MD5
D.HMAC-SHA256
E.SHA-1
AnswersC, E

MD5 produces 128-bit digests with practical collision attacks demonstrated, so it cannot assure integrity. Its weakness against chosen-prefix collisions directly satisfies the stem's criterion of an algorithm to avoid for integrity checks due to known vulnerabilities.

Why this answer

MD5 (C) must be avoided because it is cryptographically broken: practical collision attacks (e.g., the 2004 Wang attacks and later chosen-prefix collisions) allow two different inputs to produce the same 128-bit digest, so it cannot reliably detect malicious modification. SHA-1 (E) must also be avoided because collision attacks are practical (the 2017 SHAttered attack produced two colliding PDFs), making its 160-bit digest unsuitable for integrity checks against adversaries. SHA-3 (A) and SHA-256 (B) are unmarked because they are current, collision-resistant hash functions from the SHA-2/SHA-3 families and are appropriate for integrity verification.

HMAC-SHA256 (D) is unmarked because it is a keyed MAC built on SHA-256 that provides both integrity and authenticity and has no known practical breaks.

Exam trap

The trap here is that candidates often assume SHA-1 is still acceptable because it was once widely used, but the SSCP exam expects you to know that both MD5 and SHA-1 are broken for collision resistance and should be avoided.

331
MCQeasy

Which access control model enforces the principle of least privilege by granting permissions based on job functions and requires separation of duties?

A.Attribute-Based Access Control (ABAC)
B.Role-Based Access Control (RBAC)
C.Mandatory Access Control (MAC)
D.Discretionary Access Control (DAC)
AnswerB

RBAC assigns permissions to roles defined by job function rather than to individuals, so users receive only the access their duties require. Roles can also be structured to enforce separation of duties, satisfying both least privilege and the split-responsibility constraint in the stem.

Why this answer

Role-Based Access Control (RBAC) grants permissions based on job functions or roles, enforcing least privilege by giving users only the access their role requires. RBAC also supports separation of duties by ensuring no single role has excessive privileges, and by requiring multiple roles for sensitive operations. This matches the question's description precisely.

Exam trap

SSCP often tests the distinction between RBAC and ABAC/MAC/DAC, so candidates must recognize that 'job functions' and 'separation of duties' are signature RBAC characteristics, not attributes or labels.

How to eliminate wrong answers

Option A is wrong because ABAC grants access based on attributes (user, resource, environment) evaluated by policies, which is more dynamic than role-based and does not inherently enforce separation of duties through job functions. Option C is wrong because MAC uses security labels and clearances assigned by a central authority, enforcing confidentiality levels rather than job-function roles. Option D is wrong because DAC lets resource owners assign permissions at their discretion, which does not enforce least privilege or separation of duties systematically.

332
MCQmedium

A security administrator at a healthcare company must ensure that audit logs from a critical patient-record system are retained for seven years and cannot be altered even by system administrators. Which solution BEST meets these requirements?

A.Use a SIEM with role-based access control (RBAC) to limit who can view or delete logs.
B.Enable local logging with daily log rotation and store the logs on a separate encrypted volume.
C.Configure the system to send logs to a remote syslog server with file permissions restricted to root.
D.Implement a write-once read-many (WORM) storage solution for log archival with a seven-year retention policy.
AnswerD

WORM storage physically or logically prevents modification or deletion of data once written, directly satisfying the immutability requirement even against privileged administrators. A seven-year retention policy ensures compliance with the stated retention period. This is the standard approach for tamper-evident audit log archiving in regulated industries.

Why this answer

WORM storage ensures that once audit logs are written, they cannot be modified or deleted, even by users with administrative privileges, directly meeting the immutability and seven-year retention requirements. Other options focus on access control or encryption but do not provide the non-repudiation and tamper-evidence needed for compliance.

Exam trap

The trap here is assuming that restricting permissions or using RBAC is sufficient to make logs tamper-proof, when in fact only WORM or similar immutable storage guarantees that even administrators cannot alter the data.

333
MCQhard

An organization uses a mantrap at its main entrance. An employee badges in, enters the first door, but then the second door fails to open. What should the employee do?

A.Return through the first door
B.Use the intercom to contact security
C.Force the second door open
D.Wait for someone to open from the other side
AnswerB

Using the intercom to contact security is the safe response when the mantrap's second door fails. A mantrap is a physical access control vestibule designed to prevent tailgating and trap intruders; remaining inside and alerting security preserves that containment. Forcing the door or exiting backwards could breach the controlled entry and defeat the mantrap's purpose.

Why this answer

In a mantrap (access control vestibule), if the second door fails to open after the first door closes, the employee should use the intercom to contact security. This ensures that security personnel can assess the situation, verify identity, and manually override the door if appropriate, while maintaining the security integrity of the mantrap.

Exam trap

The trap is choosing an action that seems convenient (like returning or waiting) but violates security protocols; candidates may not realize that contacting security is the correct procedure to maintain security and safety.

How to eliminate wrong answers

Option A is wrong because returning through the first door may not be possible if it has locked behind the employee, and it could also trigger an alarm or violate security protocols. Option C is wrong because forcing the second door open defeats the purpose of the mantrap and could cause damage or security breach. Option D is wrong because waiting for someone to open from the other side is passive and may not happen; it also bypasses security procedures.

334
MCQeasy

An organization wants to quantify the potential financial loss from a specific risk scenario. The risk team estimates that a data breach would cost $500,000 in direct expenses and that such an event is expected to occur once every five years. Which metric are they calculating?

A.Single loss expectancy (SLE)
B.Annualized loss expectancy (ALE)
C.Annualized rate of occurrence (ARO)
D.Exposure factor (EF)
AnswerB

ALE is calculated by multiplying the single loss expectancy (SLE) by the annualized rate of occurrence (ARO). Here, SLE is $500,000 and ARO is 1/5 = 0.2, so ALE = $500,000 × 0.2 = $100,000. This metric expresses the expected yearly financial loss from the risk.

Why this answer

The team is calculating annualized loss expectancy by multiplying the single loss expectancy by the annualized rate of occurrence. With an SLE of $500,000 and an ARO of 0.2 (once every five years), the ALE is $100,000. This quantifies the expected yearly financial impact and helps prioritize risk mitigation investments.

Exam trap

The trap here is selecting single loss expectancy because it matches the dollar figure in the scenario, but the question asks for the metric that incorporates the frequency of occurrence.

335
Multi-Selecteasy

Which TWO of the following are common weaknesses in cryptographic implementations that an SSCP should be aware of? (Select exactly 2.)

Select 2 answers
A.Weak random number generation
B.Improper key storage
C.Frequent rekeying
D.Using proven encryption algorithms like AES
E.Following NIST guidelines
AnswersA, B

Weak random number generation undermines cryptographic strength because predictable or low-entropy values let attackers derive keys, nonces and session tokens. This satisfies the stem's focus on implementation weaknesses rather than algorithm design flaws, since even sound ciphers such as AES fail when their random inputs are guessable.

Why this answer

Option A (Weak random number generation) is correct because cryptographic security depends on unpredictable entropy for generating keys, IVs, and nonces; if a weak or predictable PRNG (e.g., a non-cryptographic RNG or insufficient entropy source) is used, attackers can predict keys or nonces and break confidentiality or integrity. Option B (Improper key storage) is correct because even strong algorithms fail if keys are stored insecurely — for example, hard-coded in source, kept in plaintext, or left unprotected in memory or on disk — allowing attackers to recover keys and decrypt or forge data. The unmarked options do not represent weaknesses: frequent rekeying (C) actually limits exposure from key compromise, using proven algorithms like AES (D) is a recommended practice rather than a flaw, and following NIST guidelines (E) is a security best practice, not a common implementation weakness.

Exam trap

ISC2 often tests the misconception that 'using strong algorithms' or 'following standards' automatically guarantees security, when in fact implementation flaws like weak randomness or poor key management are the real vulnerabilities.

336
MCQhard

A security operations center uses a SIEM to monitor authentication activity. The team wants to detect a password spraying campaign in which a single source attempts a small number of common passwords against many different user accounts, staying below the per-account lockout threshold. Which correlation approach would BEST detect this activity?

A.Alert when a user authenticates successfully from a country where the organization has no offices
B.Alert when one source IP generates failed logons against many distinct accounts within a short window
C.Alert when any single account exceeds five failed logons within ten minutes
D.Alert when total failed logons across the environment exceed a fixed daily count
AnswerB

Password spraying is characterized by a single source touching numerous distinct accounts with few attempts each. Correlating failed authentication events by source address and counting unique targeted accounts over a short interval detects the horizontal pattern that per-account thresholds cannot see, which is why this approach best identifies the campaign described.

Why this answer

Password spraying avoids per-account lockout by trying common passwords against many accounts with only a few attempts each. The distinguishing signal is one source address generating failures across a large number of distinct accounts in a short period. Correlating failed authentications by source and counting unique usernames over a time window surfaces that horizontal pattern, whereas per-account or global thresholds do not.

Exam trap

The trap here is applying a per-account lockout-style threshold, which spraying is explicitly designed to stay beneath, instead of correlating across many accounts from one source.

337
MCQeasy

Which of the following OWASP Top 10 vulnerabilities involves an attacker sending malicious data to an interpreter as part of a command or query?

A.Security Misconfiguration
B.Injection
C.Broken Authentication
D.Cross-Site Scripting (XSS)
AnswerB

Injection flaws occur when untrusted data is sent to an interpreter as part of a command or query, causing it to execute unintended commands. This matches the stem's description of malicious data reaching an interpreter directly, distinguishing it from broken access control or misconfiguration.

Why this answer

Injection is the OWASP Top 10 category that directly involves an attacker sending malicious data to an interpreter as part of a command or query. This occurs when untrusted data is concatenated into a command or query without proper validation or parameterization, allowing the attacker to alter the intended execution. Examples include SQL injection, OS command injection, and LDAP injection, where the interpreter executes the attacker's injected commands.

The core reasoning is that the vulnerability arises from the lack of separation between data and code, enabling the attacker to control the interpreter's behavior.

Exam trap

SSCP often tests the distinction between injection attacks and other OWASP Top 10 categories like XSS, which also involve injecting malicious data but target the client-side browser rather than a server-side interpreter.

How to eliminate wrong answers

Option A is wrong because Security Misconfiguration refers to insecure default settings, incomplete configurations, or verbose error messages, not the direct injection of malicious data into an interpreter. Option C is wrong because Broken Authentication involves flaws in authentication mechanisms (e.g., weak passwords, session fixation) that allow attackers to compromise credentials or impersonate users, not the injection of data into commands or queries. Option D is wrong because Cross-Site Scripting (XSS) is a client-side code injection attack where malicious scripts are executed in a victim's browser, not an attack against a server-side interpreter via commands or queries.

338
MCQmedium

Given the exhibit, what is the most likely conclusion?

A.The SIEM alert is a false positive and can be ignored
B.The authentication server logs are misconfigured
C.The successful login is unrelated and coincidental
D.The brute-force attack was successful and the admin account may be compromised
AnswerD

Repeated failed authentications followed by a successful logon for the same admin account indicate the password was eventually guessed, so the attacker gained authenticated access. The success after many failures is the decisive evidence that the account is compromised.

Why this answer

The exhibit shows a brute-force attack with multiple failed login attempts followed by a successful login from the same source IP. This pattern indicates that the attacker likely guessed or cracked the password, making the admin account compromised. Option D is correct because the sequence of events directly correlates with a successful brute-force attack.

Exam trap

The trap here is that candidates may dismiss the successful login as a false positive or coincidence, failing to recognize that the sequential pattern of failures followed by a success from the same source is the definitive signature of a successful brute-force attack.

How to eliminate wrong answers

Option A is wrong because the alert is not a false positive; the pattern of repeated failures followed by a success is a classic indicator of a successful brute-force attack, not a benign event. Option B is wrong because the authentication server logs are not misconfigured; they correctly recorded both the failed and successful logins, which is expected behavior. Option C is wrong because the successful login is not coincidental; it is directly linked to the preceding brute-force attempts, as evidenced by the same source IP and target account.

339
MCQmedium

Which of the following is a key advantage of using a behavior-based detection approach in a User and Entity Behavior Analytics (UEBA) system?

A.Ability to detect previously unknown threats based on anomalous behavior
B.Requires less data processing than signature-based detection
C.Easier to configure and maintain
D.Lower false positive rates compared to signature-based detection
AnswerA

Behaviour-based detection builds baselines of normal user and entity activity, so deviations trigger alerts without relying on known signatures. This satisfies the stem's requirement for identifying previously unknown threats, catching novel attack patterns or compromised accounts whose activity has never been catalogued.

Why this answer

Behavior-based detection in UEBA establishes a baseline of normal user and entity activity using machine learning and statistical models. It then identifies deviations from this baseline, enabling the detection of novel or previously unknown threats, such as zero-day exploits or insider threats, without relying on pre-defined signatures.

Exam trap

The trap here is that candidates often assume behavior-based detection is easier or produces fewer false positives, but the exam emphasizes that its key advantage is detecting unknown threats, not operational simplicity or accuracy.

How to eliminate wrong answers

Option B is wrong because behavior-based detection typically requires more data processing and computational resources than signature-based detection, which simply matches patterns against a static database. Option C is wrong because behavior-based systems are more complex to configure and maintain, requiring tuning of baselines and thresholds, whereas signature-based systems are simpler to update with new signatures. Option D is wrong because behavior-based detection often produces higher false positive rates due to legitimate but unusual activities being flagged as anomalous, while signature-based detection has lower false positives for known threats but misses unknown ones.

340
MCQmedium

A cloud application uses OAuth 2.0 to authorize a third-party app to access user data. What is the primary purpose of the access token issued by the authorization server?

A.To revoke the user's access to the client application
B.To encrypt data exchanged between client and resource server
C.To grant the client application limited access to user's resources
D.To authenticate the user to the resource server
AnswerC

The access token is a credential the client presents to the resource server, conveying delegated authorisation for a defined scope and duration. It lets the third-party app reach specific user resources without exposing the user's credentials.

Why this answer

In OAuth 2.0, the access token is a credential that represents the authorization granted to the client application by the resource owner. Its primary purpose is to allow the client to access specific, scoped resources on the resource server on behalf of the user, without exposing the user's credentials. This is defined in RFC 6749, where the token encapsulates the granted permissions and scope.

Exam trap

The trap here is that candidates often confuse authentication with authorization, mistakenly believing the access token authenticates the user to the resource server, when in fact it only authorizes the client to access resources on behalf of the user.

How to eliminate wrong answers

Option A is wrong because revoking the user's access to the client application is not a function of the access token; revocation is handled via token revocation endpoints or by the authorization server invalidating the token, not by the token itself. Option B is wrong because the access token does not encrypt data; it is a bearer token that is passed in HTTP headers, and encryption of data in transit is typically handled by TLS, not by the token. Option D is wrong because the access token is not used to authenticate the user to the resource server; authentication is performed by the authorization server during the authorization grant flow, and the token only authorizes access to resources, it does not prove the user's identity.

341
MCQmedium

A security administrator needs to implement an access control model that grants access based on attributes of the user, resource, and environment, using policy rules. Which model is most appropriate?

A.Attribute-Based Access Control (ABAC)
B.Mandatory Access Control (MAC)
C.Discretionary Access Control (DAC)
D.Role-Based Access Control (RBAC)
AnswerA

ABAC evaluates policy rules against attributes of subject, object and environment, so access decisions dynamically reflect context rather than static role or label assignments. This directly satisfies the requirement to grant access based on user, resource and environmental attributes.

Why this answer

ABAC is the correct answer because it evaluates access decisions dynamically using policy rules that combine attributes of the subject (user), the object (resource), and the environment (context such as time or location). This multi-attribute, policy-driven evaluation is the defining characteristic of ABAC, typically implemented via XACML or similar policy engines. MAC, DAC, and RBAC do not natively incorporate environmental or arbitrary resource attributes into their access decisions.

Exam trap

SSCP often tests the distinction between access control models by describing the decision input — candidates who see 'role' or 'label' keywords jump to RBAC or MAC, missing that the question specifies attributes of user, resource, and environment, which uniquely identifies ABAC.

How to eliminate wrong answers

Option B is wrong because MAC bases access decisions on security labels assigned to subjects and objects (e.g., Bell-LaPadula or Biba mandatory labels), not on flexible attribute-based policy rules. Option C is wrong because DAC lets resource owners set permissions at their discretion (e.g., via ACLs), which is identity/ownership-based rather than attribute-based. Option D is wrong because RBAC grants access based on the user's assigned role, not on a combination of user, resource, and environmental attributes.

342
MCQhard

During a vulnerability scan, a security team discovers that several virtual machine snapshots contain outdated software with known vulnerabilities. Which risk is most directly associated with this scenario?

A.Resource exhaustion
B.VM sprawl
C.Vulnerability reintroduction
D.VM escape
AnswerC

Snapshots preserve a point-in-time disk state, so reverting a virtual machine restores the outdated software and its known vulnerabilities, undoing prior patching. This directly satisfies the stem's constraint: dormant snapshot images retaining vulnerable code that re-enters production upon restore, which is precisely vulnerability reintroduction.

Why this answer

Virtual machine snapshots capture the state of a VM at a point in time, including the operating system and installed software. If a snapshot contains outdated software with known vulnerabilities, restoring that snapshot or using it to create new VMs can reintroduce those vulnerabilities into the environment, even if they were previously patched. This is known as vulnerability reintroduction.

Exam trap

SSCP often tests the distinction between different VM-related risks, and candidates may confuse vulnerability reintroduction with VM sprawl or resource exhaustion, especially when snapshots are involved.

How to eliminate wrong answers

Option A is wrong because resource exhaustion refers to running out of resources like CPU, memory, or storage, which is not directly related to outdated software in snapshots. Option B is wrong because VM sprawl refers to the uncontrolled proliferation of VMs, not the reintroduction of vulnerabilities. Option D is wrong because VM escape is an exploit where an attacker breaks out of a VM to access the host, which is a different risk and not directly associated with outdated software in snapshots.

343
MCQeasy

Which of the following is a common method for implementing multi-factor authentication (MFA) using something you have and something you know?

A.Fingerprint and retina scan
B.Smart card and PIN
C.Password and security question
D.Username and password
AnswerB

A smart card satisfies the "something you have" factor, while the PIN supplies "something you know". Combining a physical token with a memorised secret meets the stem's two-factor requirement, unlike single-factor or same-category pairings. This hardware-plus-knowledge pairing is a standard MFA implementation.

Why this answer

A smart card (something you have) combined with a PIN (something you know) satisfies the two-factor requirement using two distinct authentication factor categories. This is the classic possession-plus-knowledge MFA pairing and is widely deployed in PIV/CAC and physical access systems. The other options either use two factors from the same category or only one factor.

Exam trap

SSCP often tests whether candidates recognize that two methods from the same factor category (e.g., two biometrics or two passwords) do not constitute MFA — the trap is picking an option that sounds like two factors but is actually one category.

How to eliminate wrong answers

Option A is wrong because a fingerprint and a retina scan are both inherence factors (something you are), so combining them is single-category, not true MFA. Option C is wrong because a password and a security question are both knowledge factors (something you know), so this is not multi-factor. Option D is wrong because a username and password together constitute a single knowledge factor — a username is an identifier, not an authentication factor.

344
MCQeasy

A security analyst needs to verify that a downloaded file has not been tampered with. The publisher provides a SHA-256 hash. Which property of the hash function is being relied upon?

A.Avalanche effect
B.Collision resistance
C.Second pre-image resistance
D.Pre-image resistance
AnswerC

Second pre-image resistance guarantees that an attacker cannot find a different file producing the same SHA-256 digest as the published one. That property lets the analyst detect tampering, since any altered content yields a mismatched hash.

Why this answer

When relying on a provided hash to verify file integrity, the security analyst is using second pre-image resistance. This property ensures that given a hash value (the original file's hash), it is computationally infeasible to find another input (a tampered file) that produces the same hash. Thus, if the computed hash matches the provided hash, the file is authentic and unchanged.

Collision resistance is a stronger property but not directly required here; second pre-image resistance is the exact requirement for this scenario.

Exam trap

Candidates often incorrectly choose collision resistance because it is commonly associated with hash functions. However, the specific scenario of verifying a known hash relies on second pre-image resistance, not collision resistance. Collision resistance prevents finding any two inputs with the same hash, but here the attacker is given the hash of the original and must find a different input with that same hash, which is second pre-image resistance.

How to eliminate wrong answers

Option A is wrong because the avalanche effect describes how a small change in input drastically changes the output hash, but it does not directly prevent tampering; it is a property that contributes to security but is not the primary reliance for verifying file integrity. Option C is wrong because second pre-image resistance ensures that given a message and its hash, an attacker cannot find a different message with the same hash; while important, the scenario of verifying a downloaded file against a provided hash relies on collision resistance to prevent an attacker from creating any two messages with the same hash, not just finding a second pre-image for a known message. Option D is wrong because pre-image resistance ensures that given a hash, an attacker cannot find the original input; this is irrelevant for verifying that a file has not been tampered with, as the analyst already has the file and is checking its hash against the published one.

345
Multi-Selectmedium

Which TWO of the following are key components of a configuration management database (CMDB)? (Select TWO)

Select 2 answers
A.Password hashes
B.Change request approvals
C.Relationships between configuration items
D.Incident tickets
E.Hardware inventory details such as serial numbers
AnswersC, E

Relationships between configuration items are a core CMDB component because they map dependencies and connections across the IT estate. This satisfies the stem's requirement for key components, distinguishing a CMDB from a plain asset inventory, which records items without capturing how they interlink or affect one another.

Why this answer

Option C is correct because a CMDB's defining feature is storing configuration items (CIs) together with their dependencies and relationships, which enables impact analysis and service mapping. Option E is correct because CIs include hardware assets and their attributes, such as serial numbers, model, and location, which are core inventory data held in the CMDB. Options A, B, and D are not CMDB components: password hashes belong to credential/identity stores such as Active Directory or a secrets vault, change request approvals belong to a change management/workflow system (e.g., ITIL change records), and incident tickets belong to an incident management or ITSM ticketing system, even though these tools may integrate with the CMDB.

Exam trap

The trap here is confusing the CMDB with other ITIL processes or data stores, leading candidates to select change request approvals (a change management artifact) or incident tickets (an incident management artifact) as CMDB components, when they are separate records linked to CIs but not stored within the CMDB itself.

346
MCQhard

During an incident response, a forensic analyst captures a memory dump from a compromised server. Which of the following is the MOST important step to ensure the integrity of the evidence?

A.Create a cryptographic hash of the memory dump before analysis
B.Use a write blocker when capturing the memory dump
C.Store the memory dump on the same server for easy access
D.Run antivirus on the memory dump file
AnswerA

Hashing the memory dump with a cryptographic algorithm produces a fixed digest that later re-hashing can verify, proving the image was not altered. This preserves evidential integrity, the stem's stated requirement, before any analysis touches the data.

Why this answer

Creating a cryptographic hash (e.g., SHA-256) of the memory dump immediately after capture establishes a verifiable baseline for integrity. Any subsequent modification — accidental or intentional — will change the hash, allowing the analyst to prove the evidence was not tampered with. This chain-of-custody practice is fundamental to forensic admissibility.

Exam trap

SSCP often tests whether candidates confuse disk-imaging controls (write blockers) with memory-capture integrity steps (hashing), or overlook that evidence must never be stored on the compromised host.

How to eliminate wrong answers

Option B is wrong because write blockers are used for disk imaging to prevent writes to the source drive; they are not applicable to live memory capture, which inherently reads volatile RAM and cannot be write-blocked in the same way. Option C is wrong because storing the dump on the compromised server risks tampering, loss, or destruction by the attacker and violates evidence-handling best practice — evidence must be preserved on trusted, isolated media. Option D is wrong because running antivirus on the memory dump could quarantine or alter the file, destroying its forensic value and invalidating the hash; analysis should be done on a copy in a controlled environment.

347
MCQhard

An organization is implementing an access control system where access decisions are based on the sensitivity of the resource and the clearance of the user. Which model is being used?

A.Discretionary Access Control (DAC)
B.Attribute-Based Access Control (ABAC)
C.Role-Based Access Control (RBAC)
D.Mandatory Access Control (MAC)
AnswerD

MAC bases every access decision on comparing the resource's sensitivity label with the user's clearance, both assigned by the system rather than the owner. Users cannot alter these labels, which is the defining characteristic separating MAC from discretionary or role-based models.

Why this answer

Mandatory Access Control (MAC) enforces access decisions based on comparing the sensitivity label (e.g., classification level) of the resource with the clearance level of the user. This model is non-discretionary, meaning users cannot override or delegate permissions; the system centrally controls all access according to a security policy, such as Bell-LaPadula or Biba.

Exam trap

The trap here is that candidates often confuse MAC with RBAC because both involve centralized control, but MAC uniquely relies on mandatory sensitivity labels and user clearances, not roles or user-defined permissions.

How to eliminate wrong answers

Option A is wrong because Discretionary Access Control (DAC) allows resource owners to set permissions at their discretion, not based on fixed sensitivity labels and user clearances. Option B is wrong because Attribute-Based Access Control (ABAC) evaluates policies using multiple attributes (user, resource, environment) but does not inherently require hierarchical sensitivity labels and clearances as the primary decision factor. Option C is wrong because Role-Based Access Control (RBAC) grants access based on job roles, not on the sensitivity of the resource or the clearance of the user.

348
MCQeasy

A security administrator is implementing a policy that requires all employees to use a password manager and enable multi-factor authentication. This policy is BEST described as a:

A.Data handling policy
B.Password policy
C.Social media policy
D.Remote access policy
AnswerB

A password policy defines rules for password creation, management, and authentication, including multi-factor authentication.

Why this answer

The policy requires all employees to use a password manager and enable multi-factor authentication, which directly governs the creation, storage, and authentication strength of user credentials. This is the core function of a password policy, as defined in security frameworks like NIST SP 800-53 (IA-5) and ISO 27001 (A.9.2.1). It specifically addresses password complexity, rotation, and MFA enforcement, not data classification or access methods.

Exam trap

The trap is that candidates may confuse a password policy (which includes MFA as an authentication control) with a remote access policy, because MFA is often associated with VPN logins. However, the question explicitly states the policy applies to all employees, not just remote workers, so the correct classification is a password policy.

How to eliminate wrong answers

Option A is wrong because a data handling policy governs how data is classified, stored, transmitted, and disposed of (e.g., encryption at rest, data retention schedules), not the authentication credentials used to access systems. Option C is wrong because a social media policy regulates employee behavior on public platforms (e.g., posting confidential information, representing the company), not internal authentication mechanisms. Option D is wrong because a remote access policy defines the methods and controls for connecting to the corporate network from external locations (e.g., VPN protocols, split tunneling), not the password and MFA requirements that apply to all access, including local.

349
Multi-Selectmedium

A risk analyst is conducting a quantitative risk analysis for a data center. The analyst needs to calculate the annualized loss expectancy (ALE). Which TWO of the following values are required to compute ALE? (Choose two.)

Select 2 answers
A.Return on security investment (ROSI)
B.Single loss expectancy (SLE)
C.Annualized rate of occurrence (ARO)
D.Asset value (AV)
E.Exposure factor (EF)
AnswersB, C

ALE is calculated as SLE multiplied by the annualized rate of occurrence (ARO). Therefore, SLE is a required input. SLE represents the monetary loss from a single incident, including costs such as downtime, data recovery, and reputational damage. Without SLE, the analyst cannot determine the expected yearly loss from a given risk, making this a necessary component.

Why this answer

The annualized loss expectancy is computed by multiplying the single loss expectancy by the annualized rate of occurrence. SLE represents the expected loss from one incident, while ARO estimates how many times that incident will occur in a year. Together they yield the expected yearly financial impact of a risk.

Exposure factor and asset value feed into SLE, but are not direct inputs to ALE. ROSI is a separate metric for evaluating controls.

Exam trap

The trap here is including exposure factor or asset value as direct inputs to ALE, when they are actually components of SLE, which in turn feeds ALE.

350
MCQmedium

Which of the following best describes the purpose of a Hardware Security Module (HSM) in key management?

A.To store cryptographic keys in a secure, tamper-resistant environment
B.To replace public key infrastructure (PKI)
C.To accelerate network traffic encryption
D.To generate random numbers for non-cryptographic use
AnswerA

An HSM is a dedicated physical device that generates, stores and processes cryptographic keys inside tamper-resistant hardware, never exposing them in plaintext. This satisfies the key management requirement by protecting keys from extraction, satisfying compliance mandates such as FIPS 140-2.

Why this answer

A Hardware Security Module (HSM) is a dedicated, tamper-resistant hardware appliance designed to securely generate, store, and manage cryptographic keys throughout their lifecycle. By keeping keys within the HSM's physical and logical boundaries, it prevents unauthorized extraction even if the host system is compromised, which is the core purpose of an HSM in key management.

Exam trap

The trap here is that candidates confuse an HSM's ability to perform cryptographic operations (like encryption or signing) with its primary purpose, which is secure key storage and lifecycle management, not performance acceleration or replacing PKI.

How to eliminate wrong answers

Option B is wrong because an HSM does not replace Public Key Infrastructure (PKI); PKI is a framework of policies, roles, and software (e.g., Certificate Authorities) for managing digital certificates, while an HSM is a hardware device that can be used to protect the private keys within a PKI. Option C is wrong because accelerating network traffic encryption is not the primary purpose of an HSM; that function is typically performed by dedicated cryptographic accelerators or offload engines (e.g., Intel QAT), whereas an HSM focuses on secure key storage and limited cryptographic operations. Option D is wrong because while HSMs can generate random numbers, they are used for cryptographic purposes (e.g., key generation, nonces) and not for non-cryptographic use; general random number generation for non-cryptographic tasks is done by simpler PRNGs like those in standard OS libraries.

351
Multi-Selecteasy

A security administrator is designing physical security for a high-security area. Which TWO controls are most effective for preventing unauthorized entry? (Select TWO)

Select 2 answers
A.Biometric reader
B.Visitor log
C.Clean desk policy
D.Mantrap
E.Screen locks
AnswersA, D

A biometric reader verifies a unique physiological trait, so credentials cannot be shared, copied or lost like badges and PINs. This satisfies the high-security constraint by binding entry to a specific enrolled person, preventing unauthorised individuals from gaining access with stolen or borrowed credentials.

Why this answer

A biometric reader (A) is correct because it authenticates identity using a unique physical trait such as a fingerprint or iris pattern, which cannot be easily shared, stolen, or forged like a badge or password, making it a strong preventive access control for a high-security area. A mantrap (D) is correct because it is an interlocking double-door vestibule that admits only one person at a time and prevents tailgating or piggybacking, directly stopping unauthorized individuals from following an authorized person into the secured space. Together these controls enforce both identity verification and single-person entry, which is why they are the most effective preventive measures listed.

A visitor log (B) is only a detective/administrative record and does nothing to stop someone from entering. A clean desk policy (C) protects information from casual observation or theft but does not control physical entry. Screen locks (E) are a logical access control that secures a workstation session, not a barrier to entering a room.

Exam trap

The trap here is confusing administrative/detective controls (visitor logs, clean desk, screen locks) with preventive physical controls — SSCP often tests whether candidates can classify controls by function (preventive vs. detective vs. administrative) rather than just recognizing security-sounding terms.

352
MCQeasy

A system administrator needs to grant a temporary contractor access to a specific shared folder for two weeks. Which access control approach is most appropriate?

A.Create a new role with access to the folder and assign the contractor to that role
B.Create a temporary user account with an expiration date and grant NTFS permissions
C.Use mandatory access control (MAC) to enforce a security label for the contractor
D.Configure the folder with discretionary access control (DAC) and let the contractor request access
AnswerB

A time-bound account with an expiration date enforces automatic revocation after two weeks, satisfying the temporary access constraint without manual cleanup. NTFS permissions then scope the contractor to the specific shared folder, applying least privilege. Together they deliver both automatic expiry and granular resource-level authorisation.

Why this answer

Creating a temporary user account with an expiration date directly addresses the need for time-limited access. Granting NTFS permissions on the specific shared folder provides granular, least-privilege access control. This approach ensures the account is automatically disabled after two weeks, reducing administrative overhead and security risk.

Exam trap

The trap here is that candidates often choose role-based access control (RBAC) as a best practice, but fail to recognize that creating a new role for a single temporary user is an anti-pattern that violates role-based design principles and does not inherently enforce time limits.

How to eliminate wrong answers

Option A is wrong because creating a new role for a single temporary contractor violates the principle of role engineering—roles should be based on job functions, not individuals, and this approach adds unnecessary complexity without addressing the time limit. Option C is wrong because mandatory access control (MAC) uses system-wide security labels enforced by the operating system, which is overly rigid for a simple temporary access need and requires significant configuration overhead. Option D is wrong because discretionary access control (DAC) allows the resource owner to grant permissions, but relying on the contractor to request access introduces delays and lacks automatic expiration, leaving the folder exposed after the two-week period.

353
MCQmedium

In the Bell-LaPadula model, which property prevents a subject from reading an object at a higher classification level?

A.The *-property (no write down)
B.The Discretionary Security Property
C.The Simple Security Property (no read up)
D.The Lattice Security Property
AnswerC

The Simple Security Property forbids a subject at a lower classification from reading an object at a higher level, the no read up rule. This directly prevents upward information flow, which is the specific restriction the question describes.

Why this answer

The Simple Security Property (also called the no-read-up rule) in the Bell-LaPadula model states that a subject at a given security level cannot read an object at a higher classification level. This prevents unauthorized disclosure of classified information and is the foundational confidentiality rule of the model.

Exam trap

SSCP often tests the confusion between the Simple Security Property (no read up) and the *-property (no write down), since both are Bell-LaPadula rules but govern opposite operations.

How to eliminate wrong answers

Option A is wrong because the *-property (star property) governs write operations — it prevents a subject from writing down to a lower classification level, not reading up. Option B is wrong because the Discretionary Security Property uses an access matrix to control access based on need-to-know, not classification-level read restrictions. Option D is wrong because the Lattice Security Property is not a defined Bell-LaPadula property; Bell-LaPadula uses a lattice of security levels but the read restriction is specifically the Simple Security Property.

354
Multi-Selectmedium

An organization is hardening a Linux server. Which TWO of the following are effective steps to reduce the attack surface?

Select 2 answers
A.Disable SELinux for better performance
B.Install all available packages to ensure compatibility
C.Remove unnecessary services and software packages
D.Set file permissions using chmod and chown to restrict access
E.Enable the root account for direct login
AnswersC, D

Removing unnecessary services and packages eliminates unused daemons, open ports and vulnerable libraries, shrinking the number of exploitable entry points on the host. This directly reduces the attack surface, which is the hardening goal stated in the scenario.

Why this answer

Removing unnecessary services and software reduces potential vulnerabilities. Proper file permissions using chmod and chown enforce least privilege.

355
Multi-Selecteasy

Which TWO of the following are examples of administrative controls in a security program? (Choose two.)

Select 2 answers
A.Security policies
B.Firewall rules
C.Locks on server room doors
D.Employee background checks
E.Intrusion detection software
AnswersA, D

Security policies are administrative controls because they govern behaviour through documented rules, standards and procedures rather than hardware or software. They satisfy the stem's requirement for a management-level control, directing how personnel must operate and providing the mandate against which other controls are enforced.

Why this answer

Administrative controls are management-driven, people-and-process safeguards rather than technical or physical mechanisms. Option A, security policies, is correct because written policies define required behavior, responsibilities, and governance, which is a classic administrative control. Option D, employee background checks, is correct because vetting personnel before hire is a procedural/administrative control that reduces insider risk.

Option B, firewall rules, is a technical (logical) control enforced by network devices, so it does not belong. Option C, locks on server room doors, is a physical control, so it does not belong. Option E, intrusion detection software, is a technical detective control, so it does not belong.

Exam trap

ISC2 often tests the distinction between administrative, technical, and physical controls, and the trap here is that candidates confuse firewall rules or intrusion detection software (both technical controls) with administrative controls because they are part of a security program, but they are not process-based or policy-driven.

356
MCQhard

A network has multiple VLANs with an IDS deployed on the core switch using SPAN ports. The IDS is missing some packets during high traffic periods. What is the best course of action to improve packet capture reliability?

A.Deploy the IDS inline
B.Implement NetFlow for monitoring
C.Use multiple SPAN sessions
D.Increase the SPAN port buffer
AnswerA

SPAN ports drop frames once the mirror session exceeds interface or ASIC capacity, which explains the missed packets. An inline IDS receives every frame in the forwarding path, so nothing is discarded under load, satisfying the reliability constraint the stem describes.

Why this answer

Deploying the IDS inline ensures that all traffic destined for the monitored segment must pass through the device, eliminating packet loss caused by oversubscription of SPAN ports during high traffic periods. SPAN ports rely on switch fabric replication, which can drop packets when the aggregate traffic exceeds the port's bandwidth or the switch's internal buffer capacity. Inline deployment places the IDS directly in the data path, guaranteeing that every packet is inspected without reliance on replication.

Exam trap

ISC2 often tests the misconception that increasing buffers or adding more SPAN sessions can solve packet loss, when the real issue is the inherent unreliability of SPAN port replication under high load, making inline deployment the only guaranteed solution.

How to eliminate wrong answers

Option B is wrong because NetFlow is a flow-based monitoring technology that provides statistical summaries and metadata, not full packet capture, so it cannot improve packet capture reliability. Option C is wrong because using multiple SPAN sessions does not address the root cause of packet loss; it only replicates the same oversubscribed traffic to additional ports, potentially worsening congestion. Option D is wrong because increasing the SPAN port buffer may temporarily reduce drops but does not solve the fundamental issue of the SPAN port being unable to handle peak traffic rates, as buffers can still overflow under sustained high load.

357
Multi-Selectmedium

A company is implementing a change management process. Which THREE elements are essential for every change request? (Select THREE)

Select 3 answers
A.Description of the change
B.Impact assessment
C.Rollback plan
D.Employee performance review
E.Budget approval
AnswersA, B, C

A description of the change is essential because it defines the scope, affected systems and intended outcome, enabling the change advisory board to assess risk and impact before approval. Without it, reviewers cannot evaluate the request against the change management process, so this element satisfies the stem's requirement for every change request.

Why this answer

A description of the change (A) is essential because it defines exactly what will be modified, including the systems, services, and scope involved, so that approvers and implementers understand the request. An impact assessment (B) is required to identify the risks, affected users, dependencies, and potential downtime, which allows the change advisory board to evaluate and prioritize the change. A rollback plan (C) is critical because it provides a tested, documented procedure to revert the change if it fails or causes an outage, minimizing business disruption.

Employee performance review (D) is unrelated to change management, as it evaluates individual job performance rather than a technical or process change. Budget approval (E) may be needed for some changes, but it is not an essential element of every change request, since many changes involve no direct cost.

Exam trap

The trap here is that candidates confuse 'essential change request elements' with general business processes like HR reviews or financial approvals, but the SSCP focuses strictly on technical and operational controls for security and stability.

358
MCQeasy

A retail chain issues each cashier a badge containing a photograph and a scannable code. At the start of every shift, a supervisor visually compares the badge photograph to the person and scans the code into the point-of-sale terminal. Which two access control components are being combined in this process?

A.Authorization by the badge code and accounting by the supervisor's visual comparison
B.Identification by the badge code and authentication by the supervisor's visual comparison
C.Identification by the supervisor's visual comparison and authentication by the badge code
D.Authentication by the badge code and authorization by the supervisor's visual comparison
AnswerB

Presenting the badge code claims an identity, which is identification. The supervisor confirming that the person matches the photograph verifies that claim, which is authentication. Together they establish who the cashier is before the terminal grants any access, matching the two components the process combines.

Why this answer

The badge code is an assertion of who the cashier claims to be, and the supervisor's check that the face matches the photograph validates that assertion. Identification precedes authentication, and both precede the authorization decision the terminal makes about which functions the cashier may use.

Exam trap

The trap here is treating any credential presented at a checkpoint as authentication, when a bare identifier such as a badge number only claims an identity.

359
Multi-Selectmedium

Which TWO of the following are valid reasons for implementing a separation of duties policy? (Choose two.)

Select 2 answers
A.To reduce the workload on individual employees.
B.To detect errors through independent verification.
C.To simplify training requirements.
D.To comply with regulatory requirements.
E.To prevent fraud by requiring collusion.
AnswersB, E

Having different people perform related tasks allows for error detection.

Why this answer

Separation of duties (SoD) is a security control that divides critical tasks among multiple individuals to prevent any single person from having excessive control. Option B is correct because independent verification is a core benefit: when one person performs a task and another reviews it, errors are more likely to be caught before they cause damage. This is especially important in financial transactions or system configuration changes where a single mistake could have significant consequences.

Exam trap

ISC2 often tests the distinction between compliance as a requirement versus a fundamental security reason; candidates mistakenly choose 'compliance' as a core reason when the question asks for the underlying security benefit.

360
MCQmedium

An organization wants to implement multi-factor authentication (MFA) for remote access. Which combination represents something you have and something you are?

A.Password and security question
B.Smart card and PIN
C.Password and one-time passcode (OTP)
D.Smart card and fingerprint
AnswerD

A smart card is a physical token, satisfying the "something you have" factor, while a fingerprint is a biometric trait, satisfying "something you are". Combining these two distinct factor types delivers true multi-factor authentication for remote access, unlike two passwords or two possession factors.

Why this answer

A smart card is a physical token the user possesses (something you have), and a fingerprint is a biometric trait inherent to the user (something you are). Combining them satisfies the requirement for two different MFA factor categories. This is a classic possession-plus-inherence pairing used in high-assurance environments.

Exam trap

SSCP often tests factor-category confusion — candidates see two credentials and assume MFA, missing that both must come from different categories (know, have, are).

How to eliminate wrong answers

Option A is wrong because both a password and a security question are knowledge factors (something you know), so they do not combine different factor categories. Option B is wrong because a smart card is possession but a PIN is knowledge, not inherence — it pairs 'have' with 'know', not 'have' with 'are'. Option C is wrong because a password is knowledge and an OTP is typically possession or knowledge depending on delivery, but neither is a biometric inherence factor.

361
MCQmedium

A cloud security team is implementing a Cloud Security Posture Management (CSPM) tool. What is the primary purpose of a CSPM solution?

A.Manage user identities and access
B.Protect workloads from runtime threats
C.Encrypt data at rest
D.Detect and remediate cloud misconfigurations
AnswerD

CSPM continuously assesses cloud environments against security baselines and compliance frameworks, identifying misconfigurations such as public buckets or overly permissive roles, then alerting or auto-remediating. This detection and remediation of misconfigurations is its primary purpose, distinct from workload protection or identity governance.

Why this answer

CSPM tools continuously monitor cloud environments against security benchmarks (CIS, PCI-DSS, ISO 27001) and compliance frameworks, detecting misconfigurations such as public S3 buckets, overly permissive security groups, or disabled logging, then providing remediation guidance. The primary purpose is posture management — identifying and fixing configuration drift and policy violations before they are exploited.

Exam trap

SSCP often tests the boundary between CSPM, CWPP, and CIEM — candidates confuse posture management (configuration) with workload protection (runtime) or identity management (permissions).

How to eliminate wrong answers

Option A is wrong because managing user identities and access is the domain of CIEM (Cloud Infrastructure Entitlement Management) or IAM tools, not CSPM. Option B is wrong because protecting workloads from runtime threats is the role of CWPP (Cloud Workload Protection Platform) or runtime defense tools like Defender for Servers. Option C is wrong because encrypting data at rest is a data protection control, often handled by cloud-native encryption services or DSPM tools, not the core function of CSPM.

362
Multi-Selectmedium

An organization is implementing a new remote access VPN for employees using IPsec. Which TWO of the following are best practices for securing the IPsec VPN?

Select 2 answers
A.Use AES encryption with a minimum key size of 128 bits
B.Use pre-shared keys for authentication
C.Disable anti-replay protection to improve performance
D.Enable Perfect Forward Secrecy (PFS)
E.Allow all IP protocols through the VPN tunnel
AnswersA, D

AES with a 128-bit minimum key satisfies IPsec confidentiality requirements, since AES is the current standard block cipher and 128 bits resists brute force. DES and 3DES are deprecated, so this directly meets the best-practice constraint for the VPN.

Why this answer

Option A is correct because AES with a minimum 128-bit key is a current, strong symmetric cipher standard for IPsec ESP, providing confidentiality that is resistant to brute-force attacks; 128-bit AES is the minimum acceptable, with 256-bit preferred for higher assurance. Option D is correct because enabling Perfect Forward Secrecy (PFS) via Diffie-Hellman (e.g., DH Group 14 or higher) ensures that compromise of a long-term key cannot decrypt previously captured session keys, limiting the blast radius of a key compromise. Option B is not a best practice because static pre-shared keys are weak, hard to rotate, and do not scale; certificate-based authentication (IKEv2 with X.509) or strong EAP methods should be used instead.

Option C is wrong because disabling anti-replay protection removes a critical IPsec security feature that prevents attackers from capturing and retransmitting ESP packets, and the performance gain is negligible. Option E is wrong because allowing all IP protocols through the tunnel violates least-privilege and broadens the attack surface; traffic should be restricted by split-tunnel and firewall/ACL policy to only required protocols and subnets.

Exam trap

The trap here is that candidates often confuse pre-shared keys as a secure authentication method for IPsec, but the SSCP exam emphasizes that PSKs are weak compared to digital certificates or EAP methods, especially in enterprise environments.

363
Multi-Selectmedium

A security analyst is responding to a malware incident on a Windows server. Which TWO actions should be taken to properly collect volatile evidence?

Select 2 answers
A.Reboot the system to clear malware from memory
B.Delete suspicious files to prevent further infection
C.Perform a full disk image using a write blocker
D.Capture a memory dump using WinPmem
E.Record active network connections
AnswersD, E

WinPmem captures physical memory, preserving running processes, injected code and encryption keys that vanish on shutdown or reboot. This satisfies the volatile-evidence requirement, since RAM is lost first and must be acquired before any disk imaging or power-off.

Why this answer

Option D is correct because capturing a memory dump with WinPmem preserves the contents of RAM, which is the most volatile evidence and is lost the moment the system is powered off or rebooted. Option E is correct because recording active network connections (e.g., via netstat or similar tools) documents volatile state such as established sessions, listening ports, and remote endpoints that would otherwise disappear. Options A and B are wrong because rebooting or deleting files destroys volatile evidence and alters the system state, violating order-of-volatility principles.

Option C is incorrect here because a full disk image with a write blocker captures non-volatile storage, not volatile evidence such as memory or live network connections.

Exam trap

The trap here is that candidates often confuse 'volatile evidence' with 'non-volatile evidence' and choose disk imaging (Option C) instead of memory capture, or mistakenly think rebooting (Option A) is a safe containment step.

364
MCQeasy

A security administrator is implementing a new access control system. The organization wants to ensure that users are granted only the permissions necessary to perform their job functions and nothing more. Which principle is being applied?

A.Least privilege
B.Implicit deny
C.Separation of duties
D.Defense in depth
AnswerA

Least privilege means granting users only the access required to perform their job and no more. This directly matches the requirement to avoid excessive permissions. It reduces attack surface and limits damage from compromised accounts, making it the correct principle for this scenario.

Why this answer

Least privilege is the principle of providing users with only the access rights required for their tasks. It minimizes the potential for accidental or malicious misuse of privileges. Separation of duties, defense in depth, and implicit deny are related but distinct concepts that do not directly address minimizing granted permissions.

Exam trap

The trap here is conflating least privilege with implicit deny; implicit deny is about default denial, while least privilege is about minimizing what is explicitly granted.

365
Multi-Selectmedium

A company is migrating from WPA2-PSK to WPA3 for its wireless network. Which THREE benefits does WPA3 provide compared to WPA2?

Select 3 answers
A.Mandatory use of Protected Management Frames (PMF)
B.Use of TKIP as the mandatory encryption protocol
C.Support for 192-bit security suite in Enterprise mode
D.Resistance to offline dictionary attacks through SAE
E.Backward compatibility with WEP devices
AnswersA, C, D

Protected Management Frames become mandatory in WPA3, whereas WPA2 left them optional. This closes the deauthentication and disassociation forgery attacks that WPA2 networks remained exposed to, directly satisfying the scenario's requirement for a security improvement over WPA2-PSK.

Why this answer

Option A is correct because WPA3 mandates Protected Management Frames (PMF, defined in 802.11w), which cryptographically protects management frames such as deauthentication and disassociation, preventing spoofing and denial-of-service attacks that remain possible under WPA2 where PMF is optional. Option C is correct because WPA3-Enterprise offers an optional 192-bit security mode based on CNSA Suite algorithms (GCMP-256, HMAC-SHA-384, ECDHE and ECDSA with 384-bit curves), providing stronger cryptographic protection than the standard WPA2-Enterprise 128-bit suite. Option D is correct because WPA3 replaces the WPA2-PSK 4-way handshake with Simultaneous Authentication of Equals (SAE), a Dragonfly-based password-authenticated key exchange that resists offline dictionary attacks by requiring live interaction with the AP for each guess.

Option B is incorrect because TKIP is a deprecated, legacy encryption protocol; WPA3 requires CCMP-128 at minimum and does not mandate TKIP. Option E is incorrect because WPA3 does not provide backward compatibility with WEP devices, which use the obsolete RC4-based WEP cipher and cannot negotiate WPA3 security.

Exam trap

SSCP often tests wireless security features. The trap is confusing WPA3 benefits with those of WPA2 or assuming backward compatibility with older protocols like WEP. Candidates must remember that WPA3 does not support WEP and that TKIP is not used in WPA3.

366
MCQeasy

A healthcare organization has completed a risk assessment and documented a set of identified risks in its risk register. Management decides not to purchase cyber insurance and not to implement any additional safeguards for a specific risk involving legacy medical devices. Which risk response strategy has management chosen?

A.Risk transfer
B.Risk acceptance
C.Risk avoidance
D.Risk mitigation
AnswerB

Acceptance means management acknowledges the risk, documents the decision, and proceeds without additional controls or insurance. Because the organization chose to add no safeguards and no coverage for the legacy device risk, it has formally accepted the residual exposure. Acceptance is a legitimate strategy when the cost of treatment exceeds the potential loss.

Why this answer

When management reviews a documented risk and consciously decides to add no controls and buy no insurance, the organization is accepting the risk. Acceptance is recorded in the risk register with a rationale and often a review date, so the decision is deliberate and auditable. Mitigation, transfer, and avoidance all require concrete actions that were explicitly declined for the legacy devices.

Exam trap

The trap here is reading the absence of action as a failure to respond, when formally documented inaction is itself the acceptance strategy.

367
MCQeasy

Which of the following wireless security protocols uses AES-CCMP and is based on the 802.11i standard?

A.WEP
B.WPA
C.WPA2
D.WPA3
AnswerC

WPA2 implements the 802.11i amendment, mandating AES-CCMP for confidentiality and integrity, replacing WPA's weaker TKIP. This satisfies the stem's requirement for a protocol using AES-CCMP and based on 802.11i, unlike WEP's RC4 or WPA's TKIP.

Why this answer

WPA2 is the Wi-Fi Alliance certification that implements the IEEE 802.11i standard and mandates AES-CCMP for encryption and integrity. It replaced WPA's TKIP/RC4-based Temporal Key Integrity Protocol with the stronger AES block cipher in Counter Mode with CBC-MAC Protocol. This is why WPA2 is the correct answer for AES-CCMP plus 802.11i.

Exam trap

SSCP often tests the WPA vs. WPA2 distinction — candidates remember 'WPA2 is better' but forget that only WPA2 mandates AES-CCMP, while WPA is stuck on TKIP/RC4.

How to eliminate wrong answers

Option A is wrong because WEP uses RC4 with a static 40- or 104-bit key and a 24-bit IV, offering no real protection and predating 802.11i entirely. Option B is wrong because WPA was an interim fix that uses TKIP with RC4 and was designed to run on legacy hardware before 802.11i was ratified; it does not use AES-CCMP. Option D is wrong because WPA3, while newer and stronger, uses SAE (Simultaneous Authentication of Equals) for the handshake and GCMP-256 in WPA3-Enterprise, and it is based on the later 802.11-2016 amendments rather than the original 802.11i standard.

368
MCQmedium

An organization is redesigning its DMZ to host a public web server and an internal file server. Which architecture provides the strongest security?

A.Place both servers in the DMZ with no firewall between them.
B.Place the web server on the internal network and the file server in the DMZ with a VPN.
C.Place both servers on the internal network with a stateful firewall inspecting traffic.
D.Place the web server in the DMZ and the file server on the internal network; allow only HTTP/HTTPS from web server to file server.
AnswerD

Segregating the public web server into the DMZ while keeping the file server internal satisfies the requirement to protect internal data. Restricting traffic to HTTP/HTTPS only prevents the web tier from reaching the file server over other protocols, limiting lateral movement if it is compromised.

Why this answer

It follows the principle of least privilege and defense in depth by placing the public-facing web server in the DMZ, where it can be accessed from the internet, while the internal file server remains on the internal network, isolated from direct external access. Only HTTP/HTTPS traffic is allowed from the web server to the file server, typically enforced by a stateful firewall or an application-layer gateway, which minimizes the attack surface and prevents lateral movement if the web server is compromised.

Exam trap

The trap here is that candidates often assume placing both servers in the DMZ (Option A) is simpler and sufficient, but they overlook that the DMZ is a semi-trusted zone and internal servers should never be directly exposed to the internet or to compromised DMZ hosts without strict access controls.

How to eliminate wrong answers

Option A is wrong because placing both servers in the DMZ with no firewall between them exposes the internal file server directly to the internet, allowing any attacker who compromises the web server to access the file server without additional barriers, violating the segmentation principle. Option B is wrong because placing the file server in the DMZ with a VPN still exposes it to the internet (VPN termination is in the DMZ), and the web server on the internal network would require inbound internet traffic to traverse the internal network, increasing risk; VPNs do not replace the need for proper DMZ segmentation. Option C is wrong because placing both servers on the internal network with a stateful firewall inspecting traffic still exposes the internal network to direct internet traffic destined for the web server, bypassing the DMZ's isolation and increasing the risk of internal network compromise.

369
Drag & Dropmedium

Drag and drop the steps for establishing a VPN using IPsec in tunnel mode into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

IPsec tunnel setup: IKE phase 1 (management SA), IKE phase 2 (IPsec SA), then apply to traffic.

370
MCQeasy

A security awareness training program is being developed. Which topic is most important to include to reduce the risk of credential theft?

A.Proper use of social media
B.Physical security procedures
C.Recognizing phishing attempts
D.Data backup procedures
AnswerC

Phishing is the leading vector for stolen credentials, tricking users into surrendering passwords on fraudulent pages. Training staff to recognise suspicious senders, links and urgent requests directly reduces that risk, addressing the credential-theft constraint more effectively than general policy or password topics.

Why this answer

Phishing is the primary vector for credential theft, as attackers use deceptive emails or messages to trick users into revealing usernames and passwords. Training users to recognize phishing attempts—such as spoofed sender addresses, suspicious URLs, and urgent language—directly mitigates this risk by preventing credential disclosure at the point of attack. Unlike other topics, phishing awareness specifically targets the social engineering techniques most commonly used to steal credentials.

Exam trap

The trap here is that candidates may choose physical security procedures (Option B) because they associate credential theft with stolen hardware, but the SSCP exam emphasizes that the most common and effective method of credential theft is phishing, not physical access.

How to eliminate wrong answers

Option A is wrong because proper use of social media, while important for privacy, does not directly address credential theft; attackers typically harvest credentials through phishing rather than social media posts. Option B is wrong because physical security procedures, such as locking doors or securing badges, protect against physical theft of devices or documents but do not prevent remote phishing attacks that steal credentials via email or web forms. Option D is wrong because data backup procedures focus on recovering from data loss due to ransomware or hardware failure, not on preventing the initial compromise of credentials through social engineering.

371
Multi-Selectmedium

An organization is implementing a software inventory management process. Which TWO of the following should be tracked for each software asset?

Select 2 answers
A.License type and number of licenses
B.Physical location of the installed software
C.Version and patch level
D.Serial number of the installation media
E.Name of the user who installed it
AnswersA, C

Tracking licence type and count directly satisfies the inventory's licensing-compliance constraint, since each asset's entitlement must be reconcilable against deployed instances. Licence type distinguishes perpetual, subscription, and concurrent models, while the count exposes over-deployment or shortfalls during audits. This pairing is therefore essential for software asset management.

Why this answer

Option A (License type and number of licenses) is correct because software inventory management must track licensing entitlements—such as perpetual, subscription, or concurrent-user licenses and the quantity purchased—to ensure license compliance, avoid over-deployment penalties, and support audits. Option C (Version and patch level) is correct because knowing the exact version and patch level of each installed application is essential for vulnerability management, patch remediation, and confirming supportability. Option B is not a standard inventory attribute for software assets; physical location is typically tracked for hardware assets, not installed software.

Option D is unnecessary because installation media serial numbers are not meaningful inventory data for deployed software. Option E is not required for inventory purposes; the installing user does not determine licensing, versioning, or compliance status.

Exam trap

(ISC)² often tests the distinction between physical asset tracking (e.g., hardware serial numbers) and logical software inventory attributes, leading candidates to mistakenly select the serial number of installation media as a tracked item.

372
Multi-Selecthard

A security administrator is implementing physical security for a data center. Which THREE of the following controls should be included to provide layered security?

Select 3 answers
A.Mantrap at the main entrance
B.Screen locks on all workstations
C.CCTV monitoring of all entry points
D.Clean desk policy for employees
E.Biometric readers on server room doors
AnswersA, C, E

A mantrap permits only one person through at a time, using interlocking doors to prevent tailgating and credential passback. It enforces strict identity verification at the perimeter, forming the outermost layer of defence-in-depth for the data centre.

Why this answer

A mantrap at the main entrance (A) is correct because it creates a physical buffer zone that allows only one person through at a time, preventing tailgating and piggybacking into the facility. CCTV monitoring of all entry points (C) is correct because it provides continuous surveillance and recording of access points, enabling detection, deterrence, and forensic review of security incidents. Biometric readers on server room doors (E) are correct because they enforce strong authentication based on unique physiological traits for the most sensitive area, adding a distinct layer beyond perimeter controls.

Screen locks on workstations (B) and a clean desk policy (D) are administrative and logical controls for protecting information, not physical controls for securing a data center's entry points and rooms.

Exam trap

The trap here is that candidates confuse administrative or logical controls (like screen locks or clean desk policies) with physical security controls, which must be tangible barriers or detection systems that protect the facility's perimeter and access points.

373
MCQmedium

After a security incident, the incident response team holds a lessons learned meeting. What is the PRIMARY outcome of this meeting?

A.Permanently delete all evidence related to the incident
B.Inform the media about the incident details
C.Identify improvements to the incident response process
D.Assign blame for the incident
AnswerC

The lessons learned meeting reviews what occurred, what worked and what failed, then produces actionable recommendations to strengthen the incident response plan, tools and procedures. Its primary outcome is documented process improvement, not blame or immediate remediation of the affected systems.

Why this answer

The primary outcome of a lessons learned meeting is to identify improvements to the incident response process. This meeting focuses on analyzing what worked well and what did not, leading to actionable changes in policies, procedures, and tools to enhance future incident handling. It is a key component of the continuous improvement cycle mandated by frameworks like NIST SP 800-61.

Exam trap

The trap here is that candidates may confuse the lessons learned meeting with the immediate operational steps of incident response, such as evidence handling or public relations, rather than recognizing its core purpose of process improvement and continuous learning.

How to eliminate wrong answers

Option A is wrong because permanently deleting all evidence related to the incident violates legal hold requirements, chain of custody, and potential forensic analysis needs; evidence must be preserved according to retention policies and regulatory mandates. Option B is wrong because informing the media about incident details is not a primary outcome of a lessons learned meeting; such communication is handled by a designated public relations or legal team to avoid compromising investigations or violating disclosure laws. Option D is wrong because assigning blame is counterproductive and contrary to the purpose of a lessons learned meeting, which is to focus on process improvement rather than individual fault; a blame-free culture encourages honest reporting and effective remediation.

374
MCQeasy

Which DR testing type involves running recovery systems in parallel with production systems to verify functionality without impacting live operations?

A.Full interruption test
B.Simulation test
C.Parallel test
D.Tabletop exercise
AnswerC

A parallel test runs recovery systems alongside production, processing the same transactions in parallel, so functionality is verified without disrupting live operations. This directly satisfies the stem's constraint of validating recovery capability while leaving production systems untouched.

Why this answer

A parallel test is the correct DR testing type because it involves running the recovery systems concurrently with the production systems. This allows the organization to verify that the backup systems function correctly and can handle the workload without any impact on live operations, as the production environment remains untouched.

Exam trap

ISC2 often tests the distinction between a parallel test and a simulation test, where candidates mistakenly think a simulation involves actual system execution, but in reality, a simulation test is a theoretical exercise without any live system activation.

How to eliminate wrong answers

Option A is wrong because a full interruption test (also known as a full-scale or hot start test) requires shutting down the primary production systems and failing over entirely to the recovery site, which directly impacts live operations and is not a parallel run. Option B is wrong because a simulation test involves a walk-through or role-playing scenario where team members discuss their responses to a disaster without actually activating any recovery systems or processing live data. Option D is wrong because a tabletop exercise is a discussion-based session where participants review plans and procedures in a meeting room, with no actual execution of recovery systems or parallel processing.

375
Multi-Selectmedium

A financial services firm is deploying a centralized access control server that will make authorization decisions for dozens of internal applications. The architects want the applications to query a single decision point instead of embedding their own permission logic. Which two characteristics should the chosen model exhibit? (Choose two.)

Select 2 answers
A.Each application maintains its own copy of the permission tables so decisions can be made without network calls
B.Permissions are baked into each application's source code during development and released through the change management pipeline
C.Authorization decisions are expressed as policy that can be updated centrally and take effect without redeploying applications
D.A central policy engine evaluates subject, object, and environmental attributes at the moment of each request
E.The decision point grants access based solely on the user's job title stored in the human resources system
AnswersC, D

Centralized policy authoring means a change to rules propagates to all protected applications through the shared decision point rather than through code releases. This satisfies the architectural intent directly: the firm gains consistent enforcement and can adjust entitlements quickly, with the applications remaining unaware of the underlying rule changes.

Why this answer

Centralized authorization requires a shared decision point that evaluates rich context and a policy store that can be changed without touching application code. Attribute-based access control delivers both by evaluating subject, object, and environmental attributes in a central engine, and by expressing rules as centrally managed policy rather than as logic embedded in each application.

Exam trap

The trap here is equating centralization with speed, and therefore choosing local permission copies that quietly rebuild the fragmented logic the project set out to remove.

Page 4

Page 5 of 13

Page 6