Courseiva

Systems Security Certified Practitioner SSCP (SSCP) — Questions 451–525

971 questions total · 13pages · All types, answers revealed

Page 6

Page 7 of 13

Page 8
451
MCQhard

A security analyst is reviewing logs and sees an alert for a known malware signature on an endpoint. Upon investigation, the file is identified as a false positive. What should the analyst do next?

A.Create an exception in the detection rule.
B.Quarantine the endpoint anyway.
C.Escalate to management.
D.Delete the alert from the SIEM.
AnswerA

A confirmed false positive means the signature is triggering on benign activity, so tuning the detection rule with an exception prevents recurring noise while preserving genuine detection. This addresses the alert's inaccuracy without disabling the control entirely.

Why this answer

Creating an exception in the detection rule is the correct next step because the file has been confirmed as a false positive. This action prevents the security tool from generating future alerts for the same benign file, reducing noise and allowing the analyst to focus on genuine threats. It is a standard whitelisting practice in endpoint detection and response (EDR) or antivirus systems to maintain operational efficiency without compromising security.

Exam trap

The trap here is that candidates may confuse 'false positive' with 'true positive' and choose to quarantine or escalate, failing to recognize that the correct response is to tune the detection rule to eliminate noise.

How to eliminate wrong answers

Option B is wrong because quarantining a known false positive would disrupt legitimate operations and waste resources, as the file is not malicious. Option C is wrong because escalating a confirmed false positive to management is unnecessary and bypasses the analyst's responsibility to handle routine tuning of detection rules. Option D is wrong because deleting the alert from the SIEM removes forensic evidence and audit trails; instead, the alert should be closed with a reason or suppressed via an exception rule.

452
MCQmedium

A security analyst is reviewing Linux server logs after a suspected breach. Which auditing tool should be used to examine detailed records of system calls and file access events?

A.SELinux
B.PAM
C.auditd
D.iptables
AnswerC

auditd hooks into the Linux kernel audit subsystem, recording system calls and file access events with full context. It captures the detailed syscall-level records a breach investigation needs, unlike syslog or application logs, which omit kernel-level activity.

Why this answer

auditd is the Linux userspace auditing daemon that works with the kernel audit subsystem to record system calls, file access, authentication events, and other security-relevant activity. It writes detailed records to /var/log/audit/audit.log and can be queried with ausearch and aureport, making it the correct tool for examining system call and file access events after a suspected breach.

Exam trap

The trap here is confusing access-control or authentication tools (SELinux, PAM) with auditing tools — candidates pick SELinux because it 'logs security events,' but it does not provide syscall-level audit records.

How to eliminate wrong answers

Option A is wrong because SELinux is a mandatory access control framework that enforces policy on processes and files — it can log AVC denials, but it is not an auditing tool for examining detailed system call and file access records. Option B is wrong because PAM (Pluggable Authentication Modules) handles authentication, authorization, and session management; it does not provide system call or file access auditing. Option D is wrong because iptables is a packet-filtering firewall for network traffic, not a host-based auditing tool for system calls or file access.

453
MCQmedium

A security engineer needs to choose an asymmetric algorithm for a system with limited computational resources, such as an IoT device. The algorithm must provide equivalent security to RSA 2048-bit while using smaller key sizes. Which algorithm should they choose?

A.RSA with 2048-bit keys
B.Elliptic Curve Cryptography (ECC) with 256-bit keys
C.Diffie-Hellman with 2048-bit keys
D.3DES with 168-bit keys
AnswerB

ECC achieves equivalent security with far smaller keys because its security rests on the elliptic curve discrete logarithm problem, which resists known sub-exponential attacks. A 256-bit ECC key matches RSA 2048-bit strength, satisfying the IoT constraint of limited computational resources and smaller key sizes.

Why this answer

Elliptic Curve Cryptography (ECC) with 256-bit keys provides equivalent security to RSA 2048-bit because the elliptic curve discrete logarithm problem is significantly harder to solve than the integer factorization problem for the same key length. This allows ECC to achieve strong security with much smaller key sizes, making it ideal for resource-constrained IoT devices where memory, power, and processing are limited.

Exam trap

The SSCP exam often tests the misconception that larger key sizes always mean stronger security, leading candidates to pick RSA 2048-bit or Diffie-Hellman 2048-bit, while the trap is that ECC with much smaller key sizes (e.g., 256-bit) provides equivalent security with lower computational overhead, which is the exact requirement for IoT devices.

How to eliminate wrong answers

Option A is wrong because RSA with 2048-bit keys is the baseline for comparison, not a smaller key size alternative, and it requires significantly more computational resources than ECC for equivalent security. Option C is wrong because Diffie-Hellman with 2048-bit keys is a symmetric-key-agreement protocol that also uses large key sizes for security, not a smaller key size alternative, and it does not provide the same key-size efficiency as ECC. Option D is wrong because 3DES with 168-bit keys is a symmetric encryption algorithm, not an asymmetric algorithm, and it provides only about 112 bits of security, far less than RSA 2048-bit, while also being computationally heavy and deprecated in modern standards.

454
MCQmedium

A company's security policy requires that all logs be stored in a write-once, read-many (WORM) format. What is the primary security objective of this requirement?

A.To maintain log integrity
B.To ensure log availability
C.To improve log review speed
D.To reduce storage costs
AnswerA

WORM storage prevents modification or deletion of existing records, so attackers or rogue insiders cannot alter or erase evidence after intrusion. This preserves the log's evidential value and supports non-repudiation, directly satisfying the policy's objective of maintaining log integrity.

Why this answer

WORM (write-once, read-many) storage prevents any modification or deletion of log data after it is written, directly preserving the integrity of the logs. This ensures that log entries remain an accurate and unaltered record of events, which is critical for forensic investigations, compliance audits, and legal admissibility. The primary security objective is therefore to maintain log integrity, not availability, speed, or cost.

Exam trap

The trap here is confusing integrity with availability or cost, as candidates might think WORM ensures logs are always accessible or saves money, but the core security objective is preventing unauthorized modification.

How to eliminate wrong answers

Option B is wrong because availability focuses on ensuring logs are accessible when needed, whereas WORM specifically prevents alteration, not downtime or access issues. Option C is wrong because WORM storage does not inherently improve review speed; in fact, it can sometimes slow down analysis due to immutability constraints. Option D is wrong because WORM storage typically increases costs by using specialized media or cloud tiers, and cost reduction is not a security objective.

455
MCQhard

A security administrator is drafting a data handling standard for a retail company that processes payment cards. The standard must state how long transaction records may be retained and how they must be destroyed. Which source should PRIMARILY drive these retention and destruction requirements?

A.The storage capacity available in the primary transaction database.
B.The vendor's default configuration settings for the point-of-sale system.
C.Legal, regulatory, and contractual requirements applicable to payment card data.
D.The preferences of the marketing department for customer analytics.
AnswerC

Retention and destruction rules for payment card data flow from laws, industry standards such as the Payment Card Industry Data Security Standard, and contracts with acquiring banks. These obligations define minimum and maximum retention periods and acceptable destruction methods. Basing the standard on them ensures the company can demonstrate compliance and avoid penalties.

Why this answer

Data retention and destruction standards must be anchored in the obligations that apply to the data. For payment card information, those obligations come from laws, the payment card industry standard, and acquiring bank contracts. Operational factors such as storage capacity or analytics desires inform implementation but cannot define the retention period or destruction method.

Exam trap

The trap here is letting a convenient technical or business factor, such as available storage or analytics value, stand in for the legal and contractual obligations that actually govern retention.

456
MCQmedium

A network architect is evaluating a remote access design where users must authenticate with a hardware token and the session must be resistant to replay even if an attacker captures the encrypted traffic. Which protocol property should the architect prioritize?

A.Use of a shared static key for all sessions to simplify key management.
B.Split tunneling so only corporate traffic traverses the encrypted tunnel.
C.Per-session ephemeral keys established through a Diffie-Hellman exchange.
D.Pre-shared key authentication with AES-256 encryption in tunnel mode.
AnswerC

Ephemeral Diffie-Hellman produces a unique session key for each connection, so capturing one session does not reveal past or future keys and replay of old handshake data fails. Combined with the hardware token's one-time values, this provides the forward secrecy and replay resistance the architect needs. This is the property that directly satisfies the requirement.

Why this answer

Replay resistance and forward secrecy depend on fresh, per-session cryptographic material. Ephemeral Diffie-Hellman generates a unique key for each session, so a recorded handshake cannot be replayed against a new session and compromise of one key does not expose others. Static keys and strong bulk encryption alone do not provide these properties, and split tunneling is unrelated to the authentication exchange.

Exam trap

The trap here is equating strong bulk encryption such as AES-256 with replay protection, when replay resistance actually comes from fresh per-session key material and one-time authentication values.

457
Multi-Selecthard

A network security team is implementing a defense-in-depth strategy. Which three layers should be included? (Choose three.)

Select 3 answers
A.Intrusion Detection System (IDS)
B.Firewall
C.Single sign-on (SSO)
D.Physical security controls
E.Anti-malware at endpoints
AnswersA, B, E

An IDS monitors network traffic for malicious activity, providing a detection layer.

Why this answer

An Intrusion Detection System (IDS) is a key layer in defense-in-depth because it monitors network traffic for suspicious activity and known attack signatures, providing visibility and alerting when perimeter defenses like firewalls are bypassed. It operates by analyzing packets against a rule set (e.g., Snort rules) and generating alerts, enabling a response before damage escalates. This adds a detection layer that complements preventive controls, ensuring that even if an attacker penetrates the outer defenses, the breach is identified.

Exam trap

The trap here is that candidates often mistake Single Sign-On (SSO) for a security layer because it involves authentication, but it is an access management convenience tool, not a defensive control that protects against network or endpoint threats.

458
MCQhard

A company's backup strategy uses a full backup on Sundays and differential backups on other days. On Thursday, the storage system fails. How many backups are required to restore the data?

A.One (the full backup only)
B.Five (the full backup and all differentials from Monday to Thursday)
C.Two (the full backup and the Thursday differential)
D.Six (all backups from Sunday to Thursday)
AnswerC

Differential backups capture all changes since the last full backup, so Thursday's differential already contains Monday through Thursday's modifications. Restoration therefore needs only the Sunday full plus that single Thursday differential — two sets — satisfying the stem's recovery requirement without replaying intermediate daily backups.

Why this answer

A differential backup copies all data changed since the last full backup. Therefore, to restore data on Thursday, you need the last full backup (Sunday) and the most recent differential backup (Thursday), which contains all changes from Sunday through Thursday. This totals two backups.

Exam trap

The trap here is confusing differential backups with incremental backups, leading candidates to think they need all backups from Monday to Thursday (Option B) or all backups (Option D), when in fact only the full and the latest differential are required.

How to eliminate wrong answers

Option A is wrong because a full backup alone does not include changes made after Sunday, so data from Monday through Thursday would be lost. Option B is wrong because differential backups are cumulative; you do not need all differentials from Monday to Thursday—only the latest differential (Thursday) contains all changes since the full backup. Option D is wrong because you do not need every backup from Sunday to Thursday; the full backup plus the Thursday differential is sufficient, and including the other differentials is redundant and inefficient.

459
MCQhard

A security operations center (SOC) is investigating a suspected supply chain attack where a trusted software update was modified to include a backdoor. The update was delivered via the vendor's official update server over HTTPS. Which of the following controls, if implemented by the organization, would have BEST prevented the installation of the backdoored update?

A.TLS certificate pinning for the update server connection.
B.Network segmentation between the update server and critical systems.
C.Code signing verification of the update package before installation.
D.Endpoint detection and response (EDR) with behavioral monitoring.
AnswerC

Code signing verification checks that the update package was signed by the vendor's private key and has not been altered. If the attacker modified the update, the signature would not match, and the installation would be blocked. This directly prevents the backdoored update from being installed, assuming the vendor's private key was not compromised. It is the most effective control for this scenario.

Why this answer

Code signing verification is the key control to ensure the integrity and authenticity of software updates. If the update was modified after signing, the signature check fails, and the installation is blocked. Other controls like network segmentation or TLS pinning do not protect against a compromised update server or a malicious insider at the vendor.

Exam trap

The trap here is assuming that HTTPS and TLS pinning guarantee the integrity of the update content, when they only secure the transport, not the package itself.

460
MCQhard

An organization uses attribute-based access control (ABAC) for its cloud storage. The policy states that a user can read a document only if the user’s department attribute matches the document’s department attribute AND the current time is within business hours (9AM-5PM). A user from Engineering tries to read a document classified for Engineering at 8:55 AM. What is the expected result?

A.Access granted because the department matches
B.Access denied because the department does not match
C.Access granted because the user is in Engineering
D.Access denied because the time is outside business hours
AnswerD

ABAC evaluates all policy attributes conjunctively, so both the department match and the time condition must hold. Engineering matches the document, but 8:55 AM falls before the 9AM business-hours window, so the time constraint fails and access is denied.

Why this answer

The ABAC policy requires both conditions to be true: department match AND time within business hours (9AM-5PM). At 8:55 AM, the time condition is false, so access is denied regardless of the department match. This is a classic example of a conjunctive (AND) policy in ABAC where all attributes must satisfy the rules.

Exam trap

The trap here is that candidates focus on the department match and overlook the conjunctive AND logic, assuming a single matching attribute is sufficient for access.

How to eliminate wrong answers

Option A is wrong because it ignores the time condition; ABAC policies with AND require all attributes to match, not just one. Option B is wrong because the department does match (both Engineering), but the denial is due to time, not department mismatch. Option C is wrong because being in Engineering alone does not satisfy the policy; the time attribute must also be within business hours.

461
MCQmedium

Which of the following is the PRIMARY purpose of establishing a chain of custody when handling digital evidence?

A.To determine the priority of the incident
B.To ensure that evidence is stored in a secure location
C.To prove that evidence has not been altered or tampered with from collection to presentation
D.To identify which forensic tools were used during analysis
AnswerC

A documented chain of custody records every transfer, handler and storage condition from seizure to courtroom, creating an auditable trail that demonstrates the evidence's integrity remained intact. This directly satisfies the stem's demand for the primary purpose: proving the data was neither altered nor tampered with between collection and presentation.

Why this answer

The primary purpose of chain of custody is to create a documented, unbroken record of every person who handled the evidence, from collection through presentation in court. This documentation is critical to demonstrate that the digital evidence has not been altered, tampered with, or corrupted, thereby preserving its integrity and admissibility. Without a proper chain of custody, the opposing party can successfully challenge the evidence as unreliable or compromised.

Exam trap

The trap here is that candidates often confuse the purpose of chain of custody with the purpose of secure storage (Option B), but the exam specifically tests that the primary goal is proving evidence integrity through an unbroken record of custody, not just physical security.

How to eliminate wrong answers

Option A is wrong because establishing chain of custody has nothing to do with determining incident priority; priority is based on impact, criticality, and business risk, not evidence handling. Option B is wrong because while secure storage is an important part of evidence preservation, it is only one component of the chain of custody process, not the primary purpose; the core goal is proving integrity through documentation of every transfer and access event. Option D is wrong because identifying forensic tools used during analysis is a matter of methodology documentation, not chain of custody; chain of custody focuses on who had possession and when, not which software was employed.

462
MCQeasy

A company wants to prevent unauthorized applications from running on employee workstations. Which of the following is the most effective control?

A.User training
B.Regular antivirus updates
C.Host-based intrusion detection system
D.Application whitelisting
AnswerD

Application whitelisting enforces a default-deny model: only explicitly approved executables are permitted to run, blocking all other software regardless of origin. This directly satisfies the requirement to prevent unauthorised applications, unlike blacklisting, which only blocks known-bad programs and misses new or renamed threats.

Why this answer

Application whitelisting (also called application allowlisting) is the most effective control because it enforces a default-deny posture: only explicitly approved executables are permitted to run, blocking all unauthorized applications regardless of whether they are known malware. This directly prevents unauthorized applications from executing at the endpoint, which is the stated goal. Unlike detective or educational controls, it is a preventive technical control enforced by the OS or an agent.

Exam trap

The trap here is confusing preventive controls (whitelisting) with detective controls (HIDS) or administrative controls (training), causing candidates to pick a control that only detects or discourages rather than blocks unauthorized applications.

How to eliminate wrong answers

Option A is wrong because user training is an administrative awareness control that relies on human compliance and cannot technically prevent a user or malware from launching an unauthorized application. Option B is wrong because antivirus updates only improve detection of known malicious signatures or behaviors; they do not stop legitimate-but-unauthorized applications (e.g., unapproved productivity tools, cryptominers) from running. Option C is wrong because a host-based IDS is a detective control that logs or alerts on suspicious activity after it occurs, rather than blocking execution of unauthorized applications.

463
MCQmedium

A hospital is deploying a new electronic health records (EHR) system. The security team wants to ensure that access decisions are based on the user's assigned job function rather than on the user's identity or resource ownership. Which access control model best meets this requirement?

A.Discretionary Access Control (DAC)
B.Mandatory Access Control (MAC)
C.Role-Based Access Control (RBAC)
D.Rule-Based Access Control
AnswerC

RBAC assigns permissions to roles, and users are assigned to roles based on their job functions. In the hospital scenario, this means access to EHR functions is determined by the user's role (e.g., physician, nurse, billing clerk), not by individual identity or ownership. This aligns exactly with the requirement that access decisions be based on job function.

Why this answer

Role-Based Access Control (RBAC) is designed to assign permissions to roles, and users are then assigned to roles according to their job responsibilities. This directly satisfies the hospital's requirement that access be based on job function rather than individual identity or resource ownership. The other models either rely on ownership, labels, or global rules, which do not meet the stated need.

Exam trap

The trap here is confusing role-based access with rule-based access, assuming that any rule or policy that references job functions qualifies as RBAC.

464
MCQmedium

A company's disaster recovery plan includes offsite tape backups. During a test, it is discovered that the tapes are stored at a location that shares the same power grid as the primary site. Which risk does this pose?

A.The tapes may degrade over time
B.The tapes may be inaccessible during a power outage
C.The tapes are not encrypted
D.The recovery time may exceed the RTO
AnswerB

Sharing a power grid means a single outage can disable both the primary site and the tape storage location simultaneously. The backups survive physically but cannot be retrieved, defeating the offsite recovery objective during a regional power failure.

Why this answer

If the offsite tape storage shares the same power grid as the primary site, a regional power outage could simultaneously take down both the primary site and the tape storage facility, making the tapes physically inaccessible when they're needed for recovery. This defeats the geographic separation principle of disaster recovery, where the offsite location must be independent of the primary site's infrastructure and utility dependencies.

Exam trap

SSCP often tests whether candidates confuse availability risks (shared power grid, single point of failure) with confidentiality (encryption) or performance (RTO) risks — the key is matching the scenario's specific failure mode to the correct risk category.

How to eliminate wrong answers

Option A is wrong because tape degradation is a media lifecycle concern (typically 10-30 years for LTO) unrelated to power grid sharing. Option C is wrong because encryption is a confidentiality control and the scenario says nothing about encryption status — it's a distractor. Option D is wrong because RTO concerns recovery speed, not the physical accessibility of tapes during a shared-grid outage; the scenario describes an availability risk, not a timing risk.

465
MCQmedium

An organization uses a network-based intrusion detection system (NIDS). An analyst receives an alert for a known exploit signature. Which type of detection is the NIDS using?

A.Anomaly-based detection
B.Behavior-based detection
C.Signature-based detection
D.Heuristic detection
AnswerC

The alert fired because traffic matched a stored pattern of a known exploit, which is precisely how signature-based detection works: it compares activity against a database of predefined attack signatures rather than profiling normal behaviour or anomalies.

Why this answer

The NIDS generated an alert based on a known exploit signature, which means it compared network traffic against a database of predefined patterns or fingerprints of known attacks. This is the defining characteristic of signature-based detection, where the system relies on exact or pattern matches to known malicious activity.

Exam trap

The trap here is that candidates confuse 'signature-based' with 'heuristic' detection, because both involve pattern matching, but heuristic detection uses fuzzy logic or statistical models rather than exact known signatures.

How to eliminate wrong answers

Option A is wrong because anomaly-based detection establishes a baseline of normal network behavior and flags deviations from that baseline, not known exploit signatures. Option B is wrong because behavior-based detection analyzes patterns of activity over time to identify suspicious behavior, such as unusual data exfiltration rates, rather than matching static signatures. Option D is wrong because heuristic detection uses algorithms or rules to infer malicious intent based on generalized characteristics or statistical analysis, not a direct match to a known exploit signature.

466
MCQmedium

An organization wants to ensure that privileged accounts are used only when needed and that all activities are recorded. Which Privileged Access Management (PAM) control should be implemented?

A.Password vaulting
B.Role-based access control
C.Multi-factor authentication
D.Just-in-Time (JIT) provisioning with session recording
AnswerD

Just-in-Time provisioning grants privileged rights only for the required window, then revokes them, satisfying the 'only when needed' constraint. Session recording captures all privileged activity for audit, meeting the recording requirement. Standing admin rights would fail both conditions.

Why this answer

Just-in-Time (JIT) provisioning grants privileged access only when needed and for a limited time, and session recording captures all activities for audit. Together, they directly satisfy the requirement that privileged accounts are used only when needed and all activities are recorded. JIT eliminates standing privileges, reducing the attack surface, while session recording provides non-repudiation and forensic evidence.

Exam trap

SSCP often tests the confusion between authentication controls (MFA), authorization models (RBAC), and PAM-specific controls (JIT + session recording) — candidates pick MFA or RBAC because they sound security-relevant but miss the 'only when needed' and 'recorded' requirements.

How to eliminate wrong answers

Option A is wrong because password vaulting stores and rotates privileged credentials but does not by itself enforce time-bound access or record sessions — it is a component of PAM, not the complete control described. Option B is wrong because role-based access control (RBAC) assigns permissions based on roles but does not provide just-in-time elevation or session recording; it is a static authorization model. Option C is wrong because multi-factor authentication strengthens authentication but does not limit when privileged accounts are used or record what is done with them.

467
Multi-Selectmedium

A security administrator is implementing a data loss prevention strategy for a company that handles credit card data. The administrator must ensure the organization meets PCI DSS requirements for protecting stored cardholder data. Which TWO practices should the administrator implement? (Choose two.)

Select 2 answers
A.Encrypt cardholder data with a strong algorithm and manage cryptographic keys using documented key management procedures.
B.Transmit cardholder data over public networks using a proprietary encryption scheme that is not reviewed by independent experts.
C.Retain all cardholder data indefinitely to support future fraud investigations.
D.Render the primary account number unreadable anywhere it is stored using strong cryptography.
E.Store the full magnetic stripe data in a central repository for backup and reconciliation purposes.
AnswersA, D

PCI DSS requires strong cryptography and secure key management for stored cardholder data. Keys must be protected against disclosure and misuse, with documented processes for generation, distribution, storage, rotation, and destruction. Encryption alone without proper key management is ineffective, so implementing both encryption and formal key management procedures is a required practice for protecting stored cardholder data.

Why this answer

PCI DSS requires that stored cardholder data be protected through rendering the primary account number unreadable and through strong cryptography with proper key management. These two practices reduce the likelihood and impact of unauthorized disclosure. Retaining full track data, keeping data indefinitely, or relying on proprietary encryption all violate PCI DSS requirements or accepted security practice for cardholder data protection.

Exam trap

The trap here is selecting data retention or transmission controls when the scenario specifically asks about protecting stored cardholder data.

468
MCQhard

A company uses Infrastructure as a Service (IaaS) for its production workloads. According to the shared responsibility model, which of the following security tasks is the customer responsible for?

A.Patching the hypervisor
B.Physical security of data centers
C.Securing the network infrastructure
D.Patching the guest operating system
AnswerD

Patching the guest operating system falls to the customer under IaaS, since the provider manages only the hypervisor, physical hosts and network fabric. The customer retains control of everything from the guest OS upward, satisfying the stem's shared responsibility constraint.

Why this answer

In the IaaS shared responsibility model, the customer is responsible for securing the guest operating system, including patching, because the cloud provider manages the hypervisor and physical infrastructure. The customer controls the OS and applications running on the IaaS instances.

Exam trap

The trap is mixing up responsibilities: candidates often think the provider patches the guest OS in IaaS, but the exam tests that the customer owns guest OS patching.

How to eliminate wrong answers

Option A is wrong because patching the hypervisor is the cloud provider's responsibility in IaaS. Option B is wrong because physical security of data centers is always the provider's responsibility. Option C is wrong because securing the network infrastructure (e.g., physical routers, switches) is managed by the provider, although the customer may be responsible for virtual network security.

469
MCQeasy

Which of the following is the primary purpose of a security awareness program?

A.To teach employees about security best practices and reduce human error.
B.To evaluate the effectiveness of security technologies.
C.To enforce security policies through penalties.
D.To train employees on advanced technical security skills.
AnswerA

Awareness programmes target the human element by educating staff on phishing, password hygiene and data handling, thereby reducing accidental breaches. This directly satisfies the stem's focus on the primary purpose, which is shaping behaviour and lowering human error rather than implementing technical controls.

Why this answer

The primary purpose of a security awareness program is to educate employees on security best practices and reduce human error, which is the leading cause of security incidents. Unlike technical controls, awareness programs target the human element by teaching users to recognize phishing attempts, handle sensitive data properly, and follow secure behaviors. This aligns with the NIST SP 800-50 framework, which defines awareness as a foundational component of an organizational security posture.

Exam trap

ISC2 often tests the distinction between 'awareness' (general, non-technical education for all users) and 'training' (in-depth, role-specific technical instruction), so candidates mistakenly choose D when they confuse the scope of awareness programs with advanced technical training.

How to eliminate wrong answers

Option B is wrong because evaluating the effectiveness of security technologies is the purpose of security testing and assessment (e.g., vulnerability scanning, penetration testing), not a security awareness program. Option C is wrong because enforcing security policies through penalties is a function of policy enforcement and disciplinary procedures, not the primary goal of awareness, which is education and behavior change. Option D is wrong because training employees on advanced technical security skills is the domain of specialized technical training (e.g., for IT staff), whereas awareness programs target all employees with general, non-technical knowledge.

470
MCQhard

An organization uses VMware ESXi in a production environment. Which of the following is the most effective mitigation against VM escape attacks?

A.Using VM snapshots for quick recovery
B.Implementing network segmentation between VMs
C.Regularly patching the ESXi hypervisor
D.Disabling unnecessary guest tools within VMs
AnswerC

Patching the ESXi hypervisor closes the vulnerabilities that VM escape exploits target, directly satisfying the stem's mitigation requirement. Because escape attacks break the isolation boundary between guest and host, keeping the hypervisor current is more effective than guest-level controls, which cannot protect the host.

Why this answer

VM escape exploits a vulnerability in the hypervisor that lets a guest VM break out and access the host or other VMs. Regularly patching ESXi closes known hypervisor vulnerabilities (e.g., those disclosed in VMware security advisories) before attackers can exploit them, making it the most effective mitigation. Patching directly addresses the root cause — the hypervisor flaw — rather than the symptoms.

Exam trap

The trap is choosing a compensating or detective control (segmentation, snapshots) when the question asks for the most effective mitigation — candidates overlook that only patching removes the hypervisor vulnerability itself.

How to eliminate wrong answers

Option A is wrong because snapshots are a recovery mechanism, not a preventive control — they help you restore after a compromise but do nothing to stop a VM escape. Option B is wrong because network segmentation between VMs limits lateral movement after an escape but does not prevent the escape itself, which occurs at the hypervisor layer. Option D is wrong because disabling unnecessary guest tools reduces the guest attack surface but does not address hypervisor vulnerabilities that enable escape.

471
MCQhard

An analyst is comparing symmetric and asymmetric encryption. Which statement accurately describes a typical use case?

A.Symmetric encryption is used for key exchange over insecure channels.
B.Asymmetric encryption is used to securely exchange a symmetric key.
C.Symmetric encryption is used to sign documents to provide non-repudiation.
D.Asymmetric encryption is used for bulk data encryption because it is faster.
AnswerB

Asymmetric encryption, using public and private key pairs, is slower but solves key distribution; it typically encrypts a randomly generated symmetric session key, which then protects bulk data. This hybrid approach combines asymmetric key exchange with symmetric throughput.

Why this answer

Asymmetric encryption (e.g., RSA, ECDH) is computationally expensive and slow, making it unsuitable for bulk data encryption. Instead, it is commonly used to securely exchange a symmetric session key (e.g., an AES key) over an insecure channel. Once both parties have the symmetric key, they can switch to symmetric encryption (e.g., AES-GCM) for efficient bulk data encryption.

This hybrid approach combines the secure key distribution of asymmetric encryption with the speed of symmetric encryption.

Exam trap

A common pitfall in this context is the misconception that symmetric encryption is used for key exchange or that asymmetric encryption is faster for bulk data. In reality, asymmetric encryption is slow and reserved for secure key exchange, while symmetric encryption is fast and used for bulk data encryption.

How to eliminate wrong answers

Option A is wrong because symmetric encryption uses a single shared key and cannot securely exchange that key over an insecure channel without a pre-existing secure method; key exchange is a primary use case for asymmetric encryption (e.g., Diffie-Hellman, RSA key transport). Option C is wrong because symmetric encryption does not provide non-repudiation; digital signatures, which use asymmetric encryption (e.g., RSA or ECDSA with a private key), are required to provide non-repudiation by binding the signer's identity to the document. Option D is wrong because asymmetric encryption is significantly slower than symmetric encryption (e.g., RSA is hundreds to thousands of times slower than AES for equivalent security levels) and is therefore not used for bulk data encryption; symmetric encryption (e.g., AES-256) is the standard for encrypting large volumes of data.

472
Multi-Selecthard

Which TWO are security implications of using deprecated cryptographic protocols such as SSL 3.0 and TLS 1.0?

Select 2 answers
A.Susceptibility to downgrade attacks
B.Increased computational overhead
C.Compliance with regulations
D.Weak key exchange
E.Interoperability issues with modern systems
AnswersA, D

SSL 3.0 and TLS 1.0 permit fallback negotiation to weaker cipher suites and protocol versions. An attacker can force a session down to the deprecated protocol, exploiting its known weaknesses. This downgrade susceptibility is the direct security implication of retaining these obsolete protocols.

Why this answer

Option A is correct because deprecated protocols like SSL 3.0 and TLS 1.0 lack protections against version rollback, allowing an attacker to force a client and server to negotiate a weaker protocol or cipher suite—classic downgrade attacks such as POODLE against SSL 3.0. Option D is correct because these older protocols rely on weak key exchange mechanisms, including RSA key transport without forward secrecy and export-grade Diffie-Hellman parameters, which can expose session keys if long-term private keys are compromised. The remaining options do not describe security implications: increased computational overhead (B) is a performance concern, compliance with regulations (C) is a governance benefit rather than a risk, and interoperability issues with modern systems (E) is a compatibility problem, not a security vulnerability.

Exam trap

ISC2 often tests the misconception that deprecated protocols are 'still secure enough' or that their only downside is performance overhead, but the real trap is that candidates confuse 'interoperability issues' (which are a practical concern) with 'security implications' (which are the core focus of the question).

473
MCQeasy

A company uses digital signatures to ensure the integrity and non-repudiation of internal contracts. The private key used for signing is stored in a hardware security module (HSM). A junior administrator asks why the HSM is necessary. What is the primary reason?

A.It reduces network latency during signing.
B.It enables symmetric key exchange for large files.
C.It allows the signing process to be faster.
D.It provides non-repudiation by protecting the private key.
AnswerD

An HSM protects the private key by keeping it non-exportable and performing signing operations internally, so the key never exists in plaintext memory. This satisfies the stem's non-repudiation requirement: only the key holder could have produced the signature, and compromise of the host cannot forge it.

Why this answer

The primary reason for using an HSM is to protect the private key from unauthorized access or extraction. Non-repudiation relies on the assurance that only the legitimate signer could have used the private key; if the key is compromised, that assurance is lost. The HSM provides a tamper-resistant environment that performs signing operations internally, ensuring the private key never leaves the secure hardware.

Exam trap

The trap here is that candidates may think an HSM is used for performance or key exchange, but the SSCP exam emphasizes that its core purpose is to safeguard the private key to maintain non-repudiation and integrity.

How to eliminate wrong answers

Option A is wrong because an HSM does not reduce network latency; in fact, it may add slight latency due to hardware communication overhead. Option B is wrong because HSMs are used for asymmetric key operations (signing/encryption), not symmetric key exchange; symmetric keys are typically exchanged using asymmetric methods like Diffie-Hellman or RSA. Option C is wrong because HSMs are not primarily designed for speed; software-based signing can be faster, but HSMs prioritize security over raw performance.

474
MCQmedium

After a security incident, the CSIRT is conducting lessons learned. Which output is most directly used to update the risk management process?

A.Updated incident response plan.
B.Risk register updates.
C.Corrective actions.
D.Forensic report.
AnswerB

Risk register updates capture the incident's identified vulnerabilities, likelihood and impact changes, feeding directly into the risk management process. This satisfies the stem's requirement for the most direct output, since the register is the formal artefact through which lessons learned alter documented risk treatment decisions.

Why this answer

The risk management process is directly updated by incorporating new risk information derived from incident analysis. Risk register updates (option B) capture newly identified risks, changes in risk likelihood or impact, and the effectiveness of existing controls, which are the primary outputs that feed back into risk treatment decisions.

Exam trap

The trap here is that candidates confuse operational outputs (corrective actions, updated IR plans) with the formal risk management artifact (risk register) that directly influences risk acceptance, mitigation, or transfer decisions.

How to eliminate wrong answers

Option A is wrong because updating the incident response plan is a corrective action to improve future response, not a direct input to the risk management process; the plan itself does not modify risk registers or risk assessments. Option C is wrong because corrective actions address specific incident root causes and may reduce risk, but they are operational fixes, not the formal risk documentation updates that directly feed the risk management process. Option D is wrong because a forensic report documents evidence and findings for legal or investigative purposes, but it does not directly update risk registers or risk treatment plans unless its findings are abstracted into risk entries.

475
MCQmedium

A mobile device management (MDM) administrator at a healthcare company needs to ensure that a physician's personally owned smartphone can access patient records through the corporate email application, but the administrator must be able to remotely erase only the corporate email data and its encryption keys if the device is lost, without deleting the physician's personal photos and apps. Which MDM capability should the administrator configure?

A.Enable selective wipe, also called enterprise wipe, which removes only corporate email data and associated keys.
B.Configure a full-device remote wipe that removes all data after a predefined number of failed unlock attempts.
C.Enroll the device in a mobile application management (MAM) policy that blocks copy and paste between apps.
D.Apply a device-level passcode policy that requires a six-digit PIN and disables the camera application.
AnswerA

Selective wipe, or enterprise wipe, is designed for BYOD scenarios where the organization manages only the corporate container. It removes corporate email, attachments, and the encryption keys protecting that data while leaving personal photos and apps intact. This satisfies the requirement to remotely erase only corporate data if the device is lost.

Why this answer

Selective wipe, also known as enterprise wipe, is the MDM feature that removes only corporate data and its encryption keys from a personally owned device. It preserves the user's personal content, making it the correct choice for BYOD scenarios. Full-device wipe, passcode policies, and copy-paste restrictions do not provide the required granular remote erasure of corporate email data.

Exam trap

The trap here is assuming that any remote wipe capability erases only corporate data, when a full-device wipe destroys personal content as well.

476
MCQmedium

What is the primary risk associated with service accounts in an enterprise?

A.They are used by multiple users simultaneously
B.They are difficult to create
C.They often have excessive privileges and infrequent password changes
D.They are always tied to a specific user
AnswerC

Service accounts typically hold broad, long-lived credentials because they run automated processes, and their passwords are rarely rotated. This combination satisfies the stem's constraint: excessive privileges paired with infrequent password changes creates a prime target for lateral movement and credential abuse.

Why this answer

Service accounts are non-human accounts used by applications, daemons, or scheduled tasks to run processes and access resources. Because they must operate without interactive logon, they are frequently granted broad privileges (e.g., domain admin, local system) to ensure the service functions correctly. Additionally, their passwords are often set once and never rotated, or are hard-coded in scripts, making them a prime target for credential theft and lateral movement.

Thus, the primary risk is the combination of excessive privileges and infrequent password changes.

Exam trap

SSCP often tests the misconception that service accounts are secure because they are not used by humans, but the real risk is their excessive privileges and static credentials, which candidates may overlook in favor of less critical issues like shared use or difficulty of creation.

How to eliminate wrong answers

Option A is wrong because service accounts are typically designed for a single service or application, not for simultaneous use by multiple users; shared use is a characteristic of generic user accounts, not service accounts. Option B is wrong because creating a service account is generally straightforward—it involves provisioning a standard user account with specific rights—and difficulty is not a security risk. Option D is wrong because service accounts are explicitly not tied to a specific user; they are independent identities, and this independence is what allows them to run without human interaction, not a risk in itself.

477
MCQhard

Which attack exploits the lack of IV (Initialization Vector) randomness in the RC4 algorithm to recover the Wi-Fi password, and is considered completely broken?

A.WEP IV attack
B.PMKID attack
C.Evil twin attack
D.KRACK attack
AnswerA

WEP's RC4 implementation uses a short, non-random 24-bit IV, and its reuse enables the FMS and PTW statistical attacks to recover the keystream and derive the WEP key. This directly exploits the absent IV randomness named in the stem, making WEP completely broken.

Why this answer

The WEP IV attack exploits WEP's 24-bit IV, which is too short and reused frequently, allowing an attacker to collect enough packets to recover the RC4 keystream and derive the WEP key. WEP is considered completely broken and deprecated, and this attack (often implemented via tools like Aircrack-ng) is the classic demonstration of its weakness.

Exam trap

SSCP often tests the distinction between WEP IV attacks (RC4/IV reuse), PMKID (WPA2 handshake capture), and KRACK (WPA2 key reinstallation) — candidates confuse the underlying cryptographic flaw with the attack name.

How to eliminate wrong answers

Option B is wrong because the PMKID attack targets WPA/WPA2-PSK by capturing the PMKID from the RSN IE during association, not RC4 IV weaknesses in WEP. Option C is wrong because an evil twin attack is a rogue AP impersonating a legitimate one to lure clients, unrelated to RC4 IV randomness. Option D is wrong because KRACK (Key Reinstallation Attack) exploits the WPA2 4-way handshake by replaying message 3 to reinstall an already-in-use key, not RC4 IV reuse.

478
MCQmedium

An organization's incident response team has just completed the recovery phase of a major security incident. The team lead is now planning the post-incident activity. According to NIST SP 800-61, which of the following should be the PRIMARY focus of the lessons learned meeting?

A.Identifying improvements to the incident response plan and procedures based on what worked and what did not.
B.Updating the organization's disaster recovery plan to reflect the new threat landscape.
C.Calculating the total financial cost of the incident to report to stakeholders.
D.Determining which team members should be disciplined for mistakes made during the response.
AnswerA

The lessons learned meeting is intended to review the incident and the response to identify strengths and weaknesses, leading to improvements in the incident response plan, procedures, and training. This helps the organization better prepare for future incidents. The primary focus is on process improvement, not on assigning blame or calculating costs. NIST SP 800-61 emphasizes that the meeting should produce actionable recommendations.

Why this answer

The primary focus of a lessons learned meeting after an incident is to review the response efforts and identify improvements to the incident response plan, procedures, and training. This aligns with NIST SP 800-61, which emphasizes that the meeting should produce actionable recommendations to enhance future response. It is not about discipline, financial reporting, or solely updating disaster recovery plans.

The goal is continuous improvement of the incident response capability.

Exam trap

The trap here is confusing the lessons learned meeting with a disciplinary or financial review, when its core purpose is to improve incident response processes through constructive analysis.

479
Multi-Selectmedium

A security engineer is hardening a Linux server. Which TWO actions are recommended to reduce the attack surface? (Select TWO.)

Select 2 answers
A.Remove unnecessary services and daemons
B.Disable unused user accounts
C.Install a web server for management
D.Set umask to 000
E.Enable IPv6 routing
AnswersA, B

Removing unnecessary services and daemons eliminates listening ports and executable code that attackers could exploit, directly shrinking the server's attack surface. This satisfies the hardening constraint by reducing the number of potential entry points requiring patching and monitoring.

Why this answer

Option A is correct because removing unnecessary services and daemons eliminates listening ports, binaries, and potential vulnerabilities that attackers could exploit, directly shrinking the attack surface. Option B is correct because disabling unused user accounts removes dormant credentials and login paths that could be abused for unauthorized access or privilege escalation. Option C is wrong because installing a web server for management adds a new network-facing service and increases, rather than reduces, the attack surface.

Option D is wrong because setting umask to 000 makes newly created files world-readable and world-writable, weakening permissions instead of hardening them. Option E is wrong because enabling IPv6 routing adds network functionality and exposure that is unnecessary on a hardened server and can introduce additional attack vectors.

Exam trap

The trap is that some options sound like security measures (installing a management web server, enabling IPv6) but actually expand the attack surface—candidates must distinguish between adding functionality and reducing exposure.

480
MCQmedium

Based on the exhibit, which security threat is likely being attempted?

A.DNS poisoning
B.Man-in-the-middle attack
C.Brute-force attack
D.SQL injection
AnswerC

Repeated authentication attempts against one account, as shown in the exhibit, indicate a brute-force attack: systematic credential guessing rather than exploitation of a software flaw. This matches the stem's exhibited pattern of many failed logons from a single source.

Why this answer

The exhibit shows a large number of failed login attempts (e.g., 'Login failed' or 'Authentication error') from a single source IP within a short time window, which is the classic signature of a brute-force attack. This attack systematically tries multiple username/password combinations to gain unauthorized access, and the repeated failure messages in the logs confirm the attempt.

Exam trap

ISC2 often tests the distinction between brute-force attacks and other threats by embedding subtle clues like 'multiple failed logins' in logs, which candidates may misinterpret as a man-in-the-middle attack due to the presence of authentication errors, but the key is the volume and repetition of failures.

How to eliminate wrong answers

Option A is wrong because DNS poisoning involves corrupting DNS resolver caches with false IP mappings, which would show DNS query anomalies or spoofed responses, not repeated login failures. Option B is wrong because a man-in-the-middle attack intercepts and potentially alters communications between two parties, typically indicated by ARP spoofing, SSL certificate mismatches, or unusual traffic patterns, not a flood of authentication failures. Option D is wrong because SQL injection exploits input validation flaws to execute arbitrary SQL commands, which would manifest as database error messages or unexpected query results, not repeated login attempts.

481
Multi-Selectmedium

Which TWO of the following are symmetric encryption algorithms? (Select exactly two.)

Select 2 answers
A.DES
B.AES
C.RSA
D.ECC
E.SHA-256
AnswersA, B

DES is a symmetric block cipher using a single 56-bit key for both encryption and decryption on 64-bit blocks. It satisfies the shared-secret-key criterion, though its short key length makes it obsolete for modern use.

Why this answer

DES (Data Encryption Standard) is a symmetric encryption algorithm that uses a single key for both encryption and decryption. It operates on 64-bit blocks with a 56-bit key, and while now considered insecure due to its small key size, it remains a foundational symmetric cipher. AES (Advanced Encryption Standard) is also symmetric, using block sizes of 128 bits and key sizes of 128, 192, or 256 bits, and is the current standard for symmetric encryption.

Exam trap

ISC2 often tests the distinction between symmetric and asymmetric algorithms, and the trap here is that candidates may confuse RSA or ECC (both asymmetric) with symmetric ciphers, or mistakenly think SHA-256 is an encryption algorithm because it is used in security contexts.

482
MCQmedium

A security analyst is reviewing logs from a SIEM and notices multiple failed login attempts for a privileged account from an IP address in a foreign country, followed by a successful login after hours. Which type of security monitoring tool would be most effective at detecting this pattern as anomalous behavior based on user baseline?

A.Signature-based IDS
B.Network-based IPS
C.Host-based IDS
D.User Behavior Analytics (UBA)
AnswerD

User Behaviour Analytics builds baselines of normal activity per account and flags deviations, so the foreign-IP, after-hours privileged login pattern stands out as anomalous. Signature or rule-based tools would miss this because no known attack signature matches.

Why this answer

User Behavior Analytics (UBA) is designed to establish a baseline of normal user activity and detect anomalies such as a privileged account logging in from an unusual geographic location after hours. Unlike signature or rule-based tools, UBA uses statistical modeling and machine learning to identify deviations from the user's historical patterns, making it ideal for detecting this type of credential misuse.

Exam trap

The trap here is that candidates often confuse anomaly detection with signature-based detection, assuming that a failed login followed by a success is a known brute-force pattern that a signature-based IDS would catch, but the question specifically asks for detection based on a user baseline, which is the core function of UBA, not signature matching.

How to eliminate wrong answers

Option A is wrong because a signature-based IDS relies on predefined patterns (e.g., known attack signatures) and cannot detect novel or anomalous behavior like a login from an unusual IP unless a specific signature exists for that scenario. Option B is wrong because a network-based IPS focuses on blocking malicious traffic at the network layer (e.g., exploiting vulnerabilities) and does not analyze user login patterns or establish behavioral baselines. Option C is wrong because a host-based IDS monitors system-level events (e.g., file changes, process execution) on a single host but lacks the cross-session, user-centric analytics needed to compare a login event against historical user behavior.

483
MCQmedium

A security team discovers that a legacy system uses ECB mode to encrypt credit card numbers. What is the primary security concern with this mode?

A.Identical plaintext blocks produce identical ciphertext, revealing patterns
B.It is slow compared to other modes
C.It is vulnerable to padding oracle attacks
D.It does not provide integrity
AnswerA

ECB encrypts each 64-bit block independently with the same key, so identical plaintext blocks always yield identical ciphertext blocks. In structured data such as credit card numbers, this preserves patterns and repetitions, enabling an attacker to infer or reconstruct plaintext without breaking the cipher.

Why this answer

ECB (Electronic Codebook) mode encrypts each plaintext block independently using the same key. This means identical plaintext blocks produce identical ciphertext blocks, which allows an attacker to detect patterns, data boundaries, and repetitions in the encrypted data. For credit card numbers, which often have predictable formats (e.g., BIN ranges, fixed lengths), this pattern leakage can reveal sensitive information without breaking the encryption key.

Exam trap

The trap here is that candidates often confuse ECB's lack of diffusion with performance issues or integrity flaws, but The SSCP exam specifically tests whether you recognize that ECB's deterministic block mapping is its fundamental weakness, not speed or padding vulnerabilities.

How to eliminate wrong answers

Option B is wrong because ECB is actually one of the fastest modes—it processes blocks in parallel with no chaining overhead, so slowness is not a valid concern. Option C is wrong because padding oracle attacks exploit CBC mode (or other modes using PKCS#7 padding), not ECB; ECB does not use an initialization vector or chaining, so padding oracle attacks are not applicable. Option D is wrong because ECB does not inherently provide integrity, but that is not its primary security concern—the core issue is pattern leakage from deterministic encryption; integrity is a separate property typically addressed by MACs or authenticated encryption modes like GCM.

484
MCQhard

During an audit, it is discovered that a contractor’s account has read access to a financial database even though the contractor’s project ended six months ago. Which type of access control failure is this?

A.Inadequate authorization
B.Insufficient authentication
C.Weak password policy
D.Poor account management
AnswerD

Access persisting six months after the contractor's project ended indicates the account was never disabled or removed, which is poor account management rather than a permissions-design flaw. This satisfies the stem's constraint of stale contractor access, reflecting failed lifecycle processes for provisioning, review and timely deprovisioning.

Why this answer

The contractor's account retained access privileges after the project ended, which is a failure of the account lifecycle management process. Proper account management requires disabling or removing accounts when a user's role or affiliation changes, such as when a contract terminates. This is not an authorization or authentication issue, as the access was originally granted correctly but was not revoked in a timely manner.

Exam trap

The trap here is that candidates confuse 'inadequate authorization' (which is about granting excessive permissions) with 'poor account management' (which is about failing to revoke access when it is no longer needed), even though the original authorization was correct.

How to eliminate wrong answers

Option A is wrong because inadequate authorization refers to granting permissions that are too broad or inappropriate for a role, whereas here the access was appropriate during the project but not revoked afterward. Option B is wrong because insufficient authentication deals with verifying identity (e.g., weak MFA or passwordless login), not with the ongoing validity of an account after its purpose ends. Option C is wrong because a weak password policy concerns password complexity, length, or rotation rules, not the failure to deprovision an account after a project concludes.

485
MCQhard

A security engineer is configuring a TLS 1.3 server for an e-commerce site. The engineer wants to ensure that the cipher suite provides both confidentiality and integrity for application data. Which of the following cipher suites should the engineer select?

A.TLS_RSA_WITH_3DES_EDE_CBC_SHA
B.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
C.TLS_AES_128_GCM_SHA256
D.TLS_AES_256_CBC_SHA384
AnswerC

TLS_AES_128_GCM_SHA256 uses AES-128 in Galois/Counter Mode, which is an authenticated encryption with associated data (AEAD) cipher. GCM provides both confidentiality and integrity in a single operation, and SHA256 is used for the handshake hash. This suite meets the requirement for protecting application data.

Why this answer

TLS_AES_128_GCM_SHA256 is the only valid TLS 1.3 cipher suite listed that uses an AEAD algorithm. GCM provides authenticated encryption, ensuring both confidentiality and integrity of application data. The other options are either legacy TLS 1.2 suites with CBC and separate MACs or an invalid TLS 1.3 suite name, so they do not meet the requirement.

Exam trap

The trap here is selecting a cipher suite based on key size or familiarity without recognizing that TLS 1.3 mandates AEAD ciphers and disallows CBC mode.

486
Multi-Selecteasy

A security administrator is setting up a public key infrastructure (PKI) for internal use. Which two of the following components are essential for establishing a chain of trust from the root CA to end-entity certificates?

Select 2 answers
A.An intermediate (subordinate) CA certificate signed by the root CA
B.A certificate signing request (CSR)
C.A self-signed root CA certificate
D.An online certificate status protocol (OCSP) responder
E.A certificate revocation list (CRL)
AnswersA, C

An intermediate CA certificate, signed by the root CA, extends the trust anchor so end-entity certificates chain upward to the root. This satisfies the stem's requirement for establishing a verifiable chain of trust from root CA to end-entity certificates.

Why this answer

The chain of trust must begin with a self-signed root CA certificate (C), which is the trust anchor that is inherently trusted and whose private key signs the certificates below it. To extend that trust to end-entity certificates without exposing the root's private key, an intermediate (subordinate) CA certificate signed by the root CA (A) is required, forming the hierarchical path root CA → intermediate CA → leaf certificate. A CSR (B) is only a request containing a public key and identity information that a CA uses to issue a certificate; it is not itself a link in the trust chain.

An OCSP responder (D) and a CRL (E) are revocation-checking mechanisms that report certificate status, but they do not establish the chain of trust from the root CA to end-entity certificates.

487
MCQeasy

A company needs to encrypt large volumes of data at rest on a file server. Which type of cryptography is most appropriate for this task?

A.Asymmetric encryption
B.Public Key Infrastructure (PKI)
C.Symmetric encryption
D.Hash function
AnswerC

Symmetric encryption uses a single shared key with algorithms such as AES, delivering the high throughput needed to encrypt large volumes of data at rest on a file server. Asymmetric cryptography is far slower and unsuited to bulk data.

Why this answer

Symmetric encryption uses a single shared key for both encryption and decryption, making it significantly faster and more efficient than asymmetric encryption for bulk data encryption. For large volumes of data at rest on a file server, symmetric algorithms like AES-256 provide the necessary performance and security, as they are designed to handle high-throughput encryption with minimal computational overhead.

Exam trap

The trap here is that candidates confuse the role of asymmetric encryption (used for key exchange or small data) with bulk encryption, or mistakenly think PKI is an encryption method rather than a management framework, leading them to choose options that are technically valid in other contexts but inappropriate for large-scale data-at-rest encryption.

How to eliminate wrong answers

Option A is wrong because asymmetric encryption (e.g., RSA, ECC) is computationally intensive and orders of magnitude slower than symmetric encryption, making it impractical for encrypting large volumes of data at rest; it is typically used for key exchange or digital signatures. Option B is wrong because Public Key Infrastructure (PKI) is a framework for managing digital certificates and public keys, not an encryption algorithm itself; it supports asymmetric operations but does not directly encrypt bulk data. Option D is wrong because a hash function (e.g., SHA-256) is a one-way function that produces a fixed-size digest and is not reversible, so it cannot be used for encryption or decryption of data at rest.

488
MCQeasy

An organization is hardening a new Windows server for production use. Which of the following is the most effective method to ensure that only approved applications can run?

A.Enable BitLocker drive encryption
B.Enable User Account Control (UAC)
C.Configure AppLocker or Windows Defender Application Control
D.Install Windows Defender Antivirus
AnswerC

AppLocker and Windows Defender Application Control enforce application allowlisting, permitting only explicitly approved executables to run. This directly satisfies the requirement that only approved applications execute, unlike antivirus scanning or firewall rules, which detect or block traffic rather than restrict which programs may launch.

Why this answer

AppLocker and Windows Defender Application Control (WDAC) are the native Windows mechanisms that enforce application allowlisting by permitting only approved executables, scripts, and installers to run. They operate via policy at the kernel/OS level and are the correct control for restricting execution to approved software. This directly satisfies the requirement that only approved applications can run.

Exam trap

SSCP often tests the confusion between antivirus (denylist, detects known bad) and application allowlisting (only approved apps run), tempting candidates to pick Defender Antivirus as if it guaranteed only approved software executes.

How to eliminate wrong answers

Option A is wrong because BitLocker provides full-disk encryption for data-at-rest confidentiality and does not control which applications execute. Option B is wrong because UAC prompts for elevation and limits standard-user privileges but does not maintain an allowlist of approved applications. Option D is wrong because Windows Defender Antivirus detects and blocks known malware by signature and behavior, but it is a denylist approach, not an allowlist that guarantees only approved apps run.

489
MCQeasy

Which metric is used to measure the average time it takes to detect an incident?

A.Recovery Point Objective (RPO)
B.Mean Time to Resolve (MTTR)
C.Mean Time to Detect (MTTD)
D.Recovery Time Objective (RTO)
AnswerC

Mean Time to Detect measures the average elapsed time between an incident's actual occurrence and its detection by monitoring or staff. This directly satisfies the stem's requirement for the metric quantifying detection speed, distinguishing it from response or resolution metrics.

Why this answer

Mean Time to Detect (MTTD) is the correct metric because it specifically measures the average time elapsed between the occurrence of an incident and its detection by monitoring systems or security personnel. This metric is critical in incident response as it directly impacts the window of opportunity for attackers to cause damage before containment begins.

Exam trap

The trap here is that candidates often confuse Mean Time to Detect (MTTD) with Mean Time to Resolve (MTTR) because both acronyms start with 'MTT' and relate to incident timelines, but MTTD focuses solely on detection while MTTR covers the entire resolution process after detection.

How to eliminate wrong answers

Option A is wrong because Recovery Point Objective (RPO) measures the maximum acceptable amount of data loss measured in time, not detection time; it is used in backup and disaster recovery planning. Option B is wrong because Mean Time to Resolve (MTTR) measures the average time taken to fully resolve an incident after detection, not the detection phase itself. Option D is wrong because Recovery Time Objective (RTO) measures the maximum acceptable downtime after a disaster, not the time to detect an incident.

490
MCQhard

A financial services firm must prove that an e-commerce application's source code has not been tampered with between the build pipeline and production deployment. The pipeline already stores build artifacts in an internal repository. Which control BEST provides this assurance?

A.Generate an SBOM in SPDX format and archive it alongside each release.
B.Enable multi-factor authentication for all engineers who have access to the artifact repository.
C.Sign each build artifact with a key held by the CI/CD system and verify the signature before deployment.
D.Require developers to sign Git commits with their personal GPG keys.
AnswerC

Cryptographically signing the artifact in the pipeline and verifying that signature at deploy time binds the exact bytes to a trusted build process. Any tampering after signing invalidates the signature and blocks deployment. This is the mechanism behind sigstore/cosign and similar supply-chain integrity tools, and it directly satisfies the requirement for provable artifact integrity.

Why this answer

Signing build artifacts in the pipeline and validating those signatures before deployment creates a cryptographic chain from the trusted build to production. If any byte changes in transit or at rest, verification fails. SBOMs, commit signing, and MFA improve visibility or access control but do not seal the artifact itself, so they cannot prove non-tampering.

Exam trap

The trap here is conflating provenance metadata such as an SBOM or a signed Git commit with cryptographic integrity of the deployed artifact.

491
MCQmedium

A financial services firm runs a Java-based customer portal on Apache Tomcat. During a code review, the security team discovers that the application deserializes session objects received from an untrusted partner API without validating their contents. An attacker could craft a malicious serialized object that executes arbitrary code on the server when deserialized. Which of the following controls BEST mitigates this risk?

A.Enable TLS 1.3 with mutual authentication between the portal and the partner API.
B.Implement a strict allowlist of permitted classes for deserialization and reject all others.
C.Increase the Java heap size and enable garbage collection tuning on the Tomcat server.
D.Deploy a web application firewall (WAF) with OWASP ModSecurity Core Rule Set in blocking mode.
AnswerB

An allowlist restricts deserialization to only known, safe classes, preventing attacker-controlled gadget chains from being instantiated. Because the partner API only needs to send specific session object types, enumerating those types and rejecting everything else directly blocks the malicious object from being processed. This is the most targeted and effective mitigation for insecure deserialization in this scenario.

Why this answer

Insecure deserialization allows attackers to influence object state and potentially achieve remote code execution. The most direct fix is to constrain which classes can be deserialized using an allowlist, so only expected types from the partner API are accepted. Transport encryption, WAF rules, and JVM tuning do not validate object contents and therefore fail to eliminate the vulnerability.

Exam trap

The trap here is assuming that encrypting the transport channel with mutual TLS secures the payload, when in fact it only protects data in transit and does nothing to validate the deserialized object itself.

492
MCQeasy

Which access control model is best suited for a military environment where data classification (Unclassified, Confidential, Secret, Top Secret) and subject clearance levels are the primary factors for access decisions?

A.Attribute-Based Access Control (ABAC)
B.Mandatory Access Control (MAC)
C.Discretionary Access Control (DAC)
D.Role-Based Access Control (RBAC)
AnswerB

MAC assigns subjects clearance levels and objects classification labels, with access determined solely by those labels rather than owner discretion. This mandatory, hierarchical comparison directly matches the military requirement where clearance and data classification are the primary access factors.

Why this answer

Mandatory Access Control (MAC) enforces access based on labels (classification and clearance) and is used in military and government settings. Option B is correct. Option A (ABAC) is attribute-based and not the traditional model for military-grade security.

Option C (DAC) allows owners to set permissions, which is unsuitable for classified environments. Option D (RBAC) uses roles, not classification levels.

493
MCQeasy

A help desk technician needs to reset a user's password but should not be able to modify other user attributes. Which access control principle should be applied to enforce this restriction?

A.Need-to-know
B.Least privilege
C.Separation of duties
D.Mandatory access control
AnswerB

Least privilege grants the technician only the specific permissions needed to reset the password, nothing more. This restricts the account from modifying other user attributes, directly enforcing the stem's restriction while still allowing the required help desk task to be completed.

Why this answer

Least privilege ensures that a user or process is granted only the minimum permissions necessary to perform their job function. In this scenario, the help desk technician needs the ability to reset passwords but must be restricted from modifying other user attributes, such as group membership or account expiration. By applying least privilege, the technician's account is assigned a role or permission set that specifically allows password reset operations (e.g., via Active Directory delegated permissions or a custom RBAC role) while explicitly denying write access to other user object properties.

Exam trap

ISC2 often tests least privilege by presenting a scenario where a user needs a specific action (like password reset) and candidates confuse it with separation of duties, which focuses on splitting tasks across multiple people rather than limiting the scope of a single user's permissions.

How to eliminate wrong answers

Option A is wrong because need-to-know is a confidentiality principle that restricts access to data based on the user's requirement to know that information to perform their duties, not a mechanism for limiting modification permissions on specific attributes. Option C is wrong because separation of duties divides critical tasks among multiple individuals to prevent fraud or error (e.g., one person requests a password reset and another approves it), but it does not directly limit the scope of permissions for a single technician. Option D is wrong because mandatory access control (MAC) enforces system-wide policies based on labels and clearances (e.g., Bell-LaPadula model), which is too rigid and not designed for granular attribute-level restrictions within a single user object.

494
MCQhard

An incident responder is preparing to acquire volatile data from a compromised Linux server that is still powered on. The server hosts a critical database and cannot be shut down yet. According to order of volatility, which data source should the responder collect FIRST?

A.Output of the netstat -antp command showing active network connections
B.Contents of the /var/log/auth.log file
C.Temporary files in the /tmp directory
D.Contents of physical memory (RAM) using a tool such as LiME
AnswerD

Order of volatility dictates that memory (RAM) is more volatile than network state, disk logs, or temporary files. RAM holds running processes, open network connections, encryption keys, and malware artifacts that disappear on shutdown or reboot. Capturing RAM first preserves the most perishable evidence. Tools like LiME allow memory acquisition on Linux, making this the correct first step.

Why this answer

The order of volatility prioritizes data that is most likely to be lost first. RAM is highly volatile and contains running processes, network connections, encryption keys, and malware that may not exist on disk. Network state and disk logs are less volatile and can be collected afterward.

Capturing memory with a tool like LiME before other sources ensures the most perishable evidence is preserved for forensic analysis.

Exam trap

The trap here is assuming that network connections or logs are the most volatile because they change frequently, when actually RAM contents are lost first upon shutdown or reboot.

495
MCQmedium

A security administrator needs to choose an encryption algorithm for a high-speed network where data is encrypted at the link layer. Which algorithm is most appropriate?

A.RSA
B.Diffie-Hellman
C.AES
D.SHA-256
AnswerC

AES is a symmetric block cipher offering high throughput in hardware, making it suited to link-layer encryption where line-rate performance is required. Its low latency and efficiency satisfy the high-speed constraint, unlike asymmetric algorithms such as RSA, which are far slower and impractical for bulk data encryption.

Why this answer

AES (Advanced Encryption Standard) is the most appropriate choice for link-layer encryption in high-speed networks because it is a symmetric block cipher designed for efficient hardware and software implementation, offering high throughput with low latency. Unlike asymmetric algorithms, AES operates with a single shared key, making it ideal for encrypting bulk data at the data link layer where speed and minimal overhead are critical.

Exam trap

The trap here is that candidates confuse encryption algorithms with key exchange or hashing functions, mistakenly choosing RSA or Diffie-Hellman for bulk encryption, or SHA-256 for confidentiality, when symmetric ciphers like AES are the correct choice for high-speed link-layer encryption.

How to eliminate wrong answers

Option A is wrong because RSA is an asymmetric encryption algorithm used primarily for key exchange and digital signatures, not for bulk data encryption; its computational overhead makes it unsuitable for high-speed link-layer encryption. Option B is wrong because Diffie-Hellman is a key exchange protocol, not an encryption algorithm; it establishes a shared secret but does not encrypt data itself. Option D is wrong because SHA-256 is a cryptographic hash function, not an encryption algorithm; it provides integrity and authentication but cannot encrypt or decrypt data.

496
MCQeasy

A security administrator is reviewing the organization's account management procedures. The administrator discovers that user accounts for terminated employees remain active for up to 30 days after departure. Which account management control should the administrator implement to address this risk?

A.Enforce a password expiration policy of 30 days
B.Implement an automated account deprovisioning process tied to HR termination records
C.Conduct quarterly access reviews of all user accounts
D.Require multi-factor authentication for all user accounts
AnswerB

Automated deprovisioning triggered by HR termination records ensures accounts are disabled or removed as soon as the employment status changes. This directly reduces the window of unauthorized access and eliminates reliance on manual, error-prone processes. It addresses the root cause: accounts remaining active after termination.

Why this answer

An automated deprovisioning process linked to HR termination records disables accounts immediately upon termination, eliminating the 30-day window of exposure. Manual or periodic controls cannot match this timeliness. This is the most direct and effective control for ensuring departed employees lose access promptly.

Exam trap

The trap here is selecting a control that strengthens authentication or reviews access periodically, when the actual gap is the delay in disabling accounts after termination.

497
MCQeasy

A security analyst is hardening a new Windows server. Which configuration would MOST effectively reduce the attack surface by limiting the software that can execute?

A.Enable Windows Defender Antivirus
B.Disable AutoPlay
C.Enable User Account Control (UAC)
D.Configure AppLocker rules
AnswerD

AppLocker enforces allow/deny rules on which executables, scripts and installers may run, directly restricting software execution on the Windows server and shrinking the attack surface. Unlike firewall or patch controls, it addresses the constraint of limiting what can execute.

Why this answer

AppLocker is a Windows application control feature that lets administrators define allow/deny rules based on publisher, path, or file hash, thereby restricting which executables, scripts, and installers can run. This directly limits the software that can execute, which is the most effective way to reduce attack surface against unauthorized or malicious code. Antivirus, AutoPlay, and UAC address other threats but do not control what software is permitted to run.

Exam trap

The trap is confusing detection-based controls (antivirus) or privilege controls (UAC) with execution control—only AppLocker (or similar WDAC) actually restricts what software is allowed to run.

How to eliminate wrong answers

Option A is wrong because Windows Defender Antivirus detects known malware signatures and behaviors but does not prevent arbitrary legitimate-looking executables from running—it is reactive, not a whitelisting control. Option B is wrong because disabling AutoPlay only prevents automatic execution of removable media content; it does not restrict software execution generally. Option C is wrong because UAC prompts for elevation but does not block execution of non-elevated software—a user can still run any executable that doesn't require admin rights.

498
MCQhard

During a security incident, the IR team discovers that an attacker used a valid user account to access sensitive data. The account had multifactor authentication (MFA) enabled. Which attack technique most likely bypassed the MFA?

A.Session hijacking
B.MFA fatigue attack
C.Man-in-the-middle (MITM) attack
D.Token theft from the endpoint
AnswerB

MFA fatigue floods a victim with repeated push notifications until they approve one, so the attacker never breaks the factor itself. Because the account used valid credentials and MFA was enabled, this technique explains the compromise without any cryptographic bypass.

Why this answer

MFA fatigue attacks exploit user behavior by bombarding the victim with repeated push notifications until they inadvertently approve an authentication request. Since the attacker already has the valid credentials, they trigger the MFA prompt repeatedly, and the user eventually accepts, granting the attacker access without needing to compromise the MFA mechanism itself.

Exam trap

ISC2 often tests the distinction between technical bypasses (e.g., token theft, MITM) and social/behavioral bypasses (e.g., MFA fatigue), leading candidates to overcomplicate the attack when the simplest explanation—user error under pressure—is correct.

How to eliminate wrong answers

Option A is wrong because session hijacking steals an already-authenticated session token (e.g., via XSS or packet sniffing) and does not involve bypassing MFA at the authentication step; the MFA was already satisfied when the session was created. Option C is wrong because a man-in-the-middle attack intercepts credentials or tokens in transit (e.g., using a rogue access point or SSL stripping) but does not directly cause the user to approve an MFA prompt; it typically targets the authentication handshake, not the user's approval behavior. Option D is wrong because token theft from the endpoint requires physical or remote access to steal a stored OATH token or session cookie, which bypasses MFA by stealing the post-authentication artifact, not by tricking the user into approving a live MFA request.

499
MCQhard

Which of the following is a characteristic of TLS 1.3 that improves security over previous versions?

A.Reduced cipher suite options including CBC mode
B.Use of RC4 cipher
C.Support for static RSA key exchange
D.Mandatory forward secrecy
AnswerD

TLS 1.3 mandates ephemeral key exchange for all cipher suites, so forward secrecy is compulsory rather than optional. This prevents an attacker who later obtains the server's long-term private key from decrypting previously captured session traffic.

Why this answer

TLS 1.3 mandates forward secrecy by removing static RSA and static Diffie-Hellman key exchange, requiring ephemeral key exchange (ECDHE) for every session. This means a compromised long-term private key cannot decrypt previously recorded sessions, which is a major security improvement over TLS 1.2 where static RSA was optional but allowed. This is codified in RFC 8446.

Exam trap

SSCP often tests whether candidates confuse 'reduced cipher suites' with 'removed CBC' — TLS 1.3 reduced suites by eliminating weak ones (CBC, RC4, static RSA), not by keeping them, and forward secrecy is the headline security gain.

How to eliminate wrong answers

Option A is wrong because TLS 1.3 actually removed CBC-mode cipher suites entirely, keeping only AEAD ciphers like AES-GCM and ChaCha20-Poly1305 — CBC was a source of padding-oracle attacks. Option B is wrong because RC4 was deprecated and removed; TLS 1.3 does not support RC4 at all. Option C is wrong because static RSA key exchange was explicitly removed in TLS 1.3 precisely to enforce forward secrecy — it is not supported.

500
MCQhard

A financial firm is designing access controls for a trading application. The firm wants to prevent any single employee from both initiating a large funds transfer and approving it, and it also wants to ensure that access rights are automatically revoked when an employee changes departments. Which combination of principles is the firm applying?

A.Zero trust and continuous authentication
B.Separation of duties and role-based access control with lifecycle management
C.Defense in depth and mandatory access control
D.Least privilege and need to know
AnswerB

Separation of duties ensures that no single individual controls both initiating and approving a sensitive transaction, directly matching the transfer requirement. Pairing this with role-based access control and lifecycle management means rights are tied to roles and updated automatically when an employee changes departments, which satisfies the revocation requirement. Together these principles address both stated objectives.

Why this answer

The requirement that one employee cannot both initiate and approve a transfer is the classic definition of separation of duties, which splits a sensitive process across multiple people. Automatically revoking or adjusting rights when an employee changes departments reflects role-based access control combined with lifecycle management, where access follows the current role rather than persisting indefinitely. Applying both principles together satisfies the firm's objectives.

Exam trap

The trap here is choosing least privilege alone, when least privilege governs how much access a user has rather than preventing one person from holding two conflicting duties.

501
MCQeasy

An organization is hardening its Windows servers. Which built-in Windows feature can be used to enforce application whitelisting, ensuring only approved executables run?

A.BitLocker
B.Windows Defender Antivirus
C.AppLocker
D.User Account Control (UAC)
AnswerC

AppLocker applies policy-based allow lists that restrict which executables, scripts and installers may run, using publisher, path or hash rules. This enforces application whitelisting natively on Windows servers, satisfying the hardening requirement without third-party agents.

Why this answer

AppLocker is a Windows built-in feature introduced in Windows 7 and Server 2008 R2 that allows administrators to create and enforce rules specifying which applications and files users can run. It uses a whitelisting model based on file attributes such as publisher, path, or hash, and can be configured via Group Policy or PowerShell cmdlets. By default, AppLocker blocks any executable not explicitly allowed, thus ensuring only approved executables run.

This directly meets the requirement for application whitelisting on Windows servers.

Exam trap

The trap here is confusing access control features like UAC or antivirus with application whitelisting; candidates may think UAC restricts applications, but it only controls elevation, not execution.

How to eliminate wrong answers

Option A is wrong because BitLocker is a full-disk encryption feature that protects data at rest, not an application control mechanism. Option B is wrong because Windows Defender Antivirus is a signature-based and heuristic malware detection tool; it does not enforce a whitelist of approved executables. Option D is wrong because User Account Control (UAC) manages privilege elevation for users and administrators, prompting for consent when administrative tasks are attempted; it does not restrict which applications can execute based on a whitelist.

502
MCQmedium

A security administrator notices that a critical server's event log shows repeated failed login attempts from an internal IP address that normally does not generate any traffic. The administrator immediately blocks the IP at the firewall and resets the account password. However, the incident response team later determines that the attacker had already gained access to the server. What is the MOST likely reason the administrator's actions were insufficient?

A.The administrator did not preserve the log evidence for forensic analysis.
B.The administrator neglected to perform a full system scan for malware.
C.The administrator did not isolate the server from the network.
D.The administrator failed to notify the data owner about the incident.
AnswerC

Blocking the source IP and resetting the password only evict future attempts; they do not terminate an established session or remove malware already resident. Without isolating the server, the attacker retained active access, so containment failed despite the firewall and credential changes.

Why this answer

The most likely reason the administrator's actions were insufficient is that the server was not isolated from the network. If the attacker already gained access, blocking the IP and resetting the password does not remove the attacker's presence or prevent lateral movement or data exfiltration. Isolation is a critical containment step in incident response that limits the attacker's ability to maintain persistence or cause further damage.

Exam trap

SSCP often tests the distinction between containment and other incident response steps — candidates may focus on evidence preservation or malware scanning, but the key is that without isolation, the attacker retains access and can continue malicious activities.

How to eliminate wrong answers

Option A is wrong because while preserving log evidence is important for forensics, it does not explain why the attacker still had access — the failure to isolate is the direct cause of continued compromise. Option B is wrong because a full system scan for malware is a remediation step, but without isolation, the attacker could re-infect or evade detection; the primary gap is containment. Option D is wrong because notifying the data owner is a communication step, not a technical containment measure, and would not have prevented the attacker's ongoing access.

503
MCQhard

A financial services firm is implementing role-based access control for its trading platform. An auditor finds that several traders can approve their own trades in addition to executing them. Which principle is being violated, and which control should the security administrator implement to remediate the finding?

A.Separation of duties; enforce distinct roles so the trade executor cannot also approve the same transaction.
B.Need to know; restrict traders from viewing market data unrelated to their assigned portfolios.
C.Least privilege; implement just-in-time privileged access with approval workflows.
D.Mandatory access control; classify trades by sensitivity and apply system-enforced labels.
AnswerA

Separation of duties requires that no single individual controls all parts of a critical transaction. Allowing a trader to both execute and approve trades creates an opportunity for fraud or undetected error. Remediation is to define mutually exclusive roles so the approval function is performed by a different authorized person, which directly addresses the conflicting duties observed by the auditor.

Why this answer

The auditor observed that the same individual can execute and approve a trade, which is a classic separation of duties violation. Separation of duties ensures that critical tasks are divided among multiple people so that no single person can complete a sensitive transaction alone. Implementing mutually exclusive roles that separate execution from approval directly remediates the finding.

Exam trap

The trap here is confusing least privilege with separation of duties when a user has two legitimate but conflicting business functions.

504
MCQhard

A critical vulnerability with a CVSS score of 9.8 is discovered in a web server that cannot be patched due to vendor dependency. What is the best compensating control?

A.Increase the frequency of vulnerability scans
B.Apply a virtual patch via a WAF
C.Decommission the server immediately
D.Disable the server's network connectivity
AnswerB

A WAF virtual patch inspects and blocks exploit traffic targeting the known vulnerability signature, mitigating risk without touching the vendor-locked server. This satisfies the unpatachable constraint by compensating at the network layer rather than the host.

Why this answer

A WAF can apply a virtual patch by inspecting HTTP/HTTPS traffic and blocking exploit attempts against the unpatched vulnerability. This provides a compensating control at the application layer without modifying the vulnerable server, allowing the server to remain operational while mitigating the risk.

Exam trap

The trap here is that candidates may confuse compensating controls with detection or removal actions, choosing increased scanning (A) as a proactive measure, when in fact only a WAF provides active mitigation at the application layer.

How to eliminate wrong answers

Option A is wrong because increasing vulnerability scan frequency only detects the vulnerability; it does not prevent exploitation, so the risk remains unmitigated. Option C is wrong because decommissioning the server immediately may be too disruptive and is not a compensating control; it is a removal of the asset, not a control that allows continued operation. Option D is wrong because disabling network connectivity effectively removes the server from service, which is a last-resort isolation measure, not a compensating control that permits ongoing functionality.

505
MCQmedium

Refer to the exhibit. What is the purpose of the 'group 14' parameter in the IKEv2 proposal?

A.Defines the integrity checking method
B.Specifies the encryption algorithm
C.Sets the Diffie-Hellman group for key exchange
D.Indicates the authentication method
AnswerC

Group 14 in an IKEv2 proposal specifies the Diffie-Hellman modular exponentiation group (2048-bit MODP) used during Phase 1 to derive the shared secret. It therefore governs the strength of the key exchange itself, not encryption or integrity algorithms, which are defined by separate proposal parameters.

Why this answer

In IKEv2 proposals, the 'group 14' parameter specifies the Diffie-Hellman (DH) group used for the key exchange process. DH group 14 corresponds to a 2048-bit modular exponentiation group, which provides the cryptographic strength for establishing a shared secret over an insecure channel. This is distinct from encryption, integrity, or authentication parameters.

Exam trap

The trap is that candidates often misinterpret 'group' as referring to an integrity or encryption algorithm due to its usage in other networking contexts (e.g., router configuration for routing protocols), but in IKEv2 proposals it specifically denotes the Diffie-Hellman group used for key exchange.

How to eliminate wrong answers

Option A is wrong because integrity checking methods in IKEv2 are defined by the integrity algorithm (e.g., HMAC-SHA256), not by the DH group parameter. Option B is wrong because the encryption algorithm (e.g., AES-256) is specified by a separate 'encr' parameter in the IKEv2 proposal, not by 'group 14'. Option D is wrong because authentication methods (e.g., pre-shared keys, certificates) are configured independently, often under an 'authentication' or 'auth' parameter, and are not related to DH group selection.

506
MCQeasy

A company wants to protect its web servers from common web application attacks such as SQL injection and cross-site scripting. The security team decides to deploy a device that inspects HTTP traffic and blocks malicious requests. Which technology should they implement?

A.Unified Threat Management (UTM) appliance
B.Stateful firewall
C.Web Application Firewall (WAF)
D.Intrusion Prevention System (IPS)
AnswerC

A WAF is specifically designed to inspect HTTP/HTTPS traffic and block attacks like SQL injection and cross-site scripting. It operates at the application layer and can enforce security policies based on request patterns. Deploying a WAF directly addresses the requirement to protect web servers from these common web application attacks, making it the correct choice.

Why this answer

A Web Application Firewall (WAF) is purpose-built to inspect HTTP/HTTPS traffic and block application-layer attacks such as SQL injection and cross-site scripting. It understands web protocols and can apply rules to detect and mitigate these threats. Other options like IPS, stateful firewalls, or UTM appliances may offer some protection but are not as specialized or effective for web application security.

Exam trap

The trap here is assuming that a network IPS or stateful firewall can fully protect against web application attacks, but they lack the deep HTTP inspection capabilities of a WAF.

507
MCQmedium

An attacker sends a large number of DHCP request messages with spoofed MAC addresses to a network's DHCP server, causing the server to exhaust its IP address pool and deny service to legitimate clients. This attack is known as:

A.ARP spoofing
B.DNS poisoning
C.DHCP spoofing
D.DHCP starvation
AnswerD

DHCP starvation exhausts the server's address pool by flooding it with requests bearing spoofed MAC addresses, so each bogus request consumes a lease until no addresses remain for legitimate clients. This matches the stem's constraint exactly: pool exhaustion causing denial of service to genuine hosts.

Why this answer

DHCP starvation is an attack in which the attacker floods the DHCP server with DISCOVER/REQUEST messages using spoofed MAC addresses, exhausting the available IP address pool so legitimate clients cannot obtain a lease. The scenario described — pool exhaustion and denial of service to legitimate clients — is the textbook definition of DHCP starvation.

Exam trap

SSCP often tests the distinction between DHCP starvation (exhausting the pool) and DHCP spoofing (rogue server) — candidates conflate the two because both involve DHCP and both can be chained together in a real attack.

How to eliminate wrong answers

Option A is wrong because ARP spoofing poisons the ARP cache to redirect traffic (man-in-the-middle), not to exhaust a DHCP pool. Option B is wrong because DNS poisoning corrupts DNS resolver caches to redirect name resolution, which is unrelated to DHCP lease exhaustion. Option C is wrong because DHCP spoofing involves a rogue DHCP server handing out malicious leases (e.g., a fake gateway), not exhausting the legitimate server's pool.

508
MCQeasy

A security analyst receives an alert indicating a large number of failed login attempts from a single IP. The analyst blocks the IP. What should be done next?

A.Report to management
B.Update the firewall rules
C.Conduct a thorough investigation
D.Monitor for recurrence
AnswerC

Investigation is critical to understand if the attack was successful and if other systems are affected.

Why this answer

Blocking an IP address is an immediate containment action, but it does not confirm the root cause or scope of the incident. A thorough investigation is required to determine whether the failed logins were part of a brute-force attack, credential stuffing, or a misconfigured service, and to check for indicators of compromise (IoCs) such as successful logins from the same IP or lateral movement. Without investigation, the analyst risks missing a broader breach or violating incident response procedures like those outlined in NIST SP 800-61.

Exam trap

The trap here is that candidates assume blocking the IP is the final step, confusing containment with resolution, and overlook the mandatory investigation phase required by incident response frameworks like NIST SP 800-61 or SANS PICERL.

How to eliminate wrong answers

Option A is wrong because reporting to management is a step that typically occurs after the incident is fully analyzed and documented, not immediately after a containment action; premature reporting can lead to incomplete or misleading information. Option B is wrong because updating firewall rules is redundant if the IP was already blocked (likely via a firewall or IPS rule), and the priority is to investigate the incident rather than modify rules without understanding the attack vector. Option D is wrong because monitoring for recurrence is a passive step that should follow investigation and remediation; without understanding the cause, monitoring alone cannot prevent the same attack from succeeding via a different IP or method.

509
Multi-Selecthard

Which THREE of the following are common types of network attacks?

Select 3 answers
A.ARP spoofing
B.SYN flood
C.Pharming
D.DNS poisoning
E.SQL injection
AnswersA, B, D

An attack on the local network to intercept traffic.

Why this answer

ARP spoofing is a network attack where an attacker sends falsified Address Resolution Protocol (ARP) messages onto a local area network. This links the attacker's MAC address with the IP address of a legitimate host, enabling interception, modification, or blocking of traffic intended for that host. It is a classic Layer 2 attack that exploits the lack of authentication in ARP.

Exam trap

ISC2 often tests the distinction between network-layer attacks (like ARP spoofing, SYN flood, DNS poisoning) and application-layer attacks (like SQL injection), causing candidates to mistakenly classify SQL injection as a network attack because it involves network traffic.

510
MCQhard

A financial institution uses a centralized authentication system. An auditor notes that when an employee is terminated, their access to several critical applications remains active for up to 24 hours because each application maintains its own local user database. Which of the following is the MOST effective control to reduce this window of exposure?

A.Require employees to sign a security awareness policy acknowledging immediate termination of access.
B.Implement a mandatory password change every 30 days for all users.
C.Implement network access control (NAC) to restrict terminated employees' devices from connecting to the network.
D.Deploy a centralized identity management system with automated provisioning and deprovisioning.
AnswerD

A centralized identity management system can automate the provisioning and deprovisioning of accounts across all connected applications. When an employee is terminated, the system can immediately disable or delete their accounts in all integrated systems, eliminating the 24-hour delay caused by separate local databases. This directly addresses the root cause of the exposure.

Why this answer

The core issue is that each application maintains its own user database, causing manual and delayed deprovisioning. A centralized identity management system with automated provisioning and deprovisioning solves this by integrating with applications and immediately disabling accounts upon termination. The other options do not address the root cause of decentralized, delayed account revocation.

Exam trap

The trap here is focusing on perimeter or policy controls instead of the identity lifecycle management that actually revokes access across multiple systems.

511
MCQmedium

Refer to the exhibit. A security analyst reviews a Windows Security event log entry showing multiple logon failures for user 'admin' from IP 10.0.0.100 within 5 minutes. What type of attack is most likely occurring?

A.Brute force attack
B.Kerberos ticket replay
C.Pass-the-hash attack
D.Privilege escalation
AnswerA

Repeated authentication failures for one account from a single IP within a short window indicate systematic credential guessing against 'admin'. This pattern, rather than a single mistyped password, satisfies the brute-force definition: automated or repeated attempts to discover valid credentials.

Why this answer

Multiple logon failures for the same user from a single IP within a short time frame is characteristic of a brute force attack, where an attacker systematically tries many passwords to gain access.

Exam trap

SSCP often tests the distinction between brute force and other attacks; candidates may confuse pass-the-hash (which uses hashes) or privilege escalation (which is a goal, not an attack type) with brute force.

How to eliminate wrong answers

Option B is wrong because Kerberos ticket replay involves reusing a stolen ticket, not multiple failed logons. Option C is wrong because pass-the-hash uses a captured hash to authenticate without knowing the password, typically resulting in successful logons, not failures. Option D is wrong because privilege escalation occurs after gaining initial access, not during repeated failed logon attempts.

512
MCQmedium

A network engineer is troubleshooting a site-to-site VPN that is failing to establish. The pre-shared key is correct and both sides use IKEv2. The VPN logs show 'no proposal chosen'. What is the most likely cause?

A.Firewall blocking UDP port 500
B.Incorrect peer IP address
C.Mismatched encryption algorithms
D.Expired certificates
AnswerC

IKEv2 'no proposal chosen' means the peers could not agree on a Phase 1 or Phase 2 proposal. Mismatched encryption or integrity algorithms between the two gateways is the classic cause, since the pre-shared key and version already match.

Why this answer

The 'no proposal chosen' error in IKEv2 indicates that the two VPN peers cannot agree on a common set of security parameters during the IKE_SA_INIT exchange. Since the pre-shared key is correct and both sides use IKEv2, the most likely cause is a mismatch in the encryption algorithms (e.g., AES-256 vs. AES-128), hash algorithms (e.g., SHA-256 vs.

SHA-1), or Diffie-Hellman groups (e.g., group 14 vs. group 2). This prevents the IKE security association from being established.

Exam trap

ISC2 often tests the distinction between 'no proposal chosen' (which points to a cryptographic parameter mismatch) and 'no response' or 'timeout' (which points to connectivity or firewall issues), leading candidates to incorrectly select firewall blocking when the error message clearly indicates a proposal negotiation failure.

How to eliminate wrong answers

Option A is wrong because a firewall blocking UDP port 500 would typically result in a timeout or 'no response' error, not a specific 'no proposal chosen' message, as the packets would not reach the peer. Option B is wrong because an incorrect peer IP address would cause a connection timeout or 'no route to host' error, as the packets would be sent to the wrong destination, not a proposal mismatch. Option D is wrong because expired certificates are not relevant in a pre-shared key (PSK) authentication scenario with IKEv2; certificate issues would generate authentication failures, not proposal mismatches.

513
MCQhard

A software vendor distributes patches over the internet. Customers must be able to verify that a patch came from the vendor and was not altered in transit. The vendor wants to use a digital signature. Which key should the vendor use to create the signature?

A.The vendor's private key
B.The customer's private key
C.A symmetric session key shared with each customer
D.The vendor's public key
AnswerA

A digital signature is created by signing a hash of the patch with the signer's private key. Only the vendor possesses this private key, so a successful verification with the corresponding public key proves origin and integrity. This directly satisfies the requirement that customers can confirm the patch came from the vendor and was not modified in transit.

Why this answer

Digital signatures rely on asymmetric cryptography: the signer uses its private key to sign a hash of the data, and verifiers use the signer's public key to check the signature. Because only the vendor holds its private key, a valid signature proves the patch originated from the vendor and was not altered. Public keys, symmetric keys, and customer keys cannot provide this combination of authenticity and integrity.

Exam trap

The trap here is reversing the roles of public and private keys, or assuming a shared symmetric key can provide non-repudiation for a publicly distributed patch.

514
MCQeasy

A university's IT department manages a network used by students and faculty. The security team notices an unusual increase in outbound traffic from the student dormitory network during late hours. Upon investigation, they discover that several student laptops are infected with malware that is attempting to connect to external command-and-control (C2) servers. The team needs to contain the incident quickly while minimizing impact on legitimate users. Which of the following is the BEST immediate containment measure?

A.Shut down the entire dormitory network
B.Disconnect the infected laptops from the network and take them offline for remediation
C.Block all outbound traffic from the dormitory subnet
D.Update the antivirus definitions on the infected laptops
AnswerB

Isolating the infected laptops halts their outbound C2 connections at the endpoint, containing the incident without disrupting the wider dormitory or faculty network. Remediation then proceeds offline, so legitimate users retain connectivity while the malware's command-and-control channel is severed.

Why this answer

Disconnecting the infected laptops and taking them offline for remediation is the most targeted containment measure: it stops C2 communication immediately while leaving the rest of the dormitory network operational for legitimate users. This satisfies the requirement to contain quickly with minimal impact on unaffected users. It also preserves the infected hosts for forensic analysis before remediation.

Exam trap

SSCP often tests the misconception that broader containment (shutting down the whole network or subnet) is always better, when the BEST answer balances containment speed with minimal impact on legitimate users.

How to eliminate wrong answers

Option A is wrong because shutting down the entire dormitory network is a blunt measure that disrupts all legitimate users and is disproportionate to the scope of a few infected laptops. Option C is wrong because blocking all outbound traffic from the dormitory subnet would also disrupt legitimate academic and personal use, and it is broader than necessary. Option D is wrong because updating antivirus definitions is a remediation step, not immediate containment; the malware would continue C2 communication until the update is applied and the host cleaned.

515
Multi-Selectmedium

Which TWO of the following are effective methods for monitoring risk in real-time?

Select 2 answers
A.User access reviews
B.Security information and event management (SIEM) systems
C.Quarterly vulnerability scanning
D.Annual penetration testing
E.Intrusion detection systems (IDS)
AnswersB, E

SIEM systems aggregate and correlate log events from multiple sources in real time, generating alerts on suspicious patterns. This satisfies the stem's real-time monitoring constraint through continuous event correlation and rule-based detection, unlike periodic vulnerability scans or manual log reviews.

Why this answer

Option B is correct because SIEM systems aggregate and correlate log and event data from across the environment in real time, generating alerts on suspicious patterns so risk can be monitored continuously. Option E is correct because IDS solutions inspect network or host traffic continuously and raise alerts on malicious or anomalous activity as it happens, providing real-time risk visibility. The unmarked options do not belong because user access reviews (A) are periodic governance activities, quarterly vulnerability scanning (C) runs on a scheduled cadence rather than continuously, and annual penetration testing (D) is a point-in-time assessment performed only once a year.

Exam trap

The trap here is that candidates confuse periodic review activities (like access reviews or vulnerability scans) with real-time monitoring, failing to recognize that only SIEM and IDS provide continuous, automated analysis of live data.

516
MCQhard

A medium-sized e-commerce company uses a SIEM with correlation rules. During peak sales hours, the SIEM generates an alert: multiple failed login attempts from internal IP 172.16.10.50 followed by a successful login to a critical database server. The account used is 'dbadmin', which normally only authenticates from the IT department subnet. The user 'dbadmin' reports that they had to try several passwords because they forgot theirs earlier. The incident responder is under pressure to quickly restore normal operations. Which course of action should the responder take?

A.Block the user's account immediately to prevent any further access.
B.Reset the user's password and enable multi-factor authentication (MFA).
C.Dismiss the alert as a false positive since the user explained the failed attempts.
D.Investigate the user's recent activity, check for abnormal logins, and look for lateral movement from the source IP.
AnswerD

The alert may be benign, but the source IP and unusual dbadmin login pattern warrant verification before dismissing it. Investigating recent activity, abnormal logins and lateral movement confirms or rules out compromise without prematurely closing the incident.

Why this answer

While the user's explanation seems plausible, the alert indicates a deviation from normal behavior (logins from an unexpected subnet). The responder should investigate the user's recent activity, check for abnormal logins, and look for lateral movement from the source IP to rule out a potential compromise. Option A (blocking the user's account immediately) could be disruptive if it's a false positive and may prevent legitimate access.

Option B (resetting password and enabling MFA) is a good security measure but does not address the need to verify whether the account was actually compromised or if there is ongoing malicious activity. Option C (dismissing the alert as a false positive) is premature and ignores the possibility of credential stuffing or account takeover. Therefore, investigating further is the most appropriate course of action.

517
MCQmedium

A company is deploying a new web application that will be accessible to the public. The security team wants to ensure that session identifiers cannot be predicted or reused by an attacker who captures one over an unencrypted network segment. Which control should be implemented to BEST address this risk?

A.Generate session identifiers using a cryptographically secure random number generator and transmit them only over TLS.
B.Encode session identifiers using Base64 to obscure their contents from casual observation.
C.Bind session identifiers to the client's IP address and user agent string for validation.
D.Store session identifiers in persistent cookies with long expiration times to reduce reauthentication.
AnswerA

Cryptographically secure random session identifiers resist prediction, and transmitting them only over TLS prevents interception on the network. Together these address both predictability and capture risks. This is the standard approach for protecting session tokens in public web applications and aligns with secure session management guidance.

Why this answer

The risk is twofold: an attacker might predict a session identifier or capture one on the network. Using a cryptographically secure random generator makes prediction infeasible, and requiring TLS for transmission prevents interception. Together they directly mitigate the described threat, whereas encoding, long-lived cookies, and client binding do not address the core weaknesses.

Exam trap

The trap here is confusing encoding with encryption, or assuming that binding a token to client attributes makes it safe even when it can still be captured in transit.

518
MCQmedium

A security analyst is reviewing firewall logs and notices repeated inbound TCP SYN packets to multiple destination ports on an internal web server, but no corresponding ACK packets are returned. The source IP address is spoofed. Which type of activity does this pattern most likely indicate?

A.TCP SYN flood
B.Smurf attack
C.UDP amplification attack
D.DNS cache poisoning
AnswerA

A TCP SYN flood sends numerous SYN packets with spoofed source addresses to exhaust the server's connection backlog. Because the source is spoofed, the server's SYN-ACK replies never reach a real host, so no final ACK completes the handshake, exactly matching the observed half-open connections.

Why this answer

The pattern of many TCP SYN packets with spoofed source addresses and no completing ACKs is the signature of a TCP SYN flood, a denial-of-service technique that exhausts the target's half-open connection table. The lack of ACK packets confirms that the handshake is never completed, which is characteristic of this attack.

Exam trap

The trap here is confusing a TCP SYN flood with other volumetric attacks such as UDP amplification or Smurf, even though the observed protocol and handshake behavior uniquely identify the SYN flood.

519
Multi-Selectmedium

An incident responder is collecting volatile evidence from a compromised Linux server. Which TWO of the following should be collected first? (Select two.)

Select 2 answers
A.Disk image of the system drive
B.System log files from /var/log
C.Hardware configuration inventory
D.List of active network connections using netstat
E.Contents of RAM using LiME
AnswersD, E

Listing active network connections with netstat captures ephemeral socket state that vanishes on reboot or service restart, preserving attacker command-and-control and lateral-movement evidence. This satisfies the stem's volatility constraint: network connections are among the first artefacts lost, so they must be collected before memory-resident data degrades further.

Why this answer

Option E (Contents of RAM using LiME) is correct because RAM is the most volatile evidence on a running Linux system and is lost on shutdown or reboot; LiME (Linux Memory Extractor) is a kernel module that captures physical memory to a file for later forensic analysis, preserving running processes, encryption keys, and network state. Option D (List of active network connections using netstat) is correct because active connections, listening sockets, and associated PIDs are highly volatile and change within seconds, so capturing them early preserves evidence of command-and-control channels and lateral movement; netstat (or its modern replacement ss) reads this state directly from the kernel. Option A (Disk image of the system drive) is not first because disk contents are persistent and can be acquired later without loss, and imaging a live disk is slower and less volatile than memory or network state.

Option B (System log files from /var/log) is not first because logs are stored on disk and persist across reboots, so they are less volatile than RAM or active connections. Option C (Hardware configuration inventory) is not first because hardware configuration is static and remains available after the incident, making it the least volatile category of evidence.

Exam trap

In the SSCP exam, the order of volatility is a key concept for incident response. The trap is that candidates mistakenly prioritize disk-based artifacts (logs, images) over truly volatile data like RAM and network connections, which are lost on power-off.

520
MCQeasy

Which authentication method generates a one-time password that is valid for only a short time window?

A.Biometric scan
B.HMAC-based One-Time Password (HOTP)
C.Static password
D.Time-based One-Time Password (TOTP)
AnswerD

TOTP derives the one-time password from a shared secret combined with the current time step, so each code is valid only within a short window before the counter advances. That time-bound derivation is what limits validity, unlike event-based or static methods.

Why this answer

TOTP (Time-based One-Time Password, RFC 6238) generates a one-time password derived from a shared secret and the current time step (typically 30 seconds), so the code is valid only within a short time window. This time-bound validity is exactly what the question describes.

Exam trap

SSCP often tests the confusion between HOTP (counter-based) and TOTP (time-based), since both are OTP algorithms with similar names.

How to eliminate wrong answers

Option A is wrong because a biometric scan authenticates via a physical trait and does not generate a time-limited one-time password. Option B is wrong because HOTP (RFC 4226) is counter-based, not time-based — it increments a counter with each use, so codes don't expire on a time window. Option C is wrong because a static password does not change and has no time-limited validity.

521
MCQhard

A PKI administrator needs to check the revocation status of a digital certificate without requiring the client to download the entire CRL. Which method is designed for online, real-time certificate status checking?

A.OCSP
B.OCSP stapling
C.CRL
D.Certificate transparency
AnswerA

OCSP queries a responder for a single certificate's status in real time, returning a signed good, revoked, or unknown response. This avoids the client downloading and parsing the full CRL, directly meeting the stem's online, real-time revocation checking constraint.

Why this answer

OCSP (Online Certificate Status Protocol) is designed for online, real-time certificate status checking. It allows a client to query an OCSP responder for the revocation status of a specific certificate without downloading the entire CRL.

Exam trap

SSCP often tests the difference between OCSP and CRL, and candidates might confuse OCSP stapling as a separate protocol rather than an optimization of OCSP.

How to eliminate wrong answers

Option B is wrong because OCSP stapling is a method where the server staples the OCSP response to the TLS handshake, but it still relies on OCSP; the question asks for the method designed for online checking, which is OCSP itself. Option C is wrong because CRL (Certificate Revocation List) requires downloading the entire list, which is not real-time and can be large. Option D is wrong because Certificate Transparency is a logging framework for certificates, not for revocation checking.

522
MCQeasy

Which Windows feature allows an administrator to define security policies such as password complexity and account lockout across multiple systems in a domain?

A.Local Security Policy
B.Security Audit Policies
C.Group Policy
D.User Account Control (UAC)
AnswerC

Group Policy centrally defines and enforces domain-wide security settings, including password complexity and account lockout thresholds, by linking Group Policy Objects to sites, domains, or organisational units. This satisfies the stem's requirement for applying consistent policies across multiple systems in a domain, unlike local policy, which applies to a single machine only.

Why this answer

Group Policy is the correct answer because it is a centralized management feature in Windows Active Directory that allows administrators to define and enforce security policies—such as password complexity, account lockout thresholds, and audit settings—across multiple systems in a domain. Group Policy Objects (GPOs) are linked to sites, domains, or organizational units (OUs) and are applied to computers and users at logon or startup, ensuring consistent policy enforcement. This centralized approach is essential for enterprise environments where local settings would be impractical to manage individually.

Exam trap

The trap here is confusing local security settings with domain-wide centralized management; candidates often pick Local Security Policy because it sounds similar, but it only affects one machine, not a domain.

How to eliminate wrong answers

Option A is wrong because Local Security Policy applies only to a single standalone Windows system and cannot be used to enforce policies across a domain; it is configured via secpol.msc and affects only the local machine. Option B is wrong because Security Audit Policies are a subset of security settings that determine what events are logged, but they do not provide a mechanism for defining and distributing password complexity or account lockout policies across multiple systems; they are typically configured within Group Policy or Local Security Policy. Option D is wrong because User Account Control (UAC) is a security feature that prompts for elevation when administrative tasks are performed, but it does not define or distribute security policies like password complexity or account lockout across a domain.

523
MCQeasy

Based on the exhibit, what type of attack is most likely occurring?

A.Brute-force attack
B.Pass-the-hash attack
C.Dictionary attack
D.Password spraying attack
AnswerD

Password spraying tries a few common passwords across many accounts to avoid lockout thresholds, producing distributed failed logins rather than repeated failures on one account. The exhibit's pattern across numerous usernames matches this technique, distinguishing it from brute force.

Why this answer

The exhibit shows a scenario where an attacker attempts a small number of common passwords (e.g., one or a few) against many different usernames. This low-and-slow approach avoids triggering account lockout policies, which is the hallmark of a password spraying attack. Unlike dictionary attacks (many passwords on a single user) or brute-force attacks (exhaustive password guessing on one account), password spraying targets multiple accounts with commonly used passwords to increase success rates while staying under detection thresholds.

Exam trap

The trap here is confusing dictionary attacks (many passwords, one user) with password spraying (one password, many users), as both use a wordlist but differ in the attack vector and lockout avoidance strategy.

How to eliminate wrong answers

Option A is wrong because a brute-force attack tries all possible character combinations systematically, not a curated list of likely passwords, and would generate far more attempts than shown. Option B is wrong because a pass-the-hash attack uses captured NTLM or Kerberos hashes to authenticate without knowing the plaintext password, which is unrelated to trying passwords from a list. Option C is wrong because a dictionary attack focuses on many passwords against a single username, whereas the exhibit shows a single password attempt across multiple usernames, which is the hallmark of password spraying.

524
MCQmedium

A company wants to implement a key management system. They need to generate cryptographic keys that are unpredictable. Which source of randomness should be used?

A.Hardware random number generator (HRNG)
B.Random numbers from a website
C.Linear congruential generator (LCG)
D.Pseudorandom number generator (PRNG) seeded with current timestamp
AnswerA

An HRNG derives randomness from a physical entropy source, such as thermal or quantum noise, so its output cannot be predicted or reproduced. This satisfies the requirement for unpredictable key material, unlike deterministic software PRNGs, whose sequences are reproducible once the seed is known.

Why this answer

A hardware random number generator (HRNG) is the correct choice because it derives randomness from physical processes (e.g., thermal noise, quantum effects) that are inherently unpredictable and non-deterministic. Cryptographic key generation requires true entropy to resist brute-force and prediction attacks, which software-based deterministic methods cannot guarantee.

Exam trap

ISC2 SSCP often tests the misconception that a PRNG seeded with a timestamp is sufficient for cryptography, but the trap is that timestamps are predictable or guessable, making the output deterministic and insecure for key generation.

How to eliminate wrong answers

Option B is wrong because random numbers from a website are sourced over an untrusted network and may be intercepted, reused, or generated by a pseudorandom algorithm, offering no verifiable entropy. Option C is wrong because a linear congruential generator (LCG) is a deterministic, predictable algorithm with a short period, making it unsuitable for cryptographic key generation. Option D is wrong because a pseudorandom number generator (PRNG) seeded with a current timestamp is deterministic; if the timestamp is guessed or observed, all outputs become predictable, violating the unpredictability requirement.

525
Multi-Selectmedium

After a security incident, the response team holds a lessons learned meeting. Which TWO are primary objectives of this meeting? (Select two.)

Select 2 answers
A.Identify what went well and what could be improved
B.Update the incident response plan and runbooks
C.Delete all evidence to free up storage
D.Assign blame for the incident
E.Restore affected systems to production
AnswersA, B

Reviewing what went well and what could be improved captures strengths and gaps in detection, response and coordination, which is a primary purpose of the post-incident lessons learned meeting. It feeds directly into refining processes rather than assigning blame.

Why this answer

Option A is correct because a lessons learned (post-incident) meeting is fundamentally a review activity whose primary purpose is to evaluate the response effort, capturing both effective actions ('what went well') and gaps or weaknesses ('what could be improved') so the organization can learn from the incident. Option B is correct because the actionable output of that review is to feed findings back into the incident response plan, playbooks, and runbooks — updating procedures, detection rules, and escalation paths so future incidents are handled more effectively. Option C is incorrect because evidence must be preserved for forensic analysis, legal, and regulatory purposes, not deleted; evidence handling follows chain-of-custody requirements.

Option D is incorrect because lessons learned meetings are blameless post-mortems focused on process and systemic improvement, not on assigning individual fault, which would suppress honest reporting. Option E is incorrect because restoring affected systems to production is part of the recovery/eradication phase of incident handling, not an objective of the post-incident lessons learned meeting, which occurs after recovery.

Exam trap

The trap here is that candidates may confuse operational recovery tasks (like restoring systems or deleting evidence) with the strategic, process-improvement objectives of the lessons learned meeting, which are solely focused on analyzing the response and updating documentation.

Page 6

Page 7 of 13

Page 8