Courseiva

Systems Security Certified Practitioner SSCP (SSCP) — Questions 376–450

971 questions total · 13pages · All types, answers revealed

Page 5

Page 6 of 13

Page 7
376
Multi-Selecthard

A security engineer is designing a network segmentation strategy to isolate a DMZ containing public-facing web servers from the internal corporate network. Which TWO controls should be implemented? (Select two)

Select 2 answers
A.Separate VLANs for DMZ and internal networks
B.A firewall that only permits necessary inbound traffic to the DMZ and restricts outbound traffic from the DMZ to internal
C.Network Access Control (NAC) on all endpoints
D.A separate IP subnet for the DMZ
E.An intrusion detection system (IDS) monitoring traffic between segments
AnswersA, B

Separate VLANs provide Layer 2 isolation, ensuring broadcast traffic and direct frame-level communication cannot pass between the DMZ web servers and internal hosts. This satisfies the segmentation requirement by enforcing distinct logical network boundaries, with inter-VLAN routing then controlled by a firewall applying least-privilege rules.

Why this answer

Option A is correct because placing the DMZ and internal network in separate VLANs provides Layer 2 segmentation, preventing broadcast traffic and direct frame-level communication between the two zones unless explicitly routed through a Layer 3 device. Option B is correct because a firewall enforcing least privilege between zones is the core segmentation control: it allows only required inbound traffic (e.g., TCP 443 to the web servers) into the DMZ and restricts outbound DMZ-to-internal traffic, blocking lateral movement if a public-facing server is compromised. Option D is not sufficient on its own because a separate IP subnet alone does not enforce traffic filtering; routing between subnets can still occur without a firewall policy.

Option C does not belong because NAC controls endpoint admission to the network and does not segment an existing DMZ from the internal network. Option E does not belong because an IDS only monitors and alerts on traffic; it does not enforce segmentation or block unauthorized flows.

Exam trap

SSCP often tests the difference between preventive and detective controls, and candidates may select IDS or NAC as segmentation controls when they are not.

377
MCQeasy

Which wireless security standard replaces WPA2 and mandates Protected Management Frames (PMF) to prevent certain types of attacks?

A.802.1X
B.WPA3
C.WEP
D.WPA2
AnswerB

WPA3 mandates Protected Management Frames, which authenticate and encrypt management frames so attackers cannot forge deauthentication or disassociation frames. WPA2 left these frames unprotected, enabling those denial-of-service and handshake-capture attacks. This mandatory PMF requirement is precisely the constraint the stem specifies.

Why this answer

WPA3 is the wireless security standard that replaces WPA2 and mandates Protected Management Frames (PMF) to prevent attacks such as deauthentication and disassociation. PMF provides integrity protection for management frames, which WPA2 did not require.

Exam trap

SSCP often tests the specific features that distinguish WPA3 from WPA2, and candidates may incorrectly associate PMF with WPA2 or confuse 802.1X with a wireless security standard.

How to eliminate wrong answers

Option A is wrong because 802.1X is an authentication framework for port-based network access control, not a wireless security standard that replaces WPA2. Option C is wrong because WEP is an outdated and insecure encryption protocol, not a replacement for WPA2. Option D is wrong because WPA2 is the predecessor to WPA3 and does not mandate PMF; PMF is optional in WPA2.

378
MCQhard

After a ransomware attack, the recovery team restored systems from backups. However, some files remain encrypted. What is the most probable cause?

A.Backups were also encrypted
B.The backup software was compromised
C.The ransomware had a delayed encryption mechanism
D.Restoration process skipped some file types
AnswerA

If the backup repository was mounted or reachable during the ransomware encryption phase, the malware encrypted the backup files alongside production data. Restoring therefore reinstates encrypted copies, leaving some files unreadable. This explains why recovery succeeded partially: only backups written before the attack remained clean.

Why this answer

If backups were also encrypted, the recovery team would restore encrypted copies of the files, leaving them in an encrypted state after restoration. This occurs when the ransomware has sufficient privileges to encrypt the backup repository or when backups are stored on a mounted volume that the ransomware can access. The most probable cause is that the backup data itself was compromised, not that the restoration process failed.

Exam trap

ISC2 often tests the misconception that restoration process errors (like skipping file types) are the primary cause, when in reality the integrity of the backup source is the critical factor in ransomware recovery scenarios.

How to eliminate wrong answers

Option B is wrong because a compromised backup software would typically prevent restoration entirely or introduce new malware, not leave specific files encrypted after a successful restore. Option C is wrong because a delayed encryption mechanism would encrypt files after restoration, not leave them encrypted from the backup source. Option D is wrong because skipping file types during restoration would result in missing files, not files that are present but still encrypted.

379
MCQeasy

Which of the following hash algorithms is considered cryptographically broken and should be avoided due to collision attacks?

A.SHA-3
B.SHA-256
C.MD5
D.HMAC-SHA256
AnswerC

MD5 produces a 128-bit digest and is vulnerable to practical collision attacks, so distinct inputs can yield identical hashes. This breaks integrity guarantees, making it unsuitable where collision resistance is required, unlike SHA-256 or SHA-3.

Why this answer

MD5 is considered cryptographically broken because collision attacks can easily generate two different inputs with the same hash value. This undermines its use for digital signatures, certificates, and integrity checks. SHA-3, SHA-256, and HMAC-SHA256 are still considered secure for cryptographic purposes.

Exam trap

SSCP often tests hash algorithm security; candidates might think SHA-1 is the only broken one, but MD5 is also broken and frequently appears as a distractor.

How to eliminate wrong answers

Option A is wrong because SHA-3 is a secure hash algorithm standardized by NIST, resistant to collision attacks. Option B is wrong because SHA-256 is part of the SHA-2 family and remains secure for cryptographic use. Option D is wrong because HMAC-SHA256 is a keyed-hash message authentication code using SHA-256, which is secure and not affected by MD5's vulnerabilities.

380
MCQmedium

An incident responder is collecting evidence from a compromised server. Which of the following is the correct order for collecting volatile data?

A.Network connections, memory dump, disk image
B.Disk image, network connections, memory dump
C.Memory dump, network connections, disk image
D.Disk image, memory dump, network connections
AnswerA

Memory is more volatile than network connections, so it should be first.

Why this answer

Volatile data must be collected in order of decreasing volatility. Network connections (active sessions, ARP cache, routing tables) are more volatile than RAM and can change or disappear within seconds, so they are captured first. Memory (RAM) is collected next because it is lost on power loss but persists slightly longer than network state.

The disk image is collected last because it is persistent storage and the least volatile. This order preserves ephemeral evidence such as active sessions, running processes, and encryption keys before it disappears.

Exam trap

ISC2 often tests the misconception that disk imaging should be done first because it is the most stable evidence source, but the trap is that volatile data such as network state and memory is lost forever if not captured immediately. Note that network connections are more volatile than RAM and must be collected before the memory dump.

How to eliminate wrong answers

Option A is wrong because collecting network connections before memory dump risks losing volatile memory contents (e.g., processes, kernel objects) that may contain evidence of active malware or encryption keys. Option B is wrong because starting with a disk image is the least volatile and would cause loss of all volatile data (memory and network state) before they are captured. Option D is wrong because collecting disk image before memory dump violates the order of volatility; memory must be captured first as it is lost immediately upon shutdown or power loss.

381
MCQhard

A system administrator notices that a server's certificate was issued by a CA that is not in the trusted root store of client machines. What is the most likely impact on clients connecting via TLS?

A.Clients will receive a certificate warning or be unable to connect.
B.The server will automatically obtain a new certificate.
C.Clients will connect but with reduced cipher strength.
D.Clients will be able to connect without any warning.
AnswerA

Untrusted root means the client cannot build a valid chain to a trusted anchor, so path validation fails. Browsers typically show a warning allowing override, while stricter clients abort the handshake outright — satisfying the stem's constraint that the issuing CA is absent from the trusted root store.

Why this answer

When a server presents a certificate issued by a Certificate Authority (CA) that is not in the client's trusted root store, the TLS handshake fails the trust chain validation. The client's TLS library (e.g., OpenSSL, Schannel) will either display a certificate warning to the user or terminate the connection with an error such as 'SEC_ERROR_UNKNOWN_ISSUER' in Firefox or 'ERR_CERT_AUTHORITY_INVALID' in Chrome, depending on the client's security policy.

Exam trap

The trap here is that candidates assume TLS connections will proceed with reduced security or a warning, but in strict implementations (e.g., many browsers and modern applications), the connection is completely blocked rather than just warned.

How to eliminate wrong answers

Option B is wrong because the server cannot automatically obtain a new certificate; certificate renewal or replacement requires manual intervention or an automated protocol like ACME, but the client's lack of trust does not trigger any automatic action on the server. Option C is wrong because TLS cipher strength is negotiated independently of certificate trust; a client will not downgrade ciphers due to an untrusted CA — the handshake will fail before cipher negotiation completes. Option D is wrong because clients enforce trust validation by default; they will not connect without a warning unless the user has explicitly disabled certificate validation (e.g., by adding an exception or using an insecure configuration like `CURLOPT_SSL_VERIFYPEER` set to false).

382
MCQhard

In an OAuth 2.0 authorization flow, a client application receives an access token. This token is used to:

A.Encrypt data between client and resource server
B.Identify the user across different applications
C.Authorize access to protected resources at the resource server
D.Authenticate the user to the authorization server
AnswerC

The access token is a credential presented to the resource server, which validates it and grants access to the protected resource. It authorises the request; it does not authenticate the user to the authorisation server or issue refresh tokens.

Why this answer

In OAuth 2.0, an access token is a credential that grants the client application delegated authorization to access specific protected resources on the resource server on behalf of the resource owner. It is presented to the resource server (typically as a Bearer token in the Authorization header) to prove the client has been authorized. The token does not authenticate the user to the authorization server, nor does it encrypt data — it authorizes API access.

Exam trap

SSCP often tests the confusion between authorization (OAuth access token) and authentication (OpenID Connect ID token), so candidates who conflate the two pick options about identifying or authenticating the user.

How to eliminate wrong answers

Option A is wrong because OAuth 2.0 access tokens do not encrypt data; encryption in transit is provided by TLS, and OAuth is an authorization framework, not a cryptographic transport mechanism. Option B is wrong because identifying a user across applications is the role of OpenID Connect's ID token (a JWT containing user identity claims), not the OAuth access token, which is opaque to the client and meant for the resource server. Option D is wrong because authenticating the user to the authorization server happens during the authorization grant flow (e.g., via the authorization endpoint and user login), not through the access token, which is issued after authentication and used for resource access.

383
Multi-Selecthard

A security auditor is reviewing the cryptographic algorithms used in an organization. Which THREE of the following are considered insecure or deprecated and should be avoided? (Select THREE.)

Select 3 answers
A.RSA-2048
B.DES
C.3DES
D.AES-256
E.MD5
AnswersB, C, E

DES uses a 56-bit effective key, making exhaustive key search feasible with modern hardware. Its small block size of 64 bits also permits birthday-bound collisions. Both weaknesses make it unsuitable for protecting sensitive data, so auditors should flag it as deprecated.

Why this answer

DES (B) is insecure because its 56-bit key is far too short and can be brute-forced in hours with modern hardware, so it must be avoided. 3DES (C) is deprecated because its 64-bit block size enables Sweet32-style birthday attacks and its effective key strength is reduced, making it unsuitable for new deployments. MD5 (E) is a broken hash function with practical collision attacks, so it must not be used for integrity or signature purposes. RSA-2048 (A) and AES-256 (D) are not marked correct because they remain strong, currently recommended algorithms when implemented properly.

Exam trap

ISC2 often tests the misconception that 3DES is still acceptable because it is 'triple' strength, but the trap is that both DES and 3DES are deprecated due to small block sizes and key lengths, while MD5 is often mistakenly considered safe for checksums despite its proven collision vulnerabilities.

384
MCQeasy

A security administrator is configuring a web server to use TLS 1.3. The administrator wants to ensure that the server supports forward secrecy for all connections. Which of the following key exchange mechanisms should be used?

A.Pre-shared key (PSK) exchange
B.Ephemeral Diffie-Hellman (DHE) or Elliptic Curve Ephemeral Diffie-Hellman (ECDHE)
C.Static Diffie-Hellman (DH)
D.RSA key exchange
AnswerB

Ephemeral Diffie-Hellman (DHE) and its elliptic curve variant (ECDHE) generate a unique, temporary key pair for each session. The private keys are discarded after the session, so even if the server's long-term private key is compromised, past session keys cannot be recovered. TLS 1.3 mandates the use of ephemeral key exchanges like ECDHE for forward secrecy.

Why this answer

TLS 1.3 requires forward secrecy, which is achieved by using ephemeral key exchanges such as DHE or ECDHE. These generate a unique session key that is not derivable from the server's long-term private key. RSA and static DH key exchanges lack forward secrecy and are not supported in TLS 1.3.

PSK alone also does not provide forward secrecy.

Exam trap

The trap here is assuming that any key exchange method in TLS provides forward secrecy, when in fact only ephemeral methods do.

385
Multi-Selecthard

A company is migrating to a PaaS cloud environment. According to the shared responsibility model, which THREE security responsibilities remain with the customer? (Select THREE.)

Select 3 answers
A.Patch management of the underlying OS
B.User access and identity management
C.Data classification and encryption
D.Security of the application code
E.Physical security of the data center
AnswersB, C, D

In PaaS, the provider secures the platform and runtime, but the customer still controls who accesses the service. Managing user accounts, authentication and authorisation remains the customer's duty, satisfying the stem's shared responsibility constraint for identity.

Why this answer

In PaaS, the customer manages access policies, application-level security, and data protection, while the provider manages the runtime, OS, and infrastructure.

386
MCQhard

A DevOps team deploys containerized microservices and wants to reduce the impact of a compromised container. They need a control that limits which system calls each container process can make, without changing the application image. Which Linux kernel feature should they enable?

A.Read-only root file system for the container
B.seccomp profiles applied to the container
C.Dropping all Linux capabilities from the container
D.Linux cgroups v2 memory limits
AnswerB

seccomp filters the system calls a process may invoke, so a compromised container can be blocked from dangerous calls such as mounting file systems or loading kernel modules. Profiles are applied by the runtime at container start, requiring no change to the application image, which fits the team's constraint exactly.

Why this answer

seccomp attaches a filter to each process that permits or denies individual system calls, so even a fully compromised container is constrained at the kernel boundary. Because profiles are supplied by the container runtime at launch, the team avoids modifying the application image while gaining strong containment.

Exam trap

The trap here is treating resource limits or read-only file systems as syscall restrictions, when only seccomp filters the actual kernel calls a container may make.

387
MCQhard

An analyst is tuning an intrusion detection system that generates far too many alerts. The analyst wants to reduce noise while preserving detection of genuinely suspicious behavior. Which approach BEST supports this goal?

A.Lower the severity rating of all signature-based alerts so analysts can triage them last.
B.Baseline normal network and host activity, then write thresholds and correlation rules relative to that baseline.
C.Disable signature categories that have produced any false positives in the past month.
D.Increase the alert threshold on the console so events are only displayed after they repeat several times.
AnswerB

Baselining establishes what normal looks like for the environment, which lets the analyst set thresholds and correlations that flag meaningful deviations instead of expected traffic. This directly reduces false positives while retaining sensitivity to anomalies such as unusual outbound volume or new service behavior. It is the most effective noise-reduction technique because it adapts detection to the actual environment rather than to generic signatures.

Why this answer

Alert noise is best reduced by understanding the environment. Baselining normal traffic and behavior gives the analyst a reference point, so thresholds and correlation rules can distinguish expected activity from anomalies. This preserves detection of real threats while eliminating the benign events that flood the console, which is far more effective than suppressing categories or hiding alerts.

Exam trap

The trap here is treating alert volume as a display problem to be hidden with thresholds or severity changes rather than a detection-quality problem to be fixed with baselining.

388
MCQhard

An organization calculates the SLE for a server as $5,000 and the ARO as 0.2. What is the ALE?

A.$5,000
B.$10,000
C.$25,000
D.$1,000
AnswerD

Multiplying the single loss expectancy of $5,000 by the annualised rate of occurrence of 0.2 yields an annualised loss expectancy of $1,000. This satisfies the stem's requirement to derive the expected yearly financial loss from the two supplied quantitative risk values.

Why this answer

The Annualized Loss Expectancy (ALE) is calculated by multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO). Given SLE = $5,000 and ARO = 0.2, the ALE is $5,000 × 0.2 = $1,000. This is the expected annual financial loss from the server risk.

Exam trap

The trap here is that candidates often multiply SLE by the reciprocal of ARO (e.g., 5 instead of 0.2) or confuse ARO with a percentage, leading to an inflated ALE like $25,000.

How to eliminate wrong answers

Option A is wrong because $5,000 is the SLE, not the ALE; it ignores the ARO multiplier. Option B is wrong because $10,000 would result from multiplying SLE by 2, which is not the correct ARO of 0.2. Option C is wrong because $25,000 would result from dividing SLE by 0.2 (or multiplying by 5), which is a common arithmetic reversal error.

389
MCQeasy

What is the minimum recommended RSA key size for secure use as of current best practices?

A.1024 bits
B.4096 bits
C.3072 bits
D.2048 bits
AnswerD

2048-bit RSA is the current minimum recommended size; smaller keys such as 1024-bit are considered cryptographically weak against modern factoring attacks. This satisfies the stem's requirement for the minimum secure key length under current best practise.

Why this answer

(2048 bits) is correct because current best practices, as recommended by NIST SP 800-57 and other cryptographic standards, consider 2048-bit RSA keys as the minimum secure size for protecting data through 2030. This key length provides a sufficient security margin against known factoring attacks, balancing computational efficiency with cryptographic strength.

Exam trap

Candidates often mistake that larger keys are always better, leading them to choose 4096 bits as the minimum, when in fact 2048 bits is the officially recommended baseline for secure use.

How to eliminate wrong answers

Option A is wrong because 1024-bit RSA keys are deprecated and considered insecure due to advances in factoring algorithms and computational power; they provide only about 80 bits of security, which is below the recommended 112-bit minimum. Option B is wrong because 4096-bit RSA keys, while secure, are not the minimum recommended size; they offer excessive security margin (about 140 bits) at the cost of significantly slower performance, making them unnecessary for most applications. Option C is wrong because 3072-bit RSA keys, though providing a higher security level (128 bits), are not the minimum recommended size; 2048 bits is the established baseline per NIST and industry standards.

390
MCQhard

In a biometric system, the point at which the false rejection rate (FRR) equals the false acceptance rate (FAR) is known as the:

A.False acceptance rate (FAR)
B.Crossover error rate (CER)
C.Failure to enroll rate
D.False rejection rate (FRR)
AnswerB

The crossover error rate is the threshold where false rejection rate and false acceptance rate intersect, giving a single comparable accuracy metric. A lower CER indicates a more accurate biometric system, useful when selecting between devices.

Why this answer

The crossover error rate (CER), also called the equal error rate (EER), is the point on the biometric operating curve where the false rejection rate equals the false acceptance rate. It is the standard metric for comparing the accuracy of different biometric systems — a lower CER indicates a more accurate system. The other options name individual rates or a different concept, not the crossover point.

Exam trap

SSCP often tests biometric metrics by describing the FRR=FAR intersection — candidates who confuse CER with FAR or FRR, or who don't recognize the 'crossover' terminology, pick the wrong rate instead of the crossover point.

How to eliminate wrong answers

Option A is wrong because FAR is only the false acceptance rate — the rate at which unauthorized users are incorrectly accepted — not the crossover point. Option C is wrong because the failure to enroll rate measures the proportion of users who cannot be enrolled in the system at all, which is unrelated to the FRR/FAR crossover. Option D is wrong because FRR is only the false rejection rate — the rate at which legitimate users are incorrectly rejected — not the crossover point.

391
MCQmedium

Which of the following is a cryptographic hash function that is considered cryptographically broken due to collision attacks and should not be used for security purposes?

A.SHA-1
B.SHA-256
C.SHA-3
D.SHA-512
AnswerA

SHA-1 is vulnerable to collision attacks and is considered broken.

Why this answer

SHA-1 is considered cryptographically broken due to collision attacks and should not be used for security purposes. SHA-256, SHA-3, and SHA-512 are still considered secure.

392
Multi-Selecteasy

Which TWO of the following are examples of administrative controls? (Choose two.)

Select 2 answers
A.Firewall rules
B.Access control policies
C.Security awareness training
D.Security guards
E.Encryption of data at rest
AnswersB, C

Access control policies are administrative controls because they define rules, responsibilities and expected behaviour through documented management direction rather than technical enforcement. They satisfy the stem's requirement for administrative examples, unlike logical controls such as firewalls or physical controls such as locks.

Why this answer

Access control policies (B) are administrative controls because they define the rules, procedures, and responsibilities for managing access to resources, forming the governance framework that guides technical and physical implementations. Security awareness training (C) is also an administrative control as it educates users on security policies and procedures, reducing human error and reinforcing organizational security culture.

Exam trap

The trap here is that candidates often confuse administrative controls with technical or physical controls, mistakenly selecting firewall rules or encryption because they are common security measures, but the SSCP exam specifically tests the distinction between administrative (policy/training), technical (software/hardware), and physical (guards/locks) control categories.

393
Multi-Selecthard

Which THREE of the following are common use cases for public key infrastructure (PKI)? (Select exactly three.)

Select 3 answers
A.Password hashing
B.Symmetric key exchange
C.Digital signatures
D.Email encryption (S/MIME)
E.SSL/TLS certificate authentication
AnswersC, D, E

PKI enables digital signatures using certificates.

Why this answer

Digital signatures are a core use case for PKI because they rely on asymmetric cryptography where a private key signs data and the corresponding public key, bound to an identity via a digital certificate issued by a Certificate Authority (CA), verifies the signature. This ensures authenticity, integrity, and non-repudiation of the signed message or document.

Exam trap

The trap here is that candidates may confuse the mechanism (e.g., using PKI to exchange a symmetric key) with a direct use case of PKI, or mistakenly think password hashing involves certificates, when PKI is specifically about public key certificates, not symmetric key exchange or hashing algorithms.

394
MCQmedium

A healthcare organization's security team is reviewing a third-party cloud provider that will store electronic protected health information. The provider's SOC 2 Type II report is two years old, and the provider has since migrated to a new data center. Which action should the security administrator take FIRST to determine whether the provider still meets the organization's security requirements?

A.Request the provider's current SOC 2 Type II report or bridge letter covering the new data center period.
B.Immediately terminate the contract and select a new cloud provider with a current SOC 2 report.
C.Accept the existing SOC 2 Type II report because it demonstrates the provider has a mature security program.
D.Perform a full penetration test of the provider's new data center without notifying the provider.
AnswerA

A SOC 2 Type II report covers a historical period, and the migration to a new data center means the controls assessed in the old report may no longer be representative. Requesting an updated report or a bridge letter that covers the gap is the appropriate first step because it gives current, independent evidence of control effectiveness before any contractual or technical decisions are made.

Why this answer

A SOC 2 Type II report is point-in-time evidence covering a defined audit period and specific systems. Because the provider migrated to a new data center after the report was issued, the prior opinion does not cover the current environment. Requesting an updated report or a bridge letter is the correct first action because it provides current, independent assurance before the organization makes contractual or technical decisions.

Exam trap

The trap here is assuming that any SOC 2 Type II report satisfies due diligence regardless of its age or the scope of systems it covered.

395
MCQhard

A security operations center (SOC) manager is evaluating a new intrusion detection system (IDS). The vendor claims the system can detect previously unknown attacks by building a baseline of normal network behavior and flagging deviations. Which detection methodology is the vendor describing?

A.Anomaly-based detection
B.Stateful protocol analysis
C.Signature-based detection
D.Heuristic-based detection
AnswerA

Anomaly-based detection establishes a baseline of normal activity and alerts on deviations from that baseline. This allows it to potentially identify zero-day or previously unknown attacks that do not match existing signatures. The vendor's description of building a baseline and flagging deviations aligns exactly with anomaly-based detection, making it the correct answer for this scenario.

Why this answer

Anomaly-based detection is designed to identify unknown attacks by modeling normal behavior and detecting statistically significant deviations. This approach can catch zero-day exploits and insider threats that signature-based systems miss. However, it often generates false positives when legitimate but unusual activity occurs, requiring tuning.

The vendor's claim of detecting previously unknown attacks through baseline deviation is a textbook description of anomaly-based detection.

Exam trap

The trap here is confusing anomaly-based detection with heuristic or stateful protocol analysis, which do not rely on a learned baseline of normal network behavior.

396
MCQeasy

A company is migrating its on-premises applications to a public cloud. Which security control is MOST important to implement to protect data in transit?

A.Enable server-side encryption for cloud storage.
B.Implement data classification labels.
C.Use IPsec VPNs for all cloud connections.
D.Ensure all data transmissions use TLS 1.2 or higher.
AnswerD

TLS 1.2 or higher encrypts data in transit between clients and cloud applications, directly satisfying the requirement to protect data moving across untrusted networks during migration. Unlike controls addressing data at rest or endpoint hardening, transport-layer encryption with modern cipher suites prevents interception and tampering en route to the public cloud.

Why this answer

TLS 1.2 or higher is the standard protocol for encrypting data in transit over public networks, ensuring confidentiality and integrity between client and server. It is the most critical control because it directly protects data as it moves across the internet to the cloud, which is the primary risk in a migration scenario.

Exam trap

The trap here is that candidates often confuse IPsec VPNs (which protect network-layer traffic) with the application-layer encryption provided by TLS, assuming VPNs are always superior for cloud connections, but TLS is the standard and most practical control for protecting data in transit to public cloud services.

How to eliminate wrong answers

Option A is wrong because server-side encryption protects data at rest in cloud storage, not data in transit. Option B is wrong because data classification labels help manage access and handling policies but do not encrypt or protect data during transmission. Option C is wrong because IPsec VPNs secure site-to-site connections but are not the most important for all cloud connections; many cloud services use HTTPS/TLS natively, and forcing all traffic through a VPN can introduce latency and complexity without providing better protection than TLS for application-layer data.

397
MCQmedium

A security engineer is reviewing system logs and notices that the log file size has not changed for several days, despite high system activity. Which log management concern does this indicate?

A.Incorrect time synchronization
B.Normal log rotation
C.Insufficient storage capacity
D.Log tampering or disabled logging
AnswerD

Static log size despite high activity indicates logging has been halted or the file altered, satisfying the stem's concern about missing audit records. Tampering or disabled logging removes the evidence trail entirely, unlike rotation or retention issues, which still produce new entries.

Why this answer

The log file size remaining static despite high system activity strongly indicates that logging has been disabled or the log files have been tampered with (e.g., truncated or replaced with empty files). Under normal operation, a busy system generates continuous log entries, causing the log file size to increase. A complete lack of size change over several days is a classic red flag for log integrity compromise, not a benign administrative action.

Exam trap

ISC2 SSCP often tests the misconception that a static log file size is due to log rotation, but rotation actually creates a new active log file with new entries, not a file that remains unchanged for days.

How to eliminate wrong answers

Option A is wrong because incorrect time synchronization would cause timestamps to be wrong, but it would not prevent log entries from being written; the log file size would still increase. Option B is wrong because normal log rotation typically renames or compresses the current log file and starts a new one, which would result in a new file with a non-zero size, not a static file size for days. Option C is wrong because insufficient storage capacity would cause the system to stop writing logs, but the log file would still show a final size from when writes ceased; the question states the size has not changed for several days, implying no writes occurred, which is more consistent with disabled logging or tampering than a full disk (which would still show the last written size).

398
MCQhard

An organization wants to ensure that servers are configured securely before deployment. They plan to use a hardened operating system image and regularly scan for deviations using SCAP. Which concept does this represent?

A.Change management
B.Asset management
C.Configuration management
D.Patch management
AnswerC

Configuration management maintains a known, hardened baseline image and detects drift through SCAP scans, directly satisfying the requirement to verify servers are securely configured before deployment. It governs the full lifecycle of configuration items, ensuring deviations are identified and remediated, which is precisely the control the organisation seeks.

Why this answer

C is correct because configuration management involves establishing and maintaining consistent baseline configurations for systems, such as using a hardened OS image, and then monitoring for deviations using tools like SCAP (Security Content Automation Protocol). SCAP enables automated vulnerability scanning and compliance checking against defined security baselines, ensuring servers remain in a known secure state before and after deployment.

Exam trap

The trap here is that candidates confuse configuration management with patch management, thinking that scanning for deviations always means checking for missing patches, when in fact SCAP scans assess a wide range of configuration settings (e.g., registry keys, file permissions, service states) beyond just patch levels.

How to eliminate wrong answers

Option A is wrong because change management focuses on controlling and documenting changes to systems after deployment, not on establishing a secure baseline image or scanning for deviations from that baseline. Option B is wrong because asset management deals with tracking and inventorying hardware and software assets throughout their lifecycle, not with enforcing secure configurations or scanning for compliance. Option D is wrong because patch management specifically addresses the application of software updates to fix vulnerabilities, whereas the scenario describes using a hardened image and SCAP scanning for configuration deviations, which is broader than patching.

399
MCQmedium

A network administrator wants to block all inbound traffic except for web and email services. Which firewall rule configuration would achieve this?

A.Default-deny with allow rules for HTTP, HTTPS, and SMTP
B.Stateful inspection without default policy
C.Stateless packet filtering with a rule per service
D.Default-allow with deny rules for unwanted services
AnswerA

Default-deny drops all inbound packets unless a rule explicitly permits them, so only HTTP, HTTPS and SMTP traffic reaches the internal network. This satisfies the requirement to block everything else, since any protocol without a matching allow rule is discarded at the perimeter.

Why this answer

A default-deny with allow rules for HTTP, HTTPS, and SMTP is the correct approach because it blocks all inbound traffic except the specified services. This follows the principle of least privilege and ensures only necessary traffic is permitted.

Exam trap

SSCP often tests the concept of default-deny versus default-allow, and candidates may incorrectly believe that stateful inspection alone provides sufficient security without a default policy.

How to eliminate wrong answers

Option B is wrong because stateful inspection without a default policy leaves the firewall without a clear deny-all rule, potentially allowing unwanted traffic. Option C is wrong because stateless packet filtering with a rule per service may not explicitly deny all other traffic unless a default-deny rule is also present; the option does not mention a default-deny. Option D is wrong because default-allow with deny rules for unwanted services is less secure and more error-prone, as it allows all traffic except what is explicitly denied.

400
MCQhard

A security administrator is configuring a network intrusion detection system (NIDS) to monitor traffic for signs of attacks. The administrator wants to ensure the NIDS can detect attacks that involve fragmented packets. Which of the following should be enabled on the NIDS to reassemble fragmented packets before analysis?

A.TCP segmentation offload
B.IP defragmentation
C.Application layer gateway
D.Stream reassembly
AnswerB

IP defragmentation is the process of reassembling fragmented IP packets into complete packets before analysis. Attackers often use fragmentation to evade detection by splitting malicious payloads across multiple fragments. Enabling IP defragmentation on the NIDS allows it to reconstruct the original packet and inspect it for malicious content. This is essential for detecting fragmentation-based attacks, making it the correct choice.

Why this answer

IP defragmentation is necessary for a NIDS to reassemble fragmented IP packets before inspecting them. Fragmentation is a common evasion technique where attackers split malicious payloads across multiple packets to avoid detection. By enabling IP defragmentation, the NIDS can reconstruct the original packet and analyze it for threats.

Stream reassembly and other options do not address IP-layer fragmentation.

Exam trap

The trap here is confusing stream reassembly, which rebuilds TCP sessions, with IP defragmentation, which rebuilds fragmented IP packets.

401
MCQmedium

After implementing security controls, a risk assessment shows that a residual risk of data exfiltration remains. Which document should formally record this residual risk and the decision to accept it?

A.Incident response plan
B.Risk register
C.Business continuity plan
D.Security baseline
AnswerB

The risk register formally documents identified risks, their assessed residual level and the management decision to accept them, providing an auditable record. It satisfies the stem's requirement to record residual risk and the acceptance decision.

Why this answer

The risk register is the formal document used to track identified risks, their assessed likelihood and impact, and the chosen risk response. When a residual risk remains after controls are implemented, the risk register records that residual risk level and formally documents management's decision to accept it, including the rationale and approval. This ensures auditability and accountability for the accepted risk.

Exam trap

The trap here is that candidates confuse the risk register with the incident response plan, thinking that any risk-related documentation belongs in the incident response plan, but the risk register is specifically designed for tracking and formally accepting residual risks before any incident occurs.

How to eliminate wrong answers

Option A is wrong because the incident response plan documents procedures for detecting, responding to, and recovering from security incidents, not for recording residual risks or acceptance decisions. Option C is wrong because the business continuity plan focuses on maintaining critical business functions during and after a disruption, not on tracking residual risks from data exfiltration. Option D is wrong because a security baseline defines the minimum security configuration standards for systems, not a repository for risk acceptance decisions.

402
MCQeasy

In the context of risk assessment, which of the following best describes a vulnerability?

A.A potential event that can cause harm
B.The likelihood of a threat exploiting a weakness
C.An actual occurrence of a harmful event
D.A weakness in a system that can be exploited
AnswerD

A vulnerability is an exploitable weakness in a system, such as a missing patch, misconfiguration or flawed code. It differs from a threat, which is the actor or event that could exploit it, and from risk, which combines likelihood and impact. This matches the stem's risk assessment context.

Why this answer

In risk assessment, a vulnerability is specifically a weakness in a system, application, or process that can be exploited by a threat. Option D correctly defines this as a weakness that can be exploited, which aligns with the NIST SP 800-30 definition of vulnerability as a flaw or weakness in system security procedures, design, implementation, or internal controls that could be exercised (accidentally triggered or intentionally exploited) and result in a security breach or a violation of the system’s security policy.

Exam trap

The trap here is that candidates confuse 'vulnerability' with 'threat' (Option A) or 'risk' (Option B), because risk assessment terminology is often used interchangeably in casual conversation, but the SSCP exam strictly defines vulnerability as a weakness, not the event or likelihood.

How to eliminate wrong answers

Option A is wrong because it describes a threat (a potential event that can cause harm), not a vulnerability. Option B is wrong because it describes risk (the likelihood of a threat exploiting a weakness), which combines threat, vulnerability, and impact. Option C is wrong because it describes an incident or actual occurrence of a harmful event, which is the realization of a threat exploiting a vulnerability, not the vulnerability itself.

403
Multi-Selecthard

A company is deploying a hardware security module (HSM) to protect the root keys of its certificate authority. Which two practices are essential for maintaining the security of the CA's private keys? (Choose two.)

Select 2 answers
A.Enable remote administration of the HSM over the public internet for convenience.
B.Store the CA private keys in the HSM and configure it to prevent export of the keys in plaintext.
C.Back up the CA private keys by exporting them to an encrypted file on a network share.
D.Require multiple authorized administrators to authenticate before the HSM performs a signing operation.
E.Use the same HSM partition for the root CA and for issuing subordinate certificates to simplify management.
AnswersB, D

Keeping the CA private keys inside the HSM and preventing plaintext export ensures that the keys never exist in an unprotected form on general-purpose systems. This reduces the risk of theft or accidental disclosure and is a fundamental requirement for protecting a root CA. The HSM's tamper-resistant design provides additional safeguards against physical and logical attacks.

Why this answer

Protecting a CA's private keys requires keeping them inside a tamper-resistant HSM and preventing plaintext export, as well as enforcing multi-person control over signing operations. Exporting keys to a file, exposing administration to the internet, or merging root and issuing roles all increase the risk of key compromise. These practices reflect standard CA hardening guidance.

Exam trap

The trap here is treating encrypted key backups or convenient remote administration as acceptable for a root CA, when they actually expand the attack surface.

404
Matchingmedium

Match each network security device to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Filters traffic based on rules

Monitors and alerts on suspicious activity

Blocks malicious traffic in real-time

Manages encrypted tunnels

Why these pairings

Correct matches: Firewall filters traffic, IDS monitors and alerts, IPS monitors and blocks, VPN concentrator handles encryption. Common confusions: swapping firewall and IDS functions.

405
MCQhard

A SOC analyst reviews an alert for a user who downloaded a large amount of data from a sensitive database at 3:00 AM. The user's manager confirms the user was not on call. Which type of risk indicator is this activity best described as?

A.Technical vulnerability indicator
B.User behavior risk indicator
C.Error log indicator
D.Configuration drift indicator
AnswerB

The indicator is the user's own activity: a large sensitive-data download at 3:00 AM, confirmed by the manager as not on call. That deviation from normal working behaviour is a user behaviour risk indicator, not a network or system indicator.

Why this answer

The activity describes a user downloading a large volume of sensitive data at an anomalous time (3:00 AM) without authorization, which directly maps to a User Behavior Risk Indicator (UBRI). UBRI focuses on deviations from established baselines of user actions, such as unusual access times, data volumes, or locations, to detect potential insider threats or compromised accounts. This is not a technical vulnerability, error log, or configuration issue, but a behavioral anomaly that requires investigation.

Exam trap

ISC2 often tests the distinction between technical indicators (like vulnerabilities or errors) and behavioral indicators, trapping candidates who confuse a user's anomalous action with a system-level flaw or log entry.

How to eliminate wrong answers

Option A is wrong because a technical vulnerability indicator refers to a flaw in software, hardware, or network design (e.g., an unpatched CVE in the database server) that could be exploited, not an anomalous user action. Option C is wrong because an error log indicator is derived from system or application error messages (e.g., failed login attempts, disk I/O errors), not from successful but suspicious user behavior. Option D is wrong because configuration drift indicator tracks changes to system settings or policies over time (e.g., a firewall rule being altered or a registry key modified), not a user's data access pattern.

406
MCQhard

A security analyst is reviewing netflow data and notices a workstation periodically sending large amounts of data to an external IP address during non-business hours. The destination IP is not associated with any known business partner. The analyst suspects data exfiltration but needs to confirm before escalating. Which of the following actions would BEST validate the suspicion while preserving evidence?

A.Run a vulnerability scan against the workstation to check for missing patches.
B.Capture full packet data for the workstation and analyze the payload for sensitive information.
C.Immediately block the destination IP at the firewall to stop the transfer.
D.Disable the workstation's network account and force a password reset.
AnswerB

Capturing full packets allows deep inspection of the actual data being transferred, which can confirm whether sensitive information is leaving the network. This preserves evidence for incident response and avoids alerting the attacker. It is the most direct way to validate exfiltration without disrupting operations or tipping off the adversary.

Why this answer

Capturing full packet data allows the analyst to inspect the actual content being transmitted, which can definitively confirm whether sensitive data is being exfiltrated. This method preserves evidence and does not alert the attacker. Other actions like blocking, scanning, or disabling the account are either disruptive, do not confirm the suspicion, or could destroy evidence.

Validation should precede escalation and containment.

Exam trap

The trap here is choosing an active containment measure like blocking or disabling the account, which might stop the attack but destroys evidence and does not validate the suspicion.

407
MCQmedium

In a PKI, what is the role of the root Certificate Authority (CA)?

A.To be the trust anchor for the entire PKI hierarchy
B.To issue certificates directly to end users
C.To generate private keys for all users
D.To revoke certificates and publish CRLs
AnswerA

The root CA sits at the top of the hierarchy and self-signs its own certificate, so every subordinate CA and end-entity certificate chains back to it. That position makes it the trust anchor, and its private key must be strictly offline-protected.

Why this answer

The root Certificate Authority (CA) is the trust anchor in a Public Key Infrastructure (PKI) hierarchy. Its self-signed root certificate is the ultimate trust point from which all subordinate CA certificates and end-entity certificates derive their trust. Without a trusted root, the entire chain of trust collapses, as no certificate can be validated back to a trusted source.

Exam trap

The trap here is that candidates often assume the root CA directly issues end-user certificates or handles revocation, but the SSCP exam tests the understanding that the root CA's primary role is to serve as the immutable trust anchor, with operational tasks delegated to subordinate CAs.

How to eliminate wrong answers

Option B is wrong because the root CA typically does not issue certificates directly to end users; that task is delegated to subordinate or intermediate CAs to limit exposure of the root key. Option C is wrong because the root CA does not generate private keys for users; private keys are generated by the user or their client software and should never be known to the CA. Option D is wrong because while the root CA can theoretically revoke certificates and publish CRLs, in practice this is usually handled by subordinate CAs or a dedicated CRL issuer to reduce operational load on the root.

408
Multi-Selecteasy

A Linux administrator is hardening a server. Which TWO commands are used to manage file permissions? (Select TWO.)

Select 2 answers
A.usermod
B.passwd
C.groupadd
D.chmod
E.chown
AnswersD, E

chmod alters the read, write and execute bits of a file's permission mode, applying symbolic or octal changes to owner, group and others. Hardening requires tightening these access bits, so chmod directly satisfies the task of managing file permissions on the server.

Why this answer

Option D, chmod, is correct because it directly manages file permissions by changing the read, write, and execute bits (the mode) for the owner, group, and others on files and directories, using symbolic or octal notation. Option E, chown, is correct because it manages file ownership, changing the owning user and/or group of a file, which is a core part of file permission management since permissions are evaluated against the owner and group. Option A, usermod, is incorrect because it modifies user account attributes such as group membership, home directory, and shell, not file permissions.

Option B, passwd, is incorrect because it manages user authentication passwords, not file permissions. Option C, groupadd, is incorrect because it creates new groups in the system, not file permissions.

Exam trap

SSCP often tests whether candidates confuse user account management commands (usermod, passwd, groupadd) with file permission commands (chmod, chown) — the question's 'file permissions' phrasing is the key.

409
MCQmedium

A security analyst is evaluating a biometric system. The system currently has a high number of false rejections. Which metric is most directly related to this issue?

A.False Acceptance Rate (FAR)
B.Equal Error Rate (EER)
C.Crossover Error Rate (CER)
D.False Rejection Rate (FRR)
AnswerD

False Rejection Rate measures the proportion of legitimate users incorrectly denied access, which is exactly the high false-rejection symptom described. It is the biometric accuracy metric tied to Type I errors, unlike False Acceptance Rate, which covers impostors wrongly admitted.

Why this answer

The false rejection rate (FRR) is the metric that directly measures the proportion of legitimate users incorrectly rejected by a biometric system. A high number of false rejections is by definition a high FRR, so FRR is the metric most directly related to the reported issue. The other options describe different accuracy metrics or crossover points.

Exam trap

SSCP often tests biometric metrics by describing a symptom (too many false rejections) and asking for the metric — candidates who confuse FAR with FRR, or who pick CER/EER because it sounds more sophisticated, choose the wrong answer.

How to eliminate wrong answers

Option A is wrong because FAR measures false acceptances (unauthorized users let in), which is the opposite problem from false rejections. Option B is wrong because the Equal Error Rate is the point where FAR equals FRR, a comparative accuracy metric, not a direct measure of false rejections. Option C is wrong because the Crossover Error Rate is the same concept as EER — the intersection of FAR and FRR — and does not directly quantify the false rejection problem.

410
Multi-Selecteasy

Which THREE of the following are examples of security awareness training topics?

Select 3 answers
A.How to apply patches to servers
B.Recognizing phishing emails
C.Configuring firewall rules
D.Physical security best practices (e.g., locking screens)
E.Social engineering tactics
AnswersB, D, E

Recognising phishing emails is a core security awareness topic, teaching staff to identify suspicious senders, links and requests. It directly reduces credential theft and malware risk, satisfying the question's requirement for a valid awareness training subject.

Why this answer

Security awareness training targets the general workforce's day-to-day behavior rather than specialized technical administration. Option B (Recognizing phishing emails) is correct because teaching users to spot suspicious senders, spoofed links, and urgent lures is a core awareness objective that reduces credential theft and malware infections. Option D (Physical security best practices such as locking screens) is correct because awareness programs cover everyday physical controls like clean-desk policies, tailgating prevention, and screen locking to protect data from unauthorized access.

Option E (Social engineering tactics) is correct because understanding pretexting, baiting, and impersonation helps employees resist manipulation attempts that bypass technical controls. Options A (applying server patches) and C (configuring firewall rules) are not awareness topics; they are hands-on technical administration tasks performed by IT/security staff, not general-user training content.

Exam trap

The trap here is that candidates confuse technical administration tasks (patching, firewall configuration) with awareness-level training, which is designed for all employees and focuses on behavioral change rather than technical skills.

411
MCQhard

An organization wants to ensure that all new servers are deployed with a hardened baseline configuration. Which of the following is the most effective control to enforce this?

A.Requiring post-deployment security reviews for each server
B.Using a configuration management tool to deploy a hardened image automatically
C.Requiring administrators to manually apply CIS benchmarks after installation
D.Performing periodic vulnerability scans on all servers
AnswerB

Automated configuration management enforces the hardened baseline consistently across every new server, removing manual drift. Deploying a hardened image automatically satisfies the stem's requirement for guaranteed baseline configuration at deployment, unlike documentation or manual checklists.

Why this answer

Using a configuration management tool (e.g., Ansible, Puppet, Chef) to deploy a hardened image automatically ensures that every new server is built from a pre-defined, secure baseline without relying on manual steps. This enforces consistency and prevents configuration drift from the moment of deployment, which is the most effective control for ensuring compliance with hardening standards.

Exam trap

The trap here is that candidates often choose post-deployment reviews or vulnerability scans because they seem like thorough security measures, but the question specifically asks for the most effective control to *enforce* a hardened baseline, which requires a preventive, automated approach rather than a reactive or manual one.

How to eliminate wrong answers

Option A is wrong because post-deployment security reviews are reactive and do not prevent insecure configurations from being deployed; they only identify issues after the fact. Option C is wrong because requiring administrators to manually apply CIS benchmarks after installation introduces human error and inconsistency, and it does not guarantee that hardening is applied before the server is placed into production. Option D is wrong because periodic vulnerability scans detect existing weaknesses but do not enforce a hardened baseline at deployment time; they are a detective control, not a preventive one.

412
MCQeasy

A small business wants to prevent employees from accessing known malicious websites without deploying a full next-generation firewall. The IT consultant recommends a service that filters DNS queries before they reach the public internet. Which technology is being described?

A.A web application firewall (WAF) placed in front of the company's public website.
B.A DNS filtering service that blocks resolution of known malicious domains.
C.An intrusion prevention system (IPS) deployed inline at the network perimeter.
D.A forward proxy that caches frequently visited web content.
AnswerB

DNS filtering intercepts name resolution requests and refuses to return addresses for domains on a threat intelligence blocklist. Because it operates at the resolution stage, it can prevent connections to malicious sites across all applications without installing a full firewall. This matches the consultant's recommendation and the small business constraint.

Why this answer

DNS filtering works by checking each name resolution request against a threat intelligence feed and returning a block response for known malicious domains. It requires no inline firewall, covers all applications that use DNS, and is simple to deploy for a small business. The other options address different layers or purposes and would not deliver the same lightweight outbound protection.

Exam trap

The trap here is assuming that any perimeter security device, such as an IPS or WAF, automatically performs DNS reputation filtering, when those controls inspect different traffic.

413
MCQhard

A security analyst investigates a suspicious process on a Linux web server that is making outbound connections to an unknown IP address. The analyst wants to confirm which executable file is running and whether it has been modified since installation. Which combination of actions best accomplishes this?

A.Check the process owner with the ps command and confirm it is not root
B.Inspect the process's /proc/<pid>/exe link and compare the file hash against a known-good baseline
C.Run netstat to list the established outbound connection
D.Review the process's open file descriptors in /proc/<pid>/fd
AnswerB

The /proc/<pid>/exe symbolic link points to the actual executable backing the running process, even if the file was deleted or renamed, so it reveals the true binary. Hashing that file and comparing it to a trusted baseline shows whether the executable has been altered, satisfying both questions.

Why this answer

Resolving the /proc/<pid>/exe link identifies the exact executable behind the process, and hashing that file against a trusted baseline detects tampering. Used together, these steps confirm both the binary's identity and its integrity, which is what the investigation requires.

Exam trap

The trap here is stopping at network evidence such as the established connection, which proves activity but never identifies the executable or whether it was modified.

414
Multi-Selectmedium

An organization is developing a risk register. Which TWO elements are essential for each risk entry?

Select 2 answers
A.Risk owner
B.Risk description
C.Residual risk level
D.Likelihood and impact rating
E.Mitigation cost
AnswersB, D

Correct: A clear description of the risk is fundamental.

Why this answer

Option B (Risk description) is essential because every risk register entry must clearly document the nature of the risk — what could happen, the threat/vulnerability involved, and the potential consequence — so it can be understood, communicated, and managed consistently. Option D (Likelihood and impact rating) is essential because risk registers require each risk to be assessed and prioritized by combining the probability of occurrence (likelihood) with the severity of the outcome (impact), which drives risk ranking and treatment decisions. Option A (Risk owner) is a valuable governance field but is not one of the two essential elements tested here, as ownership can be assigned after the risk is identified and described.

Option C (Residual risk level) is not essential at the point of entry because residual risk is determined only after mitigation or treatment has been applied. Option E (Mitigation cost) is not essential because cost is a treatment consideration, not a defining attribute required for every risk entry.

Exam trap

The SSCP exam often tests the distinction between essential initial elements (description and rating) versus downstream elements (owner, residual risk, cost) to see if candidates confuse the risk register's foundational data with later risk treatment outputs.

415
MCQmedium

A network administrator wants to prevent unauthorized devices from connecting to the wired network. Which technology can be used to enforce authentication at the switch port level before granting network access?

A.MAC address filtering
B.WPA2-Enterprise
C.VLAN segmentation
D.802.1X
AnswerD

802.1X enforces port-based network access control, requiring a supplicant to authenticate via EAP through the switch to a RADIUS server before any traffic passes. Unauthorised devices fail authentication, so the port stays blocked, satisfying the switch-port-level requirement.

Why this answer

802.1X is an IEEE standard for port-based network access control that authenticates devices before granting access to the wired network. It uses EAP over LAN to communicate with a RADIUS server, ensuring only authorized devices can connect. This directly enforces authentication at the switch port level.

Exam trap

SSCP often tests the confusion between wireless security (WPA2-Enterprise) and wired port security (802.1X), or the misconception that MAC filtering is sufficient for authentication.

How to eliminate wrong answers

Option A is wrong because MAC address filtering can be spoofed and does not provide strong authentication; it merely checks a hardware address. Option B is wrong because WPA2-Enterprise is for wireless networks, not wired switch ports. Option C is wrong because VLAN segmentation isolates traffic but does not authenticate devices before granting network access.

416
MCQeasy

Which access control model enforces security based on classification labels assigned to subjects and objects, commonly used for confidentiality?

A.Clark-Wilson
B.Brewer-Nash
C.Bell-LaPadula
D.Biba
AnswerC

Bell-LaPadula enforces confidentiality through mandatory access control, comparing classification labels on subjects and objects. Its no-read-up and no-write-down rules directly satisfy the stem's requirement for label-based enforcement, preventing lower-cleared subjects from accessing higher-classified data. This contrasts with integrity-focused models such as Biba, which reverse those rules.

Why this answer

Bell-LaPadula is a mandatory access control (MAC) model designed for confidentiality. It enforces the 'no read up, no write down' rules: a subject cannot read an object at a higher classification level, and cannot write to an object at a lower level. This prevents unauthorized disclosure of classified information and is widely used in government and military systems.

Exam trap

SSCP often tests the confusion between Bell-LaPadula (confidentiality, no read up/no write down) and Biba (integrity, no read down/no write up) — candidates who memorize only one direction of the rules pick the wrong model.

How to eliminate wrong answers

Option A is wrong because Clark-Wilson focuses on integrity through well-formed transactions and separation of duties, not confidentiality via classification labels. Option B is wrong because Brewer-Nash (the Chinese Wall model) prevents conflicts of interest in commercial environments by dynamically restricting access based on what a subject has already accessed, not on static classification labels. Option D is wrong because Biba is the integrity counterpart to Bell-LaPadula, enforcing 'no read down, no write up' to prevent data corruption, not confidentiality.

417
MCQeasy

Which of the following is a vulnerability source explicitly based on publicly known flaws?

A.Configuration weaknesses
B.Hardware failure
C.CVEs
D.Design flaws
AnswerC

CVEs are identifiers assigned to publicly disclosed flaws in specific products, so they directly satisfy the stem's requirement for a vulnerability source based on publicly known issues. Unlike proprietary or internal findings, each CVE entry is catalogued and openly accessible, letting analysts correlate exposures against vendor advisories.

Why this answer

C is correct because Common Vulnerabilities and Exposures (CVEs) are a standardized, publicly maintained list of known security flaws. Each CVE entry explicitly documents a specific vulnerability that has been discovered, verified, and published, making it a direct source of publicly known flaws used for vulnerability identification and remediation.

Exam trap

The trap here is that candidates may confuse 'vulnerability source' with 'vulnerability cause'—configuration weaknesses and design flaws are causes of vulnerabilities, but only CVEs represent a formal, publicly known source of flaw documentation.

How to eliminate wrong answers

Option A is wrong because configuration weaknesses are typically the result of improper system setup or misapplied security controls, not a source of publicly known flaws; they are often organization-specific and not cataloged in a public database. Option B is wrong because hardware failure is a physical reliability issue, not a security vulnerability, and is not tracked as a publicly known flaw in vulnerability databases like CVE. Option D is wrong because design flaws are inherent architectural weaknesses that may not be publicly documented or assigned a CVE identifier; they are often discovered during security reviews or penetration testing rather than being listed as known flaws.

418
MCQhard

A company is implementing a new patch management process. After scanning for missing patches, the team must prioritize which patches to apply first. Which combination of factors is most critical for prioritization?

A.CVSS score and asset criticality
B.Number of systems affected and patch size
C.Age of the patch and vendor reputation
D.Cost of the patch and availability of workarounds
AnswerA

CVSS score quantifies technical severity, while asset criticality reflects business impact if that host is compromised. Combining both prevents wasting effort on severe flaws on trivial systems and ensures patches for exploitable vulnerabilities on high-value assets are applied first.

Why this answer

CVSS score quantifies the technical severity of a vulnerability (base, temporal, and environmental metrics), while asset criticality reflects the business impact if that asset is compromised. Combining these two factors ensures patches that are both highly exploitable and protect the most valuable systems are applied first, which is the standard risk-based prioritization approach in patch management frameworks like those from NIST and CIS.

Exam trap

SSCP often tests the distinction between technical severity (CVSS) and business impact (asset criticality), tricking candidates into choosing operational metrics like patch size or cost that feel practical but are not risk-based prioritization factors.

How to eliminate wrong answers

Option B is wrong because the number of systems affected and patch size do not reflect the severity of the vulnerability or the business value of the affected assets — patch size is irrelevant to risk. Option C is wrong because patch age and vendor reputation are not quantitative risk factors; a patch's age does not indicate exploitability, and vendor reputation is subjective. Option D is wrong because cost and workaround availability are operational considerations, not risk-prioritization factors — a cheap patch for a low-severity issue should still rank below an expensive patch for a critical vulnerability.

419
MCQmedium

An organization implements a policy requiring passwords to be at least 12 characters, include uppercase, lowercase, digits, and special characters, and be changed every 60 days. Which password policy elements are being enforced?

A.Complexity, expiry, and lockout
B.Length, complexity, and history
C.Length, complexity, and expiry
D.Length, complexity, and lockout
AnswerC

The policy enforces three distinct controls: a 12-character minimum (length), mixed character categories (complexity), and a 60-day rotation (expiry). Option C names all three elements the stem describes, matching each stated requirement precisely without adding unrelated controls such as history or lockout.

Why this answer

The policy specifies three elements: a minimum length of 12 characters (length), a requirement for uppercase, lowercase, digits, and special characters (complexity), and a 60-day change interval (expiry). Lockout and history are not mentioned in the policy, so they are not being enforced. The correct answer is length, complexity, and expiry.

Exam trap

SSCP often tests the ability to distinguish password policy elements — candidates see '12 characters' and 'uppercase/lowercase/digits/special' and '60 days' but may incorrectly add lockout or history because those are common in real policies, even though they are not stated in the question.

How to eliminate wrong answers

Option A is wrong because lockout (account lockout after failed attempts) is not mentioned in the policy — only complexity and expiry are present, and length is omitted from this option. Option B is wrong because history (preventing password reuse) is not mentioned; the policy does not state that previous passwords cannot be reused. Option D is wrong because lockout is not part of the policy, and history is also absent — only length, complexity, and expiry are enforced.

420
MCQeasy

Which of the following is a primary purpose of implementing a security baseline such as the CIS Benchmarks?

A.To automate incident response procedures
B.To establish a minimum level of security for system configurations
C.To detect real-time threats
D.To comply with regulatory requirements for log retention
AnswerB

CIS Benchmarks define hardened configuration settings that every system must meet, so the baseline establishes a minimum security floor rather than a maximum or an optional target. This directly satisfies the stem's requirement for a primary purpose: consistent, documented minimum configuration across systems.

Why this answer

The primary purpose of implementing a security baseline such as the CIS Benchmarks is to establish a minimum level of security for system configurations. These benchmarks provide prescriptive, consensus-based configuration guidelines (e.g., disabling unnecessary services, setting file permissions, enforcing password policies) that reduce the attack surface and ensure a consistent, hardened starting point across all systems in an organization.

Exam trap

The exam often tests the distinction between a preventive control (security baseline) and detective/reactive controls (IDS, SIEM, SOAR), so candidates mistakenly choose options that describe monitoring or response functions instead of the foundational hardening purpose of a baseline.

How to eliminate wrong answers

Option A is wrong because automating incident response procedures is the function of a Security Orchestration, Automation, and Response (SOAR) platform or playbook, not a static configuration baseline like CIS Benchmarks. Option C is wrong because detecting real-time threats is performed by intrusion detection systems (IDS), security information and event management (SIEM) correlation rules, or endpoint detection and response (EDR) tools, not by a configuration baseline. Option D is wrong because complying with regulatory requirements for log retention is addressed by specific log retention policies and technical controls (e.g., setting log rotation, archival, and secure storage), whereas CIS Benchmarks focus on secure configuration states, not log retention durations.

421
MCQmedium

A company is deploying a VPN for remote employees. They require strong encryption and authentication, and the solution must be compatible with native OS clients without additional software. Which VPN protocol is most appropriate?

A.PPTP
B.SSL VPN with proprietary client
C.IPsec with IKEv2
D.L2TP/IPsec with pre-shared keys
AnswerC

IPsec with IKEv2 provides strong encryption and authentication while being natively supported by Windows, macOS, iOS and Android VPN clients, so no third-party software is required. IKEv2 also reconnects quickly after network changes, suiting remote employees on unstable connections.

Why this answer

IPsec with IKEv2 is a modern VPN protocol that provides strong encryption and authentication, and it is natively supported by most operating systems (Windows, macOS, iOS, Android) without requiring additional client software. It supports flexible authentication methods including certificates and EAP, making it suitable for remote access.

Exam trap

SSCP often tests the trade-off between security and compatibility; candidates may overlook that IKEv2 is natively supported and choose L2TP/IPsec with PSK, which is less secure.

How to eliminate wrong answers

Option A is wrong because PPTP is outdated and has known security vulnerabilities; it does not provide strong encryption. Option B is wrong because an SSL VPN with a proprietary client requires additional software, violating the requirement for native OS compatibility. Option D is wrong because L2TP/IPsec with pre-shared keys is less secure than IKEv2 (PSK is a shared secret that can be compromised) and may require additional configuration, though it is natively supported; however, IKEv2 is more robust and recommended.

422
MCQeasy

A security administrator is configuring a firewall to allow HTTPS traffic from the internet to a web server. Which default port must be permitted?

A.8443
B.8080
C.443
D.80
AnswerC

HTTPS uses TCP port 443 by default for encrypted web traffic, so the firewall rule must permit it inbound to the web server. Port 80 is plain HTTP, while 22 and 3389 serve SSH and RDP respectively.

Why this answer

HTTPS (HTTP over TLS) is assigned TCP port 443 by IANA and is the default port browsers and clients use when no port is specified in an https:// URL. A firewall rule permitting inbound TCP 443 to the web server is therefore required for standard HTTPS traffic from the internet. Port 80 is the default for plain HTTP, not HTTPS.

Exam trap

The trap here is confusing well-known alternate ports (8080 for HTTP proxies, 8443 for admin HTTPS) with the IANA default, so candidates who have seen 8443 in a lab pick it instead of 443.

How to eliminate wrong answers

Option A is wrong because TCP 8443 is a common alternative/administrative HTTPS port (e.g., Tomcat, some management consoles) but is not the IANA-assigned default for HTTPS. Option B is wrong because TCP 8080 is a common alternate HTTP port used by proxies and application servers, not the default HTTPS port. Option D is wrong because TCP 80 is the default port for unencrypted HTTP, so permitting it would not enable HTTPS traffic.

423
MCQmedium

A healthcare provider must protect the confidentiality of patient records stored on a shared network drive. The compliance officer mandates that the encryption solution use a symmetric algorithm with a 256-bit key and operate as a block cipher. Which of the following should the security administrator select to meet these requirements?

A.AES-256
B.RSA-2048
C.SHA-256
D.3DES
AnswerA

AES-256 is a symmetric block cipher standardized by NIST with a 256-bit key and a 128-bit block size. It satisfies the requirement for strong symmetric encryption and is widely supported in both hardware and software for protecting data at rest, including patient records on shared storage.

Why this answer

AES-256 is the correct choice because it is a symmetric block cipher with a 256-bit key, exactly matching the compliance requirement. RSA is asymmetric and too slow for bulk data, 3DES lacks the required key size and is deprecated, and SHA-256 is a hash function that provides no confidentiality. Only AES-256 satisfies all stated conditions for protecting stored records.

Exam trap

The trap here is confusing hash functions such as SHA-256 with encryption algorithms, or assuming any symmetric cipher like 3DES meets a 256-bit key requirement.

424
MCQmedium

A network administrator needs to ensure that internal users can access only approved external websites. Which technology should be implemented?

A.Web Proxy with content filtering
B.Intrusion Prevention System (IPS)
C.Virtual Private Network (VPN)
D.Network Address Translation (NAT)
AnswerA

A web proxy with content filtering intercepts outbound HTTP and HTTPS requests, evaluating each destination against approved categories and blocking unapproved sites. This enforces the allow-list requirement for internal users, unlike firewalls that filter by IP or port alone.

Why this answer

A web proxy with content filtering intercepts HTTP/HTTPS requests from internal users and applies policy rules (e.g., URL whitelists, category blocking) to allow only approved external websites. This technology operates at the application layer, inspecting the full URL and content, making it the correct choice for granular access control.

Exam trap

ISC2 often tests the misconception that an IPS or firewall can perform URL filtering, but these devices typically filter based on IP/port/application signatures, not full URL paths or content categories, which is the specific function of a web proxy with content filtering.

How to eliminate wrong answers

Option B (Intrusion Prevention System) is wrong because an IPS monitors network traffic for malicious activity and blocks attacks, not for enforcing website access policies based on URL or content categories. Option C (Virtual Private Network) is wrong because a VPN creates an encrypted tunnel for secure remote access but does not filter or restrict which external websites users can visit. Option D (Network Address Translation) is wrong because NAT translates private IP addresses to a public IP for internet connectivity and has no capability to filter or approve specific websites.

425
Drag & Dropmedium

Drag and drop the steps for implementing a patch management process into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order for patch management is Inventory, Assess, Test, Deploy, Verify. This sequence ensures that all systems are identified, patches are evaluated, tested to avoid disruptions, deployed safely, and finally confirmed as applied correctly.

426
MCQeasy

A help desk technician receives multiple reports that users cannot access a critical web application. The application's error log shows repeated '403 Forbidden' errors. Which of the following is the most likely cause?

A.The web application firewall is blocking legitimate traffic.
B.The SSL certificate has expired.
C.The application's database connection pool is exhausted.
D.The web server's IP address has changed.
AnswerA

403 Forbidden responses indicate the server understood the request but refused authorisation, which is characteristic of a web application firewall or access rule blocking traffic. This satisfies the scenario's symptom of legitimate users being denied, rather than authentication or availability failures.

Why this answer

A 403 Forbidden error indicates that the server understood the request but is refusing to authorize it. The most likely cause is the web application firewall (WAF) blocking legitimate traffic due to false positives or overly strict rules. Option B (expired SSL certificate) would cause SSL handshake errors, not 403.

Option C (database connection pool exhausted) would result in 500-type errors. Option D (IP address change) would cause connection timeouts or DNS errors, not 403.

427
MCQhard

A healthcare organization deploys a new electronic records system. Clinicians may access patient records only while assigned to the cardiology department, and access is automatically revoked when they rotate to oncology. Which access control model best supports this requirement?

A.Role-based access control (RBAC)
B.Discretionary access control (DAC)
C.Attribute-based access control (ABAC)
D.Mandatory access control (MAC)
AnswerA

RBAC assigns permissions to roles rather than individuals, so a clinician's cardiology role grants record access only while assigned to it. Rotating to oncology means the cardiology role assignment is removed and the oncology role takes over, automatically changing access. This matches the requirement that access be tied to department membership and revoked upon rotation without per-user intervention.

Why this answer

The requirement ties access to a clinician's current department and revokes it upon rotation, which is precisely how role-based access control operates. Permissions are grouped into roles, and users receive access only through their assigned roles. When the cardiology role assignment is removed during rotation, access ends automatically, while the oncology role grants the appropriate new access.

This makes RBAC the most natural and administratively efficient fit.

Exam trap

The trap here is assuming that any model capable of expressing department membership, such as ABAC, is equally suitable, when the scenario is specifically about role assignments that change with job rotation.

428
MCQeasy

A security administrator needs to securely transfer files between two servers over an untrusted network. The administrator wants to use a protocol that provides encryption and authentication and operates over TCP port 22. Which protocol should be used?

A.File Transfer Protocol (FTP)
B.Hypertext Transfer Protocol (HTTP)
C.Secure Shell (SSH) File Transfer Protocol (SFTP)
D.Trivial File Transfer Protocol (TFTP)
AnswerC

SFTP is a subsystem of SSH that operates over TCP port 22. It provides strong encryption and authentication for file transfers, protecting data in transit. It supports public key and password authentication and is widely used for secure file transfer. This matches the requirement to use TCP port 22 and ensures confidentiality and integrity.

Why this answer

SFTP is the correct protocol because it runs over SSH on TCP port 22, providing encryption and authentication for file transfers. FTP, TFTP, and HTTP are insecure and do not meet the requirements. SFTP ensures that data remains confidential and integrity-protected during transit, making it suitable for untrusted networks.

Exam trap

The trap here is confusing SFTP with FTPS or assuming that FTP can be secured with a simple configuration change.

429
MCQhard

A security analyst is reviewing alerts from a Network Intrusion Detection System (NIDS) that monitors a demilitarized zone segment. Over one week, the same alert fires hundreds of times for traffic that the business has confirmed is a legitimate partner integration. The analyst has verified the signature is correctly written and the traffic is truly benign. What is the most appropriate action?

A.Disable the NIDS sensor on the DMZ segment to stop the noise until the partner integration is retired.
B.Increase the alert severity of the signature so that analysts investigate every occurrence manually.
C.Create a tuned exception or suppression rule scoped to the specific signature, source, and destination of the partner traffic.
D.Delete the signature from the NIDS rule set and rely on firewall logs for DMZ monitoring.
AnswerC

Since the signature is accurate and the traffic is verified benign, the correct response is targeted tuning that suppresses only that pattern while preserving the signature for all other traffic. Scoping the exception to the exact source, destination, and signature keeps detection coverage intact for genuinely malicious activity on the DMZ segment.

Why this answer

When a signature is accurate but a verified benign source repeatedly triggers it, targeted suppression is the proportionate response. Scoping the exception to the exact signature, source, and destination eliminates the noise without weakening detection elsewhere. Deleting the signature or disabling the sensor would create blind spots, and raising severity would simply escalate benign alerts for manual review.

Exam trap

The trap here is treating verified benign traffic as a reason to remove or disable the detection, rather than tuning it narrowly to preserve coverage.

430
MCQhard

An organization implements an attribute-based access control (ABAC) system with the following policy: if user.role == 'doctor' and resource.type == 'patient_record' and environment.time between 08:00-18:00 then permit. A doctor tries to access a patient record at 20:00. What is the result?

A.Permit
B.Indeterminate
C.Not applicable
D.Deny
AnswerD

ABAC evaluates every attribute in the policy, and all conditions must be satisfied for permit. The time attribute fails because 20:00 falls outside the 08:00-18:00 window, so the combined rule evaluates to deny despite the doctor role and patient record matching.

Why this answer

The ABAC policy requires the environment.time to be between 08:00 and 18:00 for access to be permitted. Since the doctor attempts access at 20:00, which falls outside this time window, the condition is not met, and the policy evaluates to 'deny' by default in a closed-system ABAC model. The correct result is Deny (option D).

Exam trap

ISC2 often tests the default deny principle in ABAC, where candidates mistakenly assume a missing explicit 'deny' rule means 'permit' or 'not applicable', but the absence of a matching permit condition results in an implicit deny.

How to eliminate wrong answers

Option A is wrong because 'permit' would only occur if all conditions in the policy are satisfied, but the time condition (08:00-18:00) is false at 20:00. Option B is wrong because 'indeterminate' typically arises from missing attributes or policy evaluation errors, not from a clear false condition; here, all attributes are present and the time is explicitly outside the allowed range. Option C is wrong because 'not applicable' would mean the policy does not match the request at all, but the user role and resource type do match; the policy applies, but the time condition fails, leading to a deny.

431
MCQhard

What is the analyst's BEST next step?

A.Isolate the system
B.Block PowerShell execution
C.Decode the command to analyze
D.Run a full antivirus scan
AnswerC

Decoding the command converts encoded payloads, such as Base64 or obfuscated script, into readable form, revealing its true intent and parameters. This directly enables the analyst to determine whether the activity is malicious before deciding on containment or escalation.

Why this answer

When an analyst encounters a suspicious PowerShell command — typically from a script block log (Event ID 4104), a command-line audit event, or an EDR alert — the encoded payload is usually Base64-encoded and unreadable at a glance. Decoding it (e.g., via CyberChef, PowerShell's [System.Text.Encoding]::Unicode.GetString([Convert]::FromBase64String(...)), or tools like PowerDecode) reveals the actual commands, URLs, and IOCs, which is essential before deciding on containment. You cannot make an informed containment or eradication decision without first understanding what the command does.

Exam trap

The trap here is confusing the investigative step (decode/analyze) with the containment step (isolate) — SSCP and similar exams frequently place a tempting 'isolate the system' answer first to lure candidates who skip analysis.

How to eliminate wrong answers

Option A is wrong because isolating the system is a containment action that should follow, not precede, understanding the threat — isolating prematurely can tip off an attacker, disrupt business operations, and destroy volatile evidence needed for scoping. Option B is wrong because blocking PowerShell execution wholesale is a blunt, disruptive control that breaks legitimate administrative automation and is a mitigation, not an investigative step. Option D is wrong because running a full antivirus scan is a detection/remediation action that may miss fileless PowerShell attacks entirely and does not answer the question of what the command actually does.

432
Multi-Selecthard

Which THREE of the following are common techniques for identifying risks?

Select 3 answers
A.Stakeholder interviews
B.Penetration testing
C.SWOT analysis
D.Quantitative risk analysis
E.Brainstorming sessions
AnswersA, C, E

Interviews with knowledgeable individuals are a key identification technique.

Why this answer

Stakeholder interviews are a common technique for identifying risks because they leverage the knowledge and experience of individuals who have a direct interest in or are affected by the project or system. By engaging stakeholders, you can uncover risks that may not be apparent from documentation or technical analysis, as they provide insights into operational, regulatory, and business-specific threats. This aligns with the risk identification process in the SSCP domain, which emphasizes gathering input from diverse sources to build a comprehensive risk profile.

Exam trap

ISC2 often tests the distinction between risk identification techniques and risk analysis or validation techniques, so the trap here is confusing a method like penetration testing (which validates controls) or quantitative analysis (which evaluates risk) with the initial discovery process of risk identification.

433
Multi-Selecthard

Which THREE of the following are key elements of a security incident response plan?

Select 3 answers
A.Vendor management process
B.Preparation and training
C.Restoring all systems from backup
D.Containment, eradication, and recovery
E.Detection and analysis
AnswersB, D, E

Preparation and training build the capability required before an incident occurs, ensuring personnel know their roles, escalation paths and containment procedures. This satisfies the stem's demand for a key element, since an untested plan fails under pressure; readiness depends on rehearsed response rather than documentation alone.

Why this answer

The three correct answers are B, D, and E because they map directly to the core phases of the NIST SP 800-61 incident response lifecycle. B (Preparation and training) is right because preparation establishes the IR policy, tools, communication paths, and team readiness—including training and exercises—before an incident occurs. E (Detection and analysis) is right because it covers identifying and validating potential incidents and determining their scope, impact, and root cause.

D (Containment, eradication, and recovery) is right because it covers limiting damage, removing the threat, and restoring normal operations. A (Vendor management process) is not a core IR phase—it is a supporting governance activity—and C (Restoring all systems from backup) is too narrow and potentially wrong, since recovery is selective and validated, not a blanket restore of every system.

Exam trap

ISC2 often tests the misconception that 'restoring all systems from backup' is a standalone key element, when in fact it is a sub-step of the recovery phase and must be preceded by containment and eradication to avoid reinfection.

434
MCQeasy

Which of the following is a primary function of a firewall?

A.Filter traffic based on rules
B.Assign IP addresses
C.Encrypt network traffic
D.Detect malware on endpoints
AnswerA

Filtering traffic against defined rule sets is the firewall's core function, inspecting packets by source, destination, port and protocol before permitting or denying passage. This directly satisfies the stem's requirement for a primary function, distinguishing firewalls from antivirus software or intrusion detection systems, which analyse content or behaviour rather than enforcing boundary access rules.

Why this answer

A firewall's primary function is to filter network traffic based on a defined set of security rules, such as source/destination IP addresses, ports, and protocols. It operates at the network layer (or higher) to permit or deny packets, acting as a barrier between trusted and untrusted networks. This rule-based filtering is the core mechanism that enforces access control policies.

Exam trap

The trap here is that candidates often confuse a firewall's primary function with ancillary features like VPN termination or intrusion detection, but the SSCP exam emphasizes that filtering traffic based on rules is the fundamental and defining role of a firewall.

How to eliminate wrong answers

Option B is wrong because assigning IP addresses is the function of a DHCP server, not a firewall; firewalls may integrate DHCP services but that is not their primary role. Option C is wrong because encrypting network traffic is performed by VPN gateways, IPsec, or TLS, not by a standard firewall; firewalls can inspect encrypted traffic but do not perform the encryption themselves. Option D is wrong because detecting malware on endpoints is the function of endpoint protection platforms (EPP) or antivirus software; firewalls may include intrusion prevention systems (IPS) to detect network-based threats, but endpoint malware detection is outside their scope.

435
MCQhard

A financial institution is implementing a digital signature solution to ensure the integrity and authenticity of wire transfer instructions. The solution must provide non-repudiation and use a NIST-approved algorithm. Which of the following should the security architect select?

A.HMAC-SHA256
B.AES-256-GCM
C.ECDSA with SHA-256
D.RSA-1024 with SHA-1
AnswerC

ECDSA (Elliptic Curve Digital Signature Algorithm) with SHA-256 is a NIST-approved digital signature algorithm (FIPS 186-4) that provides integrity, authenticity, and non-repudiation. It uses elliptic curve cryptography, which offers strong security with smaller key sizes compared to RSA. This meets the financial institution's requirements for a NIST-approved algorithm.

Why this answer

ECDSA with SHA-256 is a NIST-approved digital signature algorithm that provides non-repudiation, integrity, and authenticity. It is based on elliptic curve cryptography, which is efficient and secure with smaller key sizes. The other options either lack non-repudiation (HMAC, AES-GCM) or use deprecated algorithms (RSA-1024 with SHA-1).

Exam trap

The trap here is confusing message authentication codes or symmetric encryption with digital signatures, which are the only cryptographic mechanisms that provide non-repudiation.

436
MCQeasy

A retail company issues contactless smart cards to employees for physical entry to its data center. The security manager wants to ensure that a lost card cannot be used by someone who finds it, without adding a fingerprint reader at every door. Which access control enhancement best meets this requirement?

A.Require a personal identification number entered on the door keypad in addition to presenting the card
B.Increase the encryption key length used by the card's contactless interface
C.Enable anti-passback so the system rejects a card presented twice without an intervening exit
D.Shorten the card's validity period and require reissuance every quarter
AnswerA

Combining something the employee has, the smart card, with something the employee knows, a personal identification number, means a found card alone is insufficient for entry. This satisfies the requirement without adding biometric hardware at each door, and it is a straightforward two-factor implementation for physical access. The card still provides the credential, while the number proves the presenter is the authorized holder.

Why this answer

The requirement is to stop a finder from using a lost card, which calls for adding a second authentication factor tied to the person rather than the token. A personal identification number supplies that knowledge factor at low cost and without new biometric hardware at every door. Cryptography, expiration, and anti-passback all strengthen the credential system in different ways but none of them verifies who is presenting the card.

Exam trap

The trap here is equating stronger card security technology with verification of the person, when only an additional factor proves who is holding the card.

437
MCQeasy

A small financial services company has deployed a SIEM solution collecting logs from their firewall, web server, and domain controller. They also have an IDS monitoring the network perimeter. The security analyst receives an alert from the IDS indicating a potential exploit attempt against the web server from an external IP. The analyst checks the SIEM and sees that the firewall log shows the connection was allowed, but the web server log does not show any corresponding request. The domain controller logs show no abnormal activity. The company has a policy to immediately contain any confirmed threats. What should the analyst do first based on this information?

A.Reboot the web server to clear any potential memory-resident malware
B.Block the external IP at the firewall
C.Verify the web server's integrity by checking for filesystem changes or anomalous processes
D.Escalate the alert to the incident response team
AnswerC

The firewall allowed the connection yet the web server logged no matching request, so the exploit may have succeeded silently. Checking filesystem changes and anomalous processes establishes whether compromise actually occurred before invoking the containment policy, avoiding premature isolation based on unconfirmed evidence.

Why this answer

The analyst should first verify the web server's integrity by checking for filesystem changes or anomalous processes, because the IDS alert plus the firewall 'allow' but missing web server log entry suggests a possible discrepancy—either the request was dropped before reaching the app, or the web server was compromised and its logging tampered with. Confirming whether exploitation actually occurred is the correct first step before containment, since the policy requires containing 'confirmed' threats. This aligns with the incident response 'identification/validation' phase before eradication and containment.

Exam trap

SSCP often tests the order of incident response steps—candidates jump to containment (block IP, reboot) because the scenario feels urgent, but the policy says 'confirmed threats,' and the evidence is not yet confirmed, so verification must come first.

How to eliminate wrong answers

Option A is wrong because rebooting the web server is a disruptive containment/remediation action that would destroy volatile evidence (memory, running processes) and should not precede verification. Option B is wrong because blocking the external IP is containment, which the policy permits only for confirmed threats—and the evidence is currently ambiguous, not confirmed. Option D is wrong because escalating to the IR team is premature; the analyst should first perform triage/validation to determine whether an incident actually exists, and escalation without validation wastes IR resources.

438
MCQeasy

Which backup strategy is MOST suitable for a server with an RTO of 4 hours and an RPO of 15 minutes?

A.Full backup daily, transaction log backup every 15 minutes
B.Full backup daily
C.Full backup monthly, incremental daily
D.Full backup weekly, differential daily
AnswerA

Transaction log backups every 15 minutes cap data loss at 15 minutes, meeting the RPO, while daily full backups plus log replay restore the server within the 4-hour RTO. Differential or weekly-only schemes cannot satisfy both targets simultaneously.

Why this answer

A full backup daily combined with transaction log backups every 15 minutes meets the RPO of 15 minutes by allowing point-in-time recovery to within that window, and the full backup ensures the RTO of 4 hours is achievable because restoring the full backup plus the transaction logs is a well-understood process that can complete within the time limit. Transaction log backups capture every committed change, enabling granular recovery without requiring a full backup more frequently.

Exam trap

ISC2 often tests the distinction between RPO and RTO by making candidates think that more frequent full backups are needed for a low RPO, when in fact transaction log or differential backups can achieve the same with less overhead, and the trap here is assuming that incremental or differential backups alone can meet a 15-minute RPO without log backups.

How to eliminate wrong answers

Option B is wrong because a daily full backup alone cannot achieve an RPO of 15 minutes; any data loss would be up to 24 hours. Option C is wrong because monthly full backups with incremental daily backups would require restoring the full backup plus all incrementals, which is slow and cannot guarantee an RTO of 4 hours, and the RPO would be up to 24 hours (not 15 minutes). Option D is wrong because a weekly full backup with differential daily backups still results in an RPO of up to 24 hours (since differentials do not provide point-in-time recovery within 15 minutes), and restoring a full backup plus a differential can be time-consuming, risking the 4-hour RTO.

439
MCQmedium

A security administrator is configuring password policies to meet compliance. Which combination of settings provides the strongest protection against brute-force attacks?

A.Minimum 10 characters, no complexity, lockout after 3 attempts, history of 1
B.Minimum 6 characters, complexity required, lockout after 10 attempts, history of 5
C.Minimum 8 characters, no complexity, no lockout, password history of 3
D.Minimum 12 characters, complexity required, lockout after 5 attempts, history of 10
AnswerD

Twelve-character minimum length with complexity raises brute-force search space, lockout after five attempts throttles online guessing, and history of ten blocks reuse of previously compromised passwords. Together these settings address brute-force and credential-reuse vectors more strongly than any shorter or lockout-free combination.

Why this answer

The strongest brute-force protection combines a long minimum length (12 characters), complexity requirements, a tight lockout threshold (5 attempts), and a deep password history (10) to prevent reuse. Length exponentially increases the search space, complexity widens the character set, lockout throttles online guessing, and history blocks cycling back to old passwords.

Exam trap

SSCP often tests the trade-off between length, complexity, lockout, and history, tempting candidates to pick complexity-heavy but short passwords over longer ones.

How to eliminate wrong answers

Option A is wrong because 10 characters with no complexity and history of 1 is weaker — no complexity reduces the character set, and history of 1 allows immediate reuse of the previous password. Option B is wrong because 6 characters is far too short regardless of complexity or lockout, and lockout after 10 attempts is looser than 5. Option C is wrong because 8 characters with no complexity, no lockout, and history of 3 offers no brute-force throttling at all — an attacker can guess indefinitely.

440
MCQmedium

A security administrator needs to ensure that all servers are configured with a hardened baseline. Which tool is best suited to detect deviations from the baseline configuration?

A.Vulnerability scanner
B.Asset management database
C.SCAP scanner
D.SIEM
AnswerC

An SCAP scanner evaluates system configurations against standardised checklists such as DISA STIG or CIS benchmarks, reporting deviations from the hardened baseline. This satisfies the requirement to detect configuration drift, which signature-based vulnerability scanners alone would not reliably identify.

Why this answer

SCAP (Security Content Automation Protocol) scanners are specifically designed to automate the verification of system configurations against a defined baseline, such as a hardened image or a security policy. They use standardized checklists (e.g., XCCDF, OVAL) to detect deviations, making them the ideal tool for this task. Unlike vulnerability scanners, SCAP scanners focus on configuration compliance rather than known vulnerabilities.

Exam trap

The trap here is that candidates confuse a vulnerability scanner (which finds weaknesses) with a configuration compliance scanner (which checks for policy drift), but the question specifically asks for detecting deviations from a baseline, not vulnerabilities.

How to eliminate wrong answers

Option A is wrong because a vulnerability scanner (e.g., Nessus, Qualys) primarily identifies known software vulnerabilities (CVEs) and missing patches, not configuration drift from a hardened baseline. Option B is wrong because an asset management database (e.g., CMDB) stores inventory and configuration items but does not actively scan or detect real-time deviations from a baseline. Option D is wrong because a SIEM (Security Information and Event Management) aggregates and correlates logs for incident detection, but it does not perform proactive configuration compliance checks against a baseline.

441
MCQmedium

An analyst detects suspicious outbound traffic from a workstation to a known command-and-control IP. Which IoC blocking method is MOST appropriate as an immediate containment measure?

A.Delete the malicious files from the system
B.Remove the malware from the workstation using EDR
C.Block the IP address at the perimeter firewall
D.Disable the user's account
AnswerC

Blocking the command-and-control IP at the perimeter firewall immediately severs the workstation's outbound channel, halting data exfiltration and further instruction. This satisfies the containment constraint by stopping active communication fast, before deeper host remediation begins.

Why this answer

Blocking the IP address at the perimeter firewall is the most appropriate immediate containment measure because it directly cuts the outbound communication channel to the known command-and-control (C2) server. This stops data exfiltration and prevents the attacker from issuing further commands, buying time for deeper analysis. Firewall ACLs or blackhole routes can be applied in seconds without altering the endpoint, which is critical when the malware may have persistence mechanisms or anti-forensic capabilities.

Exam trap

The trap is that candidates may focus on endpoint remediation (e.g., deleting files or removing malware) rather than immediate containment through network-level blocking, which is the priority in incident response.

How to eliminate wrong answers

Option A is wrong because deleting malicious files from the system does not stop active C2 traffic; the malware may be running in memory or have already established a persistent connection, and file deletion alone does not terminate existing network sessions. Option B is wrong because removing malware using EDR is a remediation step, not an immediate containment measure; EDR removal can take time, may trigger malware defenses, and does not instantly block the outbound C2 traffic already in progress. Option D is wrong because disabling the user's account does not affect the malware's network communication; the malware runs as a process independent of user authentication and can continue sending data over the network even with the account disabled.

442
Multi-Selectmedium

A security administrator is reviewing the organization's incident response plan. The plan must include procedures for handling security incidents. Which of the following are appropriate steps to include in the incident response process? (Choose two.)

Select 2 answers
A.Immediate shutdown of all network services to isolate the incident.
B.Public disclosure of the incident details to all employees.
C.Containment of the incident to prevent further damage.
D.Immediate deletion of all logs to prevent attacker access.
E.Eradication of the root cause of the incident.
AnswersC, E

Containment is a critical step in incident response that aims to limit the scope and impact of an incident. It involves isolating affected systems, disabling compromised accounts, and preventing the spread of malware. This step follows identification and precedes eradication and recovery. Without containment, the incident could escalate and cause more damage, so it is an essential part of the process.

Why this answer

The incident response process typically includes preparation, identification, containment, eradication, recovery, and lessons learned. Containment and eradication are two key steps. Deleting logs destroys evidence, public disclosure to all employees is not a standard step, and shutting down all network services is overly broad and disruptive.

Thus, containment and eradication are the correct steps to include.

Exam trap

The trap here is thinking that drastic actions like deleting logs or shutting down all services are part of incident response, when in fact containment and eradication are the structured steps.

443
MCQhard

An incident responder is analyzing a network packet capture to determine the scope of a data exfiltration incident. The responder notices a large volume of outbound traffic to an unfamiliar IP address over port 443. Which of the following should the responder do FIRST to determine if the traffic is malicious?

A.Block the IP address at the firewall to stop the exfiltration.
B.Check the IP address against a threat intelligence feed to see if it is known malicious.
C.Inspect the packet payload and metadata for signs of command-and-control or data exfiltration.
D.Perform reverse DNS lookup and WHOIS on the IP address to gather ownership information.
AnswerC

The first step in determining if the traffic is malicious is to analyze the packets themselves. This includes examining payloads for known malware signatures, checking for unusual protocols or patterns, and looking at metadata such as packet sizes, timing, and frequency. This analysis can reveal if the traffic is encrypted command-and-control, data exfiltration, or benign. It provides the evidence needed to justify further actions.

Why this answer

To determine if the outbound traffic is malicious, the responder must first inspect the packet payload and metadata. This direct analysis can reveal signs of exfiltration, such as large data transfers, unusual protocols, or communication patterns indicative of command-and-control. It provides concrete evidence before taking any containment or intelligence-gathering steps that might be premature.

Exam trap

The trap here is jumping to containment or external intelligence lookups before analyzing the actual traffic, which is the most direct way to confirm malicious activity.

444
Multi-Selectmedium

Which TWO of the following are effective measures to prevent cross-site scripting (XSS) vulnerabilities in a web application?

Select 2 answers
A.Implement a Content Security Policy (CSP).
B.Use a web application firewall (WAF) to block known XSS payloads.
C.Replace GET requests with POST for all form submissions.
D.Encode all user input before displaying it in HTTP responses.
E.Use HTTPS for all communications.
AnswersA, D

A Content Security Policy restricts which sources the browser may load scripts from, so injected inline or third-party scripts are refused execution. This mitigates XSS by blocking the payload's execution path, satisfying the requirement for an effective preventive measure against cross-site scripting.

Why this answer

Option A is correct because a Content Security Policy (CSP) delivered via the Content-Security-Policy HTTP response header restricts which scripts the browser may execute (e.g., disallowing inline scripts with 'unsafe-inline' and limiting sources via script-src), which directly mitigates the impact and execution of injected XSS payloads. Option D is correct because context-aware output encoding (e.g., HTML entity encoding, JavaScript/attribute/URL encoding) ensures that user-supplied data is rendered as inert text rather than executable markup or script when placed into HTTP responses, which is the primary defense against XSS. Option B is not a reliable preventive measure because a WAF only pattern-matches known payloads and can be bypassed with obfuscation or novel vectors, so it is a compensating control rather than a fix.

Option C does not prevent XSS because the HTTP method (GET vs. POST) is irrelevant to whether untrusted input is safely rendered in the response. Option E does not prevent XSS because HTTPS only protects data in transit against eavesdropping and tampering; injected scripts still execute in the victim's browser over an encrypted connection.

Exam trap

SSCP often tests that WAF and HTTPS are compensating/detective controls, not preventive XSS fixes — candidates pick the WAF because it 'blocks XSS', but the exam wants output encoding and CSP.

445
Multi-Selecthard

Which THREE of the following are common indicators of a cross-site scripting (XSS) attack? (Choose three.)

Select 3 answers
A.Unusual cookie values or multiple cookies
B.JavaScript execution in the browser's developer console that was not initiated by the user
C.Presence of script tags in the page source that are not part of the original application
D.Unexpected pop-up windows in the browser
E.Unusual network traffic to external IP addresses
AnswersB, C, D

XSS payloads often execute script automatically.

Why this answer

XSS attacks often inject malicious JavaScript that executes in the victim's browser without user initiation. Observing unexpected script execution in the developer console indicates that an attacker's payload has run, which is a direct sign of a successful XSS exploit.

Exam trap

ISC2 often tests the distinction between direct indicators of an attack (like unexpected script execution or script tags) and secondary consequences (like unusual network traffic or cookie anomalies), causing candidates to select options that are results of an attack rather than the attack itself.

446
MCQeasy

Which of the following backup methods copies all data that has changed since the last full backup, regardless of any intermediate backups?

A.Differential backup
B.Full backup
C.Incremental backup
D.Snapshot backup
AnswerA

Differential backups capture all data changed since the last full backup, ignoring intermediate backups entirely. Incremental backups would only copy changes since the most recent backup of any type, so differential is the precise match for the stem's wording.

Why this answer

A differential backup copies all data that has changed since the last full backup, regardless of any intermediate backups. This means each differential backup grows in size as it accumulates all changes made since the last full backup, making it distinct from incremental backups which only capture changes since the last backup of any type.

Exam trap

The trap here is that candidates often confuse differential and incremental backups, mistakenly thinking differential only captures changes since the last backup of any type, when it actually captures all changes since the last full backup.

How to eliminate wrong answers

Option B is wrong because a full backup copies all data, not just changed data since the last full backup. Option C is wrong because an incremental backup copies only data that has changed since the last backup (whether full or incremental), not since the last full backup. Option D is wrong because a snapshot backup captures the state of a system at a point in time, often using copy-on-write technology, and is not a traditional backup method that tracks changes since a full backup.

447
MCQhard

An organization wants to implement a centralized authentication system that supports single sign-on and uses tickets. Which technology should they choose?

A.LDAP
B.Kerberos
C.SAML
D.RADIUS
AnswerB

Kerberos issues time-stamped tickets through a Key Distribution Centre, letting users authenticate once and access multiple services without resending credentials. This directly satisfies the stem's twin requirements: centralised authentication plus ticket-based single sign-on. Microsoft Entra ID uses token-based protocols instead, so it does not meet the ticket criterion.

Why this answer

Kerberos is the correct choice because it is a ticket-based authentication protocol that provides single sign-on (SSO) capabilities. It uses a trusted third-party Key Distribution Center (KDC) to issue time-limited tickets, allowing users to authenticate once and access multiple services without re-entering credentials.

Exam trap

The trap here is that candidates often confuse LDAP (a directory protocol) with authentication, or assume SAML's SSO capability uses tickets, when in fact Kerberos is the only option that explicitly uses tickets as its core mechanism.

How to eliminate wrong answers

Option A (LDAP) is wrong because LDAP is a directory access protocol used for querying and modifying directory services, not a ticket-based authentication system; it does not inherently support SSO via tickets. Option C (SAML) is wrong because SAML is an XML-based federated identity standard that uses assertions (not tickets) for SSO across domains, but it relies on browser redirects and does not use a ticket-granting ticket model like Kerberos. Option D (RADIUS) is wrong because RADIUS is a network access protocol for AAA (Authentication, Authorization, Accounting) typically used for dial-up or VPN connections, and it does not provide ticket-based SSO; it uses shared secrets and is not designed for centralized ticket management.

448
MCQmedium

A security administrator is configuring a new system and wants to enforce a mandatory access control model to ensure confidentiality of classified data. Which access control model should the administrator implement?

A.Discretionary Access Control (DAC)
B.Biba
C.Role-Based Access Control (RBAC)
D.Bell-LaPadula
AnswerD

Bell-LaPadula enforces mandatory access control through no read up and no write down, preventing subjects from reading data above their clearance or leaking it to lower levels. This directly preserves confidentiality of classified data, unlike integrity-focused models such as Biba.

Why this answer

Bell-LaPadula is the mandatory access control model designed to enforce confidentiality using the 'no read up, no write down' rules (simple security property and *-property). It assigns security labels to subjects and objects and prevents lower-cleared subjects from reading higher-classified data, directly meeting the requirement to protect classified information.

Exam trap

SSCP often tests the confusion between Bell-LaPadula (confidentiality, no read up/no write down) and Biba (integrity, no read down/no write up) — candidates swap the two models.

How to eliminate wrong answers

Option A is wrong because DAC lets resource owners set permissions at their discretion, which cannot enforce mandatory confidentiality labels. Option B is wrong because Biba is the integrity model (no read down, no write up) — it protects data integrity, not confidentiality. Option C is wrong because RBAC assigns permissions based on roles, not classification labels, and is not a mandatory model in the Bell-LaPadula sense.

449
MCQeasy

What is the default port for Microsoft SQL Server?

A.443
B.3389
C.1433
D.3306
AnswerC

Microsoft SQL Server listens on TCP port 1433 by default for client connections, satisfying the stem's request for the standard port. Named instances instead use dynamic ports via the SQL Server Browser service on UDP 1434, but a default instance answers on 1433 unless an administrator has reconfigured it.

Why this answer

Microsoft SQL Server's default instance listens on TCP port 1433 for client connections using the Tabular Data Stream (TDS) protocol. This is the well-known port assigned by IANA for SQL Server, and it is what clients use when connecting without specifying a port. Named instances, however, use dynamic ports and rely on the SQL Server Browser service on UDP 1434 to direct clients to the correct port.

Exam trap

SSCP often tests the confusion between default ports of common services, especially database systems like SQL Server (1433) and MySQL (3306), or remote access protocols like RDP (3389).

How to eliminate wrong answers

Option A is wrong because port 443 is the default for HTTPS (HTTP over TLS), not for SQL Server. Option B is wrong because port 3389 is used by Microsoft Remote Desktop Protocol (RDP) for remote desktop connections, not database traffic. Option D is wrong because port 3306 is the default port for MySQL and MariaDB, not Microsoft SQL Server.

450
MCQhard

During a malware containment operation, the incident response team decides to isolate an infected endpoint using network access controls. However, the malware is spreading via removable media. Which additional containment measure should the team implement?

A.Block the malware's command-and-control IP at the firewall
B.Disable the user's account and force a password reset
C.Reimage the infected system immediately
D.Group policy to disable USB ports or restrict autorun
AnswerD

Network isolation blocks lateral spread over the LAN but does nothing against USB-borne propagation, since removable media bypasses network access controls entirely. Disabling USB ports or restricting autorun via Group Policy closes that physical channel, satisfying the stem's requirement to contain malware spreading through removable media.

Why this answer

The malware is spreading via removable media, so disabling USB ports or restricting autorun via Group Policy directly cuts off the propagation vector. Network access controls (NAC) isolate the endpoint from the network, but they do not prevent the malware from copying itself to USB drives or executing via autorun.inf. Group Policy can disable the storage device class (e.g., via 'Removable Storage Access' policies) or disable autorun entirely (via 'Turn off Autoplay' policy), stopping the spread at the physical media level.

Exam trap

The exam often tests the distinction between containment and remediation, and the trap here is that candidates confuse blocking C2 traffic (Option A) with stopping local propagation, failing to recognize that removable media spread is independent of network connectivity.

How to eliminate wrong answers

Option A is wrong because blocking the C2 IP at the firewall only disrupts command-and-control communication, not the local spread via removable media; the malware can still propagate via USB drives without needing network connectivity. Option B is wrong because disabling the user's account and forcing a password reset addresses credential compromise or unauthorized access, but does not stop the malware from copying itself to removable media or autorunning on other systems. Option C is wrong because reimaging the infected system immediately is a remediation step, not a containment step; containment must first stop the spread, and reimaging should only occur after containment is achieved to avoid reinfection or data loss.

Page 5

Page 6 of 13

Page 7