Courseiva

Systems Security Certified Practitioner SSCP (SSCP) — Questions 526–600

971 questions total · 13pages · All types, answers revealed

Page 7

Page 8 of 13

Page 9
526
MCQhard

A security analyst reviews a firewall log showing an internal IP attempting outbound connections to multiple external IPs on port 443. The analyst suspects command and control. Which additional data source would be MOST useful for confirmation?

A.NetFlow data
B.System event logs
C.DNS logs
D.Antivirus logs
AnswerC

DNS logs record the domain names resolved before outbound connections, revealing algorithmically generated or newly registered C2 domains that raw IP-and-port-443 firewall entries cannot show. This directly confirms command and control by tying the internal host's beaconing to known malicious infrastructure.

Why this answer

DNS logs are the most useful additional data source because C2 traffic often uses domain generation algorithms (DGAs) or connects to known malicious domains. By correlating the outbound connections on port 443 with DNS queries, the analyst can identify suspicious domain lookups that precede the connections, revealing the C2 infrastructure. Unlike NetFlow or system logs, DNS logs directly show the domain names being resolved, which is a key indicator of C2 activity.

Exam trap

The trap here is that candidates often choose NetFlow data (Option A) because it shows traffic flows, but they overlook that DNS logs directly reveal the domain names being resolved, which is critical for identifying C2 domains that may not appear in NetFlow's IP-only view.

How to eliminate wrong answers

Option A is wrong because NetFlow data provides metadata about traffic flows (source/destination IPs, ports, and volume) but does not include the domain names or DNS queries, making it less effective for identifying C2 domains. Option B is wrong because system event logs record local OS events (e.g., process creation, logins) and do not directly capture network-level DNS queries or outbound connection destinations. Option D is wrong because antivirus logs focus on file-based malware detections and may miss network-only C2 activity, especially if the malware is fileless or uses encrypted channels.

527
MCQmedium

An organization wants to ensure that only corporate-managed devices can connect to the internal network. Non-compliant devices should be placed in a restricted VLAN with limited access. Which technology should be deployed?

A.Virtual Private Network (VPN)
B.Network Access Control (NAC)
C.Stateful firewall
D.Intrusion Prevention System (IPS)
AnswerB

NAC enforces admission control at the network edge, authenticating and assessing device posture before granting access. Non-compliant devices are dynamically assigned to a restricted VLAN, exactly matching the requirement that only corporate-managed devices reach the internal network.

Why this answer

NAC (Network Access Control) is purpose-built to enforce endpoint compliance before granting network access. It authenticates devices via 802.1X, MAC authentication bypass, or agent-based posture checks, and can dynamically assign non-compliant devices to a quarantine/restricted VLAN with limited ACLs. This matches the requirement of allowing only corporate-managed devices on the internal network while isolating others.

Exam trap

The trap here is confusing 'restrict access' with firewall/IPS filtering — candidates pick a stateful firewall or IPS because they think of blocking traffic, but the question is about device identity and posture-based admission, which only NAC provides.

How to eliminate wrong answers

Option A is wrong because a VPN only provides encrypted remote access tunnels; it does not perform endpoint posture assessment or dynamically place non-compliant devices into a restricted VLAN. Option C is wrong because a stateful firewall filters traffic based on sessions and ports but has no visibility into device identity or compliance state, so it cannot distinguish corporate-managed from unmanaged endpoints. Option D is wrong because an IPS detects and blocks malicious traffic patterns (exploits, signatures, anomalies) but does not authenticate endpoints or enforce VLAN assignment based on device compliance.

528
Multi-Selectmedium

Which TWO are valid reasons to revoke a user's access? (Choose two.)

Select 2 answers
A.User is terminated
B.User changes job roles
C.User password expires
D.User completes quarterly training
E.User updates personal information
AnswersA, B

Termination ends the user's employment relationship, so all organisational access must be revoked immediately to prevent unauthorised use of credentials. This is a standard, mandatory trigger in the joiner-mover-leaver process, removing entitlements the user no longer legitimately requires.

Why this answer

Option A (User is terminated) is correct because when an employee leaves the organization, all access rights, accounts, and credentials must be revoked immediately to prevent unauthorized access and satisfy offboarding/least-privilege controls. Option B (User changes job roles) is correct because a role change triggers a review of existing permissions; access tied to the old role should be revoked and replaced with only the entitlements required for the new role, enforcing least privilege and separation of duties. Option C (User password expires) is not a revocation reason—an expired password simply requires a reset/change, and the account remains active.

Option D (User completes quarterly training) is unrelated to access rights; completing training does not remove entitlements. Option E (User updates personal information) is also unrelated—updating profile data such as contact details does not affect authorization or account status.

Exam trap

The trap here is that candidates confuse password expiration (a temporary lockout that can be resolved) with revocation (a permanent or indefinite removal of access rights), and they may think that completing training or updating personal info could justify revocation, but these are normal user lifecycle events that do not indicate a security risk.

529
Multi-Selecthard

Which three statements are true regarding mandatory access control (MAC) systems? (Select THREE)

Select 3 answers
A.Multilevel security is enforced
B.Subjects have clearance levels
C.Access decisions are based on security labels
D.The owner of an object can change its security label
E.Users can grant permissions to other users
AnswersA, B, C

MAC enforces multilevel security, where the system constrains information flow between sensitivity levels using labels and clearances. This mandatory, non-discretionary enforcement is the defining property distinguishing MAC from discretionary access control, where owners set permissions.

Why this answer

Option A is correct because MAC systems enforce multilevel security, where information flows are restricted between hierarchical sensitivity levels (e.g., Confidential, Secret, Top Secret) according to the system's policy rather than user discretion. Option B is correct because in MAC, every subject (user or process) is assigned a clearance level that determines the maximum classification of data it may access. Option C is correct because access decisions in MAC are made by comparing the security labels (classification) of objects against the clearance and labels of subjects, per rules such as Bell-LaPadula's no-read-up and no-write-down.

Option D is incorrect because in MAC the owner cannot arbitrarily relabel an object; label changes are controlled by the system's security policy and typically require privileged administrative authority. Option E is incorrect because discretionary delegation of permissions to other users is characteristic of DAC, not MAC, where access is governed by system-enforced labels and clearances rather than owner-granted permissions.

Exam trap

The trap here is that candidates confuse MAC with Discretionary Access Control (DAC), where owners can change permissions and grant access, leading them to incorrectly select options D or E as true for MAC.

530
MCQhard

An organization is restoring a critical database from a backup after a ransomware attack. Which of the following steps should be performed BEFORE restoring the data to ensure the restoration is successful and secure?

A.Notify users that the system will be available in one hour
B.Disconnect the backup server from the network
C.Immediately restore the most recent backup to minimize data loss
D.Verify the integrity of the backup and patch the exploited vulnerability
AnswerD

Validating backup integrity confirms the data is uncorrupted and restorable, while patching the exploited vulnerability prevents immediate re-infection during restoration. Both must precede the restore to satisfy the stem's requirement that restoration be successful and secure.

Why this answer

Verifying backup integrity (e.g., using checksums or restore tests) ensures the backup is not corrupted or incomplete, which is critical after a ransomware attack where backups may also be targeted. Patching the exploited vulnerability (e.g., applying a security update or disabling the vulnerable service) prevents re-infection during or after the restore, ensuring the recovery is secure. Without these steps, restoring a compromised or incomplete backup could lead to data loss or immediate re-encryption by the same ransomware.

Exam trap

The trap here is that candidates assume restoring the most recent backup is always the priority, but the SSCP exam emphasizes that verifying backup integrity and securing the environment against re-infection are mandatory prerequisites for a successful and secure recovery.

How to eliminate wrong answers

Option A is wrong because notifying users of a one-hour availability before verifying the backup or patching the vulnerability is premature and unrealistic; restoration time depends on backup size and integrity checks, and users should only be notified after a successful restore and testing. Option B is wrong because disconnecting the backup server from the network is a good practice during recovery to prevent ransomware spread, but it is not the step that ensures restoration success and security—it is a containment measure that should be done before or during the restore, not the critical prerequisite for a successful restore. Option C is wrong because immediately restoring the most recent backup without verifying its integrity risks restoring a corrupted or encrypted backup (common in ransomware attacks where backups are also encrypted), and without patching the vulnerability, the system will be immediately re-infected.

531
MCQhard

An incident responder is investigating a compromised Linux server and needs to collect volatile data. The responder has root access and wants to ensure that the data collected is admissible in a court of law. Which of the following commands should be used FIRST to capture the contents of physical memory?

A.LiME (Linux Memory Extractor) to dump memory to a file
B.gcore to dump the memory of all running processes
C.The 'free' command to display memory usage statistics
D.dd if=/dev/mem of=/evidence/memory.dd
AnswerA

LiME is a loadable kernel module designed for volatile memory acquisition on Linux. It allows the responder to dump physical memory to a file or over the network without altering the system state significantly. It is widely accepted in forensics because it preserves the integrity of the memory image and is less likely to crash the system, making the evidence more defensible in court.

Why this answer

LiME is specifically designed for Linux memory forensics, allowing a responder to capture physical memory in a forensically sound manner. It loads as a kernel module and writes the memory image to a file or network destination, preserving the integrity of the evidence. This method is accepted in legal proceedings because it does not alter the system state unnecessarily and captures a comprehensive image.

Exam trap

The trap here is assuming that traditional tools like dd on /dev/mem or process-level dumps are sufficient for full physical memory acquisition, when they are not forensically reliable on modern systems.

532
MCQhard

A security analyst reviews firewall logs and sees multiple 'ACL drop' entries for a specific internal IP trying to connect to a database server on port 1433. The rule base has an explicit permit for this traffic. What is the most likely reason for the drops?

A.The firewall rule is disabled
B.The database server is down
C.An earlier deny rule matches the traffic before the permit rule
D.The internal IP is on a blacklist
AnswerC

Firewalls evaluate ACLs top-down and stop at the first match. A deny entry positioned above the explicit permit matches the port 1433 traffic first, so the packet is dropped before the permit is ever evaluated.

Why this answer

The most likely reason for the ACL drops despite an explicit permit rule is that an earlier deny rule in the firewall rule base matches the traffic before the permit rule. Firewalls process ACL rules sequentially from top to bottom; the first matching rule determines the action. If a deny rule appears before the permit rule and matches the source IP, destination port, or other criteria, the traffic is dropped before reaching the permit entry.

Exam trap

The trap here is that candidates assume an explicit permit rule guarantees traffic flow, but they forget that ACLs are processed top-down and an earlier deny rule can override a later permit rule.

How to eliminate wrong answers

Option A is wrong because if the firewall rule were disabled, the traffic would not match any rule and would be subject to the default implicit deny, but the logs specifically show 'ACL drop' entries, which indicate a rule explicitly denied the traffic. Option B is wrong because a down database server would cause connection timeouts or TCP RSTs, not ACL drops; ACL drops occur at the firewall layer before any server interaction. Option D is wrong because blacklists are typically implemented as separate threat intelligence feeds or dynamic block lists, not as standard ACL rules; if the IP were on a blacklist, it would still be matched by an earlier deny rule, not by a separate 'blacklist' mechanism in the ACL.

533
Multi-Selecthard

Which THREE steps are essential during the identification phase of incident response?

Select 3 answers
A.Eradicate the threat
B.Notify stakeholders
C.Monitor logs and alerts
D.Determine scope of incident
E.Classify incident severity
AnswersC, D, E

Continuous log and alert monitoring detects anomalies and indicators of compromise, satisfying the identification phase's need to spot potential incidents early. Without this visibility, analysts cannot distinguish genuine security events from benign activity, so triage and escalation would lack the evidence required to confirm an incident.

Why this answer

During the identification phase of incident response, the essential steps are monitoring logs and alerts (C) to detect potential incidents, determining the scope of the incident (D) to understand its impact, and classifying incident severity (E) to prioritize response. Options A and B are not part of identification; eradication occurs later in the response phase, and stakeholder notification typically happens after identification and analysis.

534
MCQhard

A security analyst reviews log files and sees multiple failed SSH attempts from various IP addresses. The analyst implements a rate-limiting rule on the firewall to block IPs after 5 failed attempts in 10 minutes. This is an example of which type of security control?

A.Compensating
B.Preventive
C.Detective
D.Deterrent
E.Corrective
AnswerB

Rate-limiting blocks offending IPs before further authentication attempts succeed, stopping the brute-force activity rather than merely recording it. Because the control acts in advance to avert the incident, it functions as a preventive control, satisfying the requirement to halt repeated failed SSH attempts.

Why this answer

Rate-limiting SSH attempts by blocking IPs after 5 failed attempts in 10 minutes is a preventive control because it actively stops unauthorized access before it can occur. By enforcing a threshold on the firewall, the control reduces the attack surface against brute-force attacks, directly preventing further authentication attempts from suspicious sources.

Exam trap

Candidates often mistake preventive controls for deterrent controls. Preventive controls physically block the action (e.g., firewall rate-limiting), while deterrent controls only discourage (e.g., warning banners). This question's firewall rule actively blocks further attempts, making it preventive.

How to eliminate wrong answers

Option A is wrong because compensating controls are alternative measures that provide equivalent protection when a primary control cannot be implemented (e.g., using out-of-band authentication instead of a smart card), not a proactive block on SSH attempts. Option C is wrong because detective controls identify and log malicious activity after it happens (e.g., IDS alerts), whereas this firewall rule blocks attempts in real time. Option D is wrong because deterrent controls discourage attackers through fear of consequences (e.g., warning banners), but they do not physically or logically prevent the action.

Option E is wrong because corrective controls remediate damage after an incident (e.g., restoring from backup), not preemptively limiting failed logins.

535
MCQmedium

A financial services firm with 500 servers and 2000 workstations uses an internal public key infrastructure (PKI) for authentication and secure communication. The root CA certificate is self-signed and stored on an offline root CA server. Recently, the root CA server was physically stolen from a locked data center. Although the server was encrypted, forensic analysis confirms that the root CA private key was extracted. The security team must immediately revoke trust in the compromised root CA and issue new certificates to all devices. The environment includes Active Directory and Group Policy. Which approach best ensures all systems trust the new CA hierarchy and obtain valid certificates with minimal disruption?

A.Generate a new root CA, sign new subordinate CAs, distribute the new root via Group Policy, and re-issue all end-entity certificates.
B.Publish a certificate revocation list (CRL) and wait for existing certificates to expire.
C.Generate a new root CA certificate and key, then re-issue all subordinate CA certificates without re-issuing end-entity certificates.
D.Enable OCSP stapling on all web servers to check revocation status in real time.
AnswerA

Because the root private key was extracted, the entire hierarchy is untrusted; only a fresh root with new subordinates restores trust. Publishing the new root through Group Policy pushes it to all domain-joined machines automatically, and re-issuing end-entity certificates completes the replacement with minimal manual disruption.

Why this answer

The root CA private key has been compromised, requiring the entire PKI hierarchy to be rebuilt from scratch. A new self-signed root CA must be generated, new subordinate CAs signed under it, and all end-entity certificates re-issued to devices. Distributing the new root CA certificate via Active Directory Group Policy ensures that all domain-joined systems trust the new hierarchy automatically, minimizing manual intervention and disruption.

Exam trap

The trap here is that candidates may think re-issuing only subordinate CAs (Option C) is sufficient, overlooking that end-entity certificates signed by the compromised root remain untrusted and must also be replaced to restore a valid chain of trust.

How to eliminate wrong answers

Option B is wrong because publishing a CRL only revokes trust in the compromised root CA but does not establish a new trusted hierarchy; waiting for existing certificates to expire leaves systems vulnerable and without valid certificates for an extended period. Option C is wrong because re-issuing subordinate CA certificates without re-issuing end-entity certificates leaves all existing end-entity certificates signed by the compromised root CA still in use, which are untrusted and cannot be validated. Option D is wrong because OCSP stapling is a revocation checking mechanism, not a method to replace a compromised root CA or issue new certificates; it does not address the need to establish a new trust anchor.

536
MCQmedium

During incident response, a team needs to isolate an infected workstation that is part of a critical manufacturing network. Which containment method is MOST appropriate to minimize disruption while preventing the spread of malware?

A.Place the workstation into a quarantine VLAN via switch configuration
B.Apply a host-based firewall rule to block all inbound traffic
C.Physically unplug the network cable
D.Disable the user's Active Directory account
AnswerA

A quarantine VLAN isolates the workstation at the switch port while leaving the manufacturing network's routing and production traffic intact. This contains malware spread with minimal disruption, unlike disabling the switch port or powering off, which would halt critical operations.

Why this answer

Placing the workstation into a quarantine VLAN via switch configuration is most appropriate because it logically isolates the infected host from the rest of the network at Layer 2, preventing lateral spread of malware while allowing the manufacturing network to continue operating. This method uses 802.1Q VLAN tagging and access control lists (ACLs) on the switch to restrict traffic without physically disconnecting the device, which could disrupt time-sensitive manufacturing processes. It also preserves the ability to remotely manage or forensically image the workstation if needed.

Exam trap

The trap here is that candidates often choose 'physically unplug the network cable' because it seems like the most definitive containment, but they overlook the requirement to minimize disruption in a critical manufacturing network where sudden disconnection can halt production or cause safety hazards.

How to eliminate wrong answers

Option B is wrong because applying a host-based firewall rule to block all inbound traffic does not prevent the infected workstation from initiating outbound connections to spread malware to other systems, and it relies on the compromised host's own software, which may be disabled or bypassed by the malware. Option C is wrong because physically unplugging the network cable completely removes the workstation from the network, which can cause immediate disruption to critical manufacturing processes that depend on that workstation for real-time control or monitoring. Option D is wrong because disabling the user's Active Directory account only prevents authentication and access to domain resources, but does not stop the workstation from communicating with other devices on the same subnet or from spreading malware via non-authenticated protocols like ARP or NetBIOS.

537
MCQeasy

Which of the following protocols operates on TCP port 443 and provides encrypted communication between a web browser and a web server?

A.HTTPS
B.SMTP
C.SSH
D.HTTP
AnswerA

HTTPS secures HTTP traffic by layering it over TLS, which encrypts the session between browser and web server. It listens on TCP port 443 by default, satisfying both constraints in the stem: the specified port and encrypted communication. Plain HTTP uses port 80 and offers no encryption.

Why this answer

HTTPS (HTTP over TLS) operates on TCP port 443 and provides encrypted communication between a web browser and a web server using TLS. It is the standard secure web protocol and the only option that matches both the port and the encryption requirement.

Exam trap

SSCP often tests port/protocol pairings — the trap is that candidates know HTTPS is secure but may confuse it with SSH (port 22) or forget that HTTP (port 80) is the unencrypted counterpart.

How to eliminate wrong answers

Option B is wrong because SMTP (Simple Mail Transfer Protocol) uses TCP port 25 (or 587/465 for submission) and is for email transport, not encrypted web browsing. Option C is wrong because SSH uses TCP port 22 and provides secure remote shell access, not web browsing. Option D is wrong because HTTP uses TCP port 80 and is unencrypted, so it does not meet the encryption requirement.

538
MCQmedium

A software company wants outside contractors to reach a single internal source code repository without creating accounts in the company directory. The identity team proposes using the Security Assertion Markup Language so that contractors authenticate against their own employer's identity provider. Which statement describes the trust relationship that must exist for this to work?

A.Both organizations must share a single directory database that is replicated between their networks.
B.The company's service provider must trust assertions signed by the contractor's identity provider.
C.The contractor's identity provider must create shadow accounts for each user in the company directory.
D.The repository must issue a client certificate to each contractor before any assertion is accepted.
AnswerB

In a Security Assertion Markup Language exchange, the relying party accepts authentication statements only if it trusts the issuing authority. The company's repository acts as the service provider, and the contractor's employer acts as the identity provider, so a configured trust with the provider's signing certificate is mandatory. Without that trust relationship, the repository would treat incoming assertions as untrusted and deny access regardless of the contractor's credentials.

Why this answer

Federated authentication succeeds only when the relying party trusts the assertions issued by the partner identity provider, typically established by exchanging metadata and trusting the provider's signing certificate. Once that trust exists, contractors authenticate at their own employer and the repository consumes the signed assertion, so no local accounts are needed. This design keeps user lifecycle management with the employer while giving the company a verifiable basis for granting access.

Exam trap

The trap here is assuming federation requires local accounts or shared directories, when it actually depends on a configured trust in the partner's signed assertions.

539
MCQmedium

A security auditor discovers that a Linux server has a user who can execute any command as root via sudo without a password. Which file should be reviewed to verify this configuration?

A./etc/shadow
B./etc/group
C./etc/sudoers
D./etc/passwd
AnswerC

/etc/sudoers defines sudo privileges, including NOPASSWD entries that let a user run commands as root without authentication. Reviewing it confirms the auditor's finding, since the sudoers policy is the authoritative source for this configuration rather than PAM or group membership files.

Why this answer

The /etc/sudoers file is the primary configuration file for the sudo command, defining which users or groups can run which commands on which hosts, and whether a password is required. A user with NOPASSWD: ALL in this file can execute any command as root without a password. Therefore, reviewing /etc/sudoers is the correct action to verify the auditor's finding.

Exam trap

SSCP often tests the distinction between authentication files (/etc/passwd, /etc/shadow) and authorization configuration files (/etc/sudoers), so candidates may incorrectly choose /etc/shadow because it relates to passwords, but the question specifically asks about sudo privileges.

How to eliminate wrong answers

Option A is wrong because /etc/shadow stores encrypted password hashes and password aging information for user accounts, not sudo privileges. Option B is wrong because /etc/group defines group memberships but does not specify sudo command permissions or password requirements. Option D is wrong because /etc/passwd contains basic user account information such as UID, GID, home directory, and default shell, but not sudo configuration.

540
MCQeasy

Which of the following encryption algorithms is classified as a symmetric block cipher and is the current standard recommended by NIST, supporting key sizes of 128, 192, and 256 bits?

A.AES
B.RSA
C.3DES
D.ChaCha20
AnswerA

AES is a symmetric block cipher operating on 128-bit blocks, with key sizes of 128, 192, and 256 bits, exactly matching the stem's requirements. NIST adopted it as the current standard (FIPS 197), replacing DES and 3DES. Its substitution-permutation network resists linear and differential cryptanalysis far better than legacy ciphers.

Why this answer

AES (Advanced Encryption Standard) is a symmetric block cipher that encrypts data in fixed 128-bit blocks and is the current standard recommended by NIST (FIPS 197). It supports key sizes of 128, 192, and 256 bits, making it the correct answer for a symmetric block cipher with those specific key lengths.

Exam trap

Candidates often confuse symmetric with asymmetric algorithms, or mistakenly think 3DES is still the current standard. In the SSCP exam, remember that AES is the only symmetric block cipher recommended by NIST that supports 128, 192, and 256-bit keys.

How to eliminate wrong answers

Option B (RSA) is wrong because it is an asymmetric (public-key) cipher, not a symmetric block cipher, and it does not use fixed block sizes or the specified key sizes. Option C (3DES) is wrong because, while it is a symmetric block cipher, it is deprecated by NIST due to its small 64-bit block size and slow performance, and it supports key sizes of 56, 112, or 168 bits, not 128, 192, or 256 bits. Option D (ChaCha20) is wrong because it is a stream cipher, not a block cipher, and although it is a symmetric algorithm, it does not use the specified key sizes in the context of a block cipher standard.

541
MCQmedium

A security analyst is reviewing the organization's disaster recovery plan and notices that the Recovery Time Objective (RTO) for a critical application is 2 hours, but the current recovery process takes 8 hours. Which of the following should the analyst recommend FIRST?

A.Accept the risk and document the deviation.
B.Increase the RTO to 8 hours to match the current capability.
C.Purchase a new disaster recovery site.
D.Implement additional automation to reduce recovery time.
AnswerD

The RTO is not being met, so the first step is to improve the recovery process to meet the objective. Automation can significantly reduce manual steps and speed up recovery. Other options like increasing the RTO or accepting the risk might be considered later, but the initial recommendation should be to close the gap by enhancing the process. This aligns with continuous improvement in disaster recovery planning.

Why this answer

When the actual recovery time exceeds the RTO, the priority is to improve the recovery process to meet the business requirement. Automation can reduce manual effort and errors, speeding up recovery. Adjusting the RTO or accepting risk should only be considered after attempting to meet the objective.

Purchasing new infrastructure is a last resort and may not address process inefficiencies.

Exam trap

The trap here is thinking that changing the RTO is the solution, but the RTO is a business requirement that should be met.

542
MCQhard

In a Bell-LaPadula model implementation, a user with a Secret clearance attempts to read a document classified as Top Secret. Additionally, they try to write to a document classified as Unclassified. What are the results of these actions?

A.Read denied, write allowed
B.Read allowed, write allowed
C.Read denied, write denied
D.Read allowed, write denied
AnswerC

Reading is blocked by the no-read-up property, since Secret clearance cannot access Top Secret data. Writing is blocked by the no-write-down property, which prevents a Secret subject from leaking information to an Unclassified object. Both Bell-LaPadula constraints are therefore satisfied, denying each action.

Why this answer

Under Bell-LaPadula, the Simple Security Property (no read up) denies a Secret-cleared user from reading a Top Secret document. The *-Property (no write down) denies the same user from writing to an Unclassified document. Therefore, both the read and the write are denied.

Exam trap

SSCP often tests the direction of Bell-LaPadula rules — the trap is mixing up 'no read up' and 'no write down' with Biba's integrity rules, leading candidates to incorrectly allow the write down.

How to eliminate wrong answers

Option A is wrong because it incorrectly allows the write down to Unclassified, violating the *-Property. Option B is wrong because it allows both the read up (violating the Simple Security Property) and the write down (violating the *-Property). Option D is wrong because it allows the read up to Top Secret, which violates the Simple Security Property.

543
MCQeasy

Which of the following is a common defense against ARP spoofing attacks on a local area network?

A.DHCP snooping
B.Port security
C.MAC filtering
D.Dynamic ARP Inspection
AnswerD

Dynamic ARP Inspection intercepts ARP packets on untrusted switch ports and validates each against the DHCP snooping binding table, discarding forged replies that map an attacker's MAC to another host's IP. This directly satisfies the stem's requirement for a LAN-level defence, preventing the cache poisoning that enables man-in-the-middle interception.

Why this answer

Dynamic ARP Inspection (DAI) validates ARP packets on a per-port basis by comparing IP-to-MAC bindings against a trusted DHCP snooping database, dropping ARP packets with invalid bindings. This directly prevents ARP spoofing/poisoning attacks by ensuring only legitimate ARP replies are accepted on untrusted ports.

Exam trap

SSCP often tests the distinction between DHCP snooping (filters DHCP) and DAI (filters ARP), so candidates who see 'ARP spoofing' and pick DHCP snooping because it builds the binding table miss that DAI is the enforcement mechanism.

How to eliminate wrong answers

Option A is wrong because DHCP snooping builds the trusted binding table used by DAI but does not itself inspect or block malicious ARP packets — it only filters DHCP messages. Option B is wrong because port security limits the number of MAC addresses per port and can mitigate MAC flooding, but it does not validate ARP payloads or IP-to-MAC bindings. Option C is wrong because MAC filtering restricts which MAC addresses can connect to a port or AP, but an attacker can spoof a permitted MAC and still send forged ARP replies.

544
MCQeasy

During a security assessment, you discover that a Windows server has the Telnet service running. Which of the following is the BEST action to harden the server against this finding?

A.Configure a host-based firewall to allow Telnet only from specific IPs
B.Enable encryption on Telnet
C.Remove the Telnet service and use SSH instead
D.Audit Telnet connections in Event Viewer
AnswerC

Telnet transmits credentials and session data in cleartext, so any network observer can capture them. Removing the service eliminates that exposure, while SSH provides encrypted, authenticated remote administration. Disabling or firewalling Telnet leaves the insecure service installed and re-enableable.

Why this answer

The best action is to remove Telnet and use SSH instead because Telnet transmits data, including credentials, in cleartext, making it inherently insecure. SSH provides encrypted communication, eliminating the vulnerability. Removing the service also reduces the attack surface.

Exam trap

SSCP often tests the misconception that restricting or monitoring Telnet makes it secure, when the fundamental flaw is lack of encryption, so replacement with SSH is the only proper hardening.

How to eliminate wrong answers

Option A is wrong because restricting Telnet by IP still leaves it unencrypted and vulnerable to interception; it does not address the core insecurity. Option B is wrong because Telnet does not support encryption natively; enabling encryption would require a different protocol like SSH. Option D is wrong because auditing Telnet connections is a detective measure, not a hardening action; it does not prevent exploitation.

545
MCQeasy

Which of the following is a secure remote access VPN protocol that uses TLS for encryption and is commonly used with Cisco AnyConnect?

A.IPsec
B.SSL/TLS VPN
C.L2TP/IPsec
D.PPTP
AnswerB

SSL/TLS VPN tunnels traffic over port 443, so it traverses firewalls that block IPsec's ESP and IKE ports. Cisco AnyConnect is Cisco's SSL/TLS VPN client, satisfying the stem's requirement for a TLS-encrypted remote access protocol commonly paired with AnyConnect.

Why this answer

An SSL/TLS VPN uses TLS (typically over TCP port 443) to encrypt traffic and is the protocol underlying Cisco AnyConnect, which is a classic example of a client-based SSL VPN. It provides secure remote access without requiring IPsec's UDP ports, making it firewall-friendly.

Exam trap

SSCP often tests the confusion between IPsec and SSL/TLS VPNs — candidates see 'Cisco AnyConnect' and pick IPsec because AnyConnect supports both, missing that the question specifies TLS.

How to eliminate wrong answers

Option A is wrong because IPsec is a separate VPN protocol suite (using IKE on UDP 500/4500 and ESP) and, while AnyConnect can support IPsec/IKEv2, the question specifically asks for the TLS-based protocol. Option C is wrong because L2TP/IPsec combines L2TP tunneling with IPsec encryption — it does not use TLS and is not the protocol behind AnyConnect's SSL mode. Option D is wrong because PPTP is an obsolete, insecure protocol (broken MS-CHAPv2, no strong encryption) and is not TLS-based.

546
MCQeasy

A security administrator is implementing an access control model that assigns permissions based on the clearance of the subject and the classification of the object. Which model is being implemented?

A.Role-Based Access Control (RBAC)
B.Discretionary Access Control (DAC)
C.Attribute-Based Access Control (ABAC)
D.Mandatory Access Control (MAC)
AnswerD

Mandatory Access Control enforces access decisions through system-assigned labels: each subject holds a clearance and each object a classification, and the operating system compares these to grant or deny access. Because users cannot alter labels or delegate permissions, this satisfies the stem's requirement that permissions derive from clearance and classification rather than owner discretion.

Why this answer

Mandatory Access Control (MAC) is the only model where access decisions are based on comparing the subject's security clearance with the object's classification label, as defined by a central authority. In MAC, the system enforces these labels and users cannot alter them, making it mandatory rather than discretionary. This matches the scenario of assigning permissions based on clearance and classification, which are core components of MAC (e.g., Bell-LaPadula or Biba models).

Exam trap

SSCP often tests the confusion between MAC and DAC, where candidates might think that any access control based on labels is discretionary, but the key differentiator is that MAC is system-enforced and non-discretionary, while DAC allows owner discretion.

How to eliminate wrong answers

Option A is wrong because RBAC assigns permissions based on roles within an organization, not on clearance and classification labels. Option B is wrong because DAC allows the owner of an object to determine access, which is discretionary and not based on system-wide clearance/classification. Option C is wrong because ABAC uses a combination of attributes (e.g., user, resource, environment) to make decisions, but it does not inherently rely on clearance and classification labels as the primary basis, and it is more granular and policy-driven.

547
MCQmedium

A system administrator notices that a user's account has been locked out multiple times within an hour. The admin reviews the logs and finds repeated failed login attempts from an unusual IP address. What is the BEST immediate action to mitigate further risk?

A.Disable the user account
B.Delete the failed login log entries
C.Implement a firewall rule to block the IP address
D.Reset the user's password
AnswerC

Blocking the IP address addresses the external source but does not prevent further use of the compromised account from other IPs.

Why this answer

The account is already locked out from repeated failed login attempts, so disabling it does not add protection against the current attack. The BEST immediate action to mitigate further risk is to block the unusual source IP address (Option C), which stops the ongoing attack at the network level. While an attacker could change IPs, blocking the known malicious source is the most direct and effective immediate mitigation.

Disabling the account (Option A) is redundant given the lockout and does not address the source of the attack.

Exam trap

SSCP often tests the difference between addressing the immediate attack vector (block the source IP) and taking redundant account actions. Candidates may pick 'disable the account' because it feels like a strong containment step, but the account is already locked out, making that action ineffective against the ongoing attack.

How to eliminate wrong answers

Option B is wrong because deleting log entries destroys forensic evidence and is unethical/illegal in many contexts — it does not mitigate risk. Option C is wrong because a firewall rule blocking one IP is a partial mitigation that can be bypassed via IP rotation or spoofing, and it does not protect the account from other sources. Option D is wrong because resetting the password does not stop the ongoing attack and may lock out the legitimate user further; disabling the account is the stronger immediate containment.

548
MCQmedium

A network administrator notices that legitimate clients are unable to obtain IP addresses from the DHCP server. The network logs show a high volume of DHCP Discover messages from different MAC addresses. Which attack is most likely occurring?

A.DHCP starvation
B.DHCP spoofing
C.ARP spoofing
D.DNS amplification
AnswerA

DHCP starvation floods the server with Discover messages using spoofed source MAC addresses, exhausting the available address pool. Legitimate clients then receive no offer, matching the observed high volume of Discover traffic from many different MAC addresses.

Why this answer

DHCP starvation occurs when an attacker floods the DHCP server with Discover requests using spoofed MAC addresses, exhausting the DHCP address pool. Legitimate clients then cannot obtain leases because the server has no available IPs to offer. The high volume of Discover messages from many different MAC addresses is the signature of this attack.

Exam trap

The trap is confusing starvation with spoofing — both involve DHCP and an attacker, but starvation exhausts the pool (denial of service) while spoofing redirects clients to a rogue server (MITM); the 'high volume of Discover from different MACs' clue points to starvation.

How to eliminate wrong answers

Option B is wrong because DHCP spoofing involves a rogue DHCP server responding to client requests with malicious gateway/DNS settings — it does not exhaust the pool or prevent legitimate clients from getting addresses from the real server. Option C is wrong because ARP spoofing poisons ARP caches to redirect traffic (MITM), which does not consume DHCP leases or block DHCP allocation. Option D is wrong because DNS amplification is a reflection/amplification DDoS attack using open DNS resolvers to flood a victim with responses — it has nothing to do with DHCP pool exhaustion.

549
MCQmedium

A security team is conducting a lessons learned meeting after a major security incident. The team identifies that the incident response plan was not followed because team members were unsure of their roles. Which of the following should be the PRIMARY outcome of this meeting to address the issue?

A.Outsource all incident response activities to a third-party provider.
B.Purchase a new SIEM solution to improve detection capabilities.
C.Immediately terminate the employees who failed to follow the plan.
D.Update the incident response plan with clearer role definitions and provide additional training.
AnswerD

The lessons learned meeting should result in actionable improvements. If roles were unclear, updating the plan to define responsibilities and training personnel accordingly directly addresses the root cause. This ensures future responses are more effective and aligns with the post-incident activity phase of NIST SP 800-61, which emphasizes revising policies and procedures based on findings.

Why this answer

The primary outcome of a lessons learned meeting is to identify improvements and implement changes to prevent recurrence. Since the issue was unclear roles, updating the incident response plan with clear role definitions and providing training directly addresses the deficiency. This aligns with best practices for continuous improvement in incident response.

Exam trap

The trap here is focusing on punitive actions or technology purchases instead of the root cause, which is a process and people issue that requires clear role definition and training.

550
MCQmedium

A security operations center uses Nessus to scan its internal network nightly. A newly deployed web server is reporting a critical TLS vulnerability, but the vulnerability analyst confirms the server is configured to negotiate only TLS 1.3 with approved cipher suites. The scanner plugin was last updated eight weeks ago. Which action should the analyst take FIRST to resolve the discrepancy?

A.Escalate the finding to the change advisory board as a confirmed critical risk requiring emergency patching.
B.Accept the risk for the web server and document the exception because TLS 1.3 is enabled.
C.Disable the TLS-related plugin family on the scanner so the server stops generating noisy findings.
D.Update the Nessus plugins and credentials, then rescan the host to validate the finding before acting.
AnswerD

An eight-week-old plugin set can produce false positives because detection logic for TLS versions and cipher negotiation changes frequently. Refreshing plugins and ensuring credentialed scanning lets the scanner inspect the true negotiated protocol and cipher list rather than inferring from a banner or stale signature. Validating before remediation prevents wasted patching effort and preserves trust in the vulnerability management process.

Why this answer

Stale scanner content is a common source of false positives, especially for protocol and cipher detection where vendor logic evolves quickly. Before treating the TLS finding as real, the analyst should refresh plugins, confirm credentials work, and rescan so the scanner evaluates the actual negotiated protocol and cipher suites. Only validated findings should be escalated, suppressed, or formally accepted as risk.

Exam trap

The trap here is assuming a scanner finding is authoritative and jumping straight to remediation or risk acceptance instead of validating the scan data first.

551
MCQmedium

A financial services firm has just contained a ransomware incident on a file server. The incident response plan requires a formal post-incident activity phase. The CISO wants to know what the team should do FIRST to improve future response. Which action best aligns with NIST SP 800-61 post-incident activity?

A.Update the incident response plan with new detection signatures based on the ransomware variant.
B.Immediately reimage the server and restore data from the most recent backup.
C.Conduct a lessons learned meeting with all involved parties to review the incident timeline and response actions.
D.Notify the board of directors and external regulators about the incident.
AnswerC

NIST SP 800-61 identifies lessons learned as a key post-incident activity. A meeting with stakeholders reviews what happened, what worked, and what needs improvement. This directly addresses the CISO's goal of improving future response by capturing insights while details are fresh. It should occur before final recovery changes obscure the timeline, making it the correct first action.

Why this answer

NIST SP 800-61 defines post-incident activity as including lessons learned to improve future response. Holding a lessons learned meeting with involved parties captures what happened, what was effective, and what needs improvement. This should occur before recovery actions or plan updates, because the team's memory is freshest and evidence is still available.

The other actions are either recovery steps or communication tasks that do not directly fulfill the improvement goal.

Exam trap

The trap here is assuming that technical fixes like reimaging or signature updates constitute post-incident improvement, when NIST SP 800-61 prioritizes a lessons learned review first.

552
Multi-Selectmedium

Which TWO are benefits of network segmentation using VLANs? (Choose two.)

Select 2 answers
A.Increased available bandwidth
B.Improved security through traffic isolation
C.Reduced broadcast traffic
D.Elimination of routing requirements
E.Simplified IP address management
AnswersB, C

VLANs logically partition a switched network, so broadcast domains and traffic are confined to each segment. Hosts on separate VLANs cannot communicate directly without a router or firewall, limiting lateral movement and satisfying the segmentation requirement.

Why this answer

Option B is correct because VLANs logically isolate groups of devices into separate broadcast domains, so traffic from one VLAN cannot reach another without an explicit Layer 3 device (router or Layer 3 switch) applying ACLs or firewall rules, which improves security through traffic isolation. Option C is correct because each VLAN forms its own broadcast domain, so broadcasts (e.g., ARP requests) are confined to the originating VLAN instead of flooding the entire flat network, thereby reducing overall broadcast traffic. Option A is not a guaranteed benefit: VLANs do not inherently increase bandwidth, and inter-VLAN traffic must still traverse a router or Layer 3 switch, which can even become a bottleneck.

Option D is wrong because VLANs actually require Layer 3 routing (router-on-a-stick or an SVI on a multilayer switch) for hosts in different VLANs to communicate. Option E is wrong because IP address management is not simplified by VLANs alone; it typically requires DHCP scopes per VLAN/subnet and careful subnet planning, and can become more complex with many VLANs.

Exam trap

ISC2 often tests the misconception that VLANs increase bandwidth, when in fact they only reduce unnecessary traffic (like broadcasts) but do not add physical throughput.

553
MCQhard

A forensic analyst needs to review security events from multiple Windows servers. To ensure that logs are centrally collected and resistant to tampering, which of the following should be implemented?

A.Use Windows Event Forwarding to a central event collector
B.Store logs only on the local server and back them up weekly
C.Configure Event Viewer on each server to overwrite events as needed
D.Enable auditing of account logon events
AnswerA

Windows Event Forwarding uses the WS-Management protocol to push events from source servers to a central collector, where they are stored on a separate host. This centralisation means an attacker compromising one server cannot alter or delete the forwarded copies.

Why this answer

Windows Event Forwarding (WEF) uses the WS-Management/WinRM protocol to push selected event logs from source servers to a central Windows Event Collector (WEC) server. Because events are forwarded in near real time to a separate host, an attacker who compromises a source server cannot easily erase the already-forwarded copies, satisfying the tamper-resistance requirement. It also centralizes review, which is what the forensic analyst needs across multiple servers.

Exam trap

The trap is that candidates equate 'enable auditing' (Option D) with 'centralize and protect logs' — auditing generates events but does nothing to aggregate or harden them, which is the actual requirement.

How to eliminate wrong answers

Option B is wrong because storing logs only locally and backing them up weekly leaves a window in which an attacker can clear or alter the local Security log (event ID 1102) before the backup runs, and weekly backups are not tamper-resistant. Option C is wrong because configuring Event Viewer to overwrite events as needed destroys forensic evidence by design — log retention is reduced, not improved. Option D is wrong because enabling auditing of account logon events only generates the events; it does not collect or protect them centrally, so it addresses generation, not aggregation or integrity.

554
MCQeasy

Which access control model allows the owner of a resource to grant access permissions to other users?

A.RBAC (Role-Based Access Control)
B.DAC (Discretionary Access Control)
C.MAC (Mandatory Access Control)
D.ABAC (Attribute-Based Access Control)
AnswerB

Discretionary Access Control lets the resource owner decide who receives permissions, satisfying the owner-grant constraint. Access rights are assigned at the owner's discretion via ACLs, unlike MAC or RBAC where policy or roles govern assignment.

Why this answer

DAC (Discretionary Access Control) is defined by the resource owner having discretion to grant or revoke access to other subjects, typically via ACLs or Unix file permissions. The owner decides who gets access, which is the defining characteristic of discretionary control. This is contrasted with MAC, where the system enforces access based on labels and clearances, not owner choice.

Exam trap

SSCP often tests the confusion between DAC (owner-controlled) and RBAC (role-controlled), so candidates pick RBAC when the question emphasizes 'owner grants access.'

How to eliminate wrong answers

Option A is wrong because RBAC grants access based on the user's role within the organization, not on the resource owner's discretion. Option C is wrong because MAC enforces access via system-assigned labels and clearances (e.g., Bell-LaPadula, Biba), removing owner discretion entirely. Option D is wrong because ABAC evaluates attributes (user, resource, environment) via policy, not owner-granted permissions.

555
Multi-Selectmedium

During a virtualized environment security assessment, which THREE of the following are considered risks associated with virtual machine snapshots? (Select three.)

Select 3 answers
A.Snapshots may contain unpatched vulnerabilities
B.Sensitive data may persist in snapshots
C.Snapshots cause VM sprawl
D.Snapshots can be used to roll back security configurations
E.Snapshots can be used as an attack vector for VM escape
AnswersA, B, D

Snapshots capture the full VM state, including the guest OS and installed software, at the moment of creation. Restoring one reinstates that captured image, so any patches applied afterwards are lost, reintroducing the unpatched vulnerabilities the snapshot preserved. This directly satisfies the stem's requirement that snapshots constitute a risk.

Why this answer

Option A is correct because a snapshot captures the VM's disk state at a point in time, including the guest OS and installed applications; if that state predates patching, restoring or mounting the snapshot reintroduces unpatched vulnerabilities into the environment. Option B is correct because snapshots preserve the full contents of the virtual disks (and often memory state), so credentials, keys, and other sensitive data that were later deleted or rotated can persist inside snapshot files such as .vmdk delta disks or .avhd files. Option D is correct because rolling back to a snapshot reverts the entire VM state, including security settings, firewall rules, group policies, and patch levels, potentially undoing hardening or remediation performed after the snapshot was taken.

Option C is not a snapshot-specific risk; VM sprawl refers to the uncontrolled proliferation of VMs, not snapshot files, and is a lifecycle/governance issue rather than an inherent snapshot risk. Option E is not correct because VM escape exploits hypervisor or virtualization-layer vulnerabilities, not snapshots themselves; snapshots are a data-exposure and rollback concern, not a mechanism for escaping the VM boundary.

Exam trap

SSCP often tests the distinction between snapshot-specific risks and broader virtualization risks like VM sprawl or VM escape, causing candidates to select plausible but incorrect options.

556
MCQmedium

A security administrator is implementing a biometric access control system for a data center. The organization wants to minimize the chance that an unauthorized person is granted access, even if it means legitimate users occasionally have to retry. Which metric should the administrator tune to achieve this goal?

A.Crossover Error Rate (CER)
B.False Acceptance Rate (FAR)
C.False Rejection Rate (FRR)
D.Equal Error Rate (EER)
AnswerB

FAR measures the likelihood that an unauthorized user is incorrectly accepted. By tuning the system to lower the FAR, the administrator reduces the chance of granting access to impostors. This aligns with the goal of minimizing unauthorized access, even at the cost of more frequent retries by legitimate users, which would increase the False Rejection Rate.

Why this answer

The goal is to minimize unauthorized access, which means reducing the False Acceptance Rate. Lowering FAR makes the system stricter, accepting fewer impostors, though it may increase false rejections. CER and EER represent balanced points and do not prioritize security, while FRR relates to rejecting legitimate users, which is not the primary concern here.

Exam trap

The trap here is confusing FAR with FRR, or assuming that CER/EER is always the optimal setting, when the scenario explicitly prioritizes security over convenience.

557
MCQeasy

Which of the following is a key principle of the 3-2-1 backup rule?

A.Two copies on three different media types with one onsite
B.One copy on two different media types with three offsite
C.Three copies on two different media types with one offsite
D.Three copies on three different media types with two offsite
AnswerC

The rule mandates three total copies of data, stored across two distinct media types, with one copy held offsite. That separation protects against simultaneous loss: a single media failure, theft or site disaster cannot destroy every copy at once.

Why this answer

The 3-2-1 backup rule is a foundational data protection strategy: maintain three copies of your data (one primary and two backups), store them on two different media types (e.g., disk and tape, or local SSD and cloud object storage), and ensure at least one copy is stored offsite to protect against site-level disasters. Option C correctly captures this: three copies, two media types, one offsite.

Exam trap

The trap here is that candidates often misremember the numbers, confusing the '3' copies with '3' media types or '2' offsite, leading them to select options like A or D that sound plausible but violate the exact 3-2-1 structure.

How to eliminate wrong answers

Option A is wrong because it states 'two copies on three different media types with one onsite' — the rule requires three copies, not two, and only two different media types, not three. Option B is wrong because it says 'one copy on two different media types with three offsite' — the rule mandates three copies total, with only one offsite, not three offsite. Option D is wrong because it specifies 'three copies on three different media types with two offsite' — the rule requires only two different media types, not three, and only one offsite copy, not two.

558
MCQmedium

A financial services firm's incident response team has just contained a malware outbreak on a file server. The server contains regulated customer data. The team lead instructs the responder to capture the current state of the system before any remediation. According to NIST SP 800-61, which action should the responder take FIRST to preserve the most volatile evidence?

A.Dump the contents of RAM and capture active network connections.
B.Export the server's event logs to a remote syslog server.
C.Capture a forensic image of the server's hard drive using a write blocker.
D.Document the server's physical location and hardware configuration.
AnswerA

RAM contents, running processes, and active network connections are the most volatile evidence and are lost when the system is powered off or rebooted. NIST SP 800-61 recommends collecting these first during the containment phase. Capturing memory and network state preserves indicators such as injected code, encryption keys, and command-and-control sessions before any remediation disrupts them.

Why this answer

The order of volatility dictates that the most transient evidence be collected first. RAM contents, running processes, and active network connections disappear when a system is powered down or rebooted, so they must be captured before disk imaging, log export, or physical documentation. This aligns with NIST SP 800-61 guidance to preserve volatile data during containment.

Exam trap

The trap here is assuming that disk imaging always comes first because it is the most familiar forensic step, when in fact volatile memory and network state must be captured before any shutdown or reboot.

559
MCQeasy

A small business wants to let visitors use its guest Wi-Fi without exposing internal servers. The visitors must reach the internet only, while employees keep using the corporate SSID. Which design best isolates guest traffic from the internal network?

A.Enable MAC filtering on the guest access points so only registered visitor devices may associate
B.Keep guests on the corporate SSID but enable client isolation so wireless clients cannot talk to each other
C.Place guest clients on a separate VLAN whose only permitted path is to the internet gateway, with ACLs blocking access to internal subnets
D.Configure the guest SSID to use WPA3-Personal with a strong passphrase and rotate it monthly
AnswerC

A dedicated guest VLAN creates a distinct Layer 2 broadcast domain, and ACLs on the router or firewall restrict that VLAN to internet-bound traffic only. Because guest frames never share a segment with corporate hosts and routing rules deny internal destinations, a compromised visitor device cannot reach internal servers. This directly matches the requirement while keeping employee traffic untouched.

Why this answer

Guest isolation requires separating traffic at Layer 2 and controlling it at Layer 3. A dedicated VLAN removes guests from the corporate broadcast domain, and ACLs or firewall rules that permit only internet-bound flows prevent lateral movement to internal servers. Encryption, client isolation, and MAC filtering affect who may join or talk to peers, but none of them keeps an associated guest away from internal subnets.

Exam trap

The trap here is equating wireless client isolation with network segmentation, when isolation only blocks station-to-station traffic on the same SSID.

560
MCQmedium

During a risk assessment, a company identifies that a legacy system cannot be patched due to vendor end-of-life. The system is critical to operations. Which risk response strategy is most appropriate initially?

A.Avoid the risk by decommissioning the system immediately
B.Transfer the risk by purchasing cyber insurance
C.Accept the risk without any further action
D.Mitigate the risk by implementing compensating controls
AnswerD

Compensating controls such as network segmentation or strict access restrictions reduce the likelihood or impact of exploitation on the unpatched legacy system, which is mitigation. Avoidance would mean decommissioning a system the stem states is critical to operations.

Why this answer

When a legacy system cannot be patched due to vendor end-of-life, the most appropriate initial risk response is to implement compensating controls. Compensating controls, such as network segmentation, strict access controls, or an intrusion detection system, reduce the likelihood or impact of exploitation without requiring a patch. This approach balances operational necessity with security, as immediate decommissioning (avoidance) may be infeasible for a critical system.

Exam trap

The trap here is that candidates often confuse risk acceptance with passive inaction, but the SSCP exam expects that acceptance must be a deliberate decision with documented justification and often paired with compensating controls, not simply ignoring the risk.

How to eliminate wrong answers

Option A is wrong because decommissioning a critical system immediately would disrupt operations, and risk avoidance is not appropriate when the system is essential to business functions; the goal is to manage risk, not eliminate it at the cost of operations. Option B is wrong because transferring risk via cyber insurance does not reduce the technical vulnerability; it only provides financial compensation after a breach, which does not address the immediate security gap. Option C is wrong because accepting the risk without any further action is negligent; while acceptance is a valid strategy, it requires documented understanding and often compensating controls, not passive inaction.

561
Multi-Selectmedium

A security analyst is hardening a web application that stores user-uploaded images. The application currently writes uploads to a directory served directly by the web server. Which TWO controls BEST reduce the risk of a malicious upload leading to remote code execution? (Choose two.)

Select 2 answers
A.Validate the file's magic bytes and extension against an allowlist of permitted image formats.
B.Log every upload event with the client IP address and user agent for later review.
C.Store uploaded files outside the web root and serve them through a handler that sets Content-Type and Content-Disposition.
D.Increase the PHP upload_max_filesize directive to accommodate large images.
E.Rename each uploaded file to a random UUID while keeping the original extension.
AnswersA, C

Checking magic bytes and enforcing an extension allowlist ensures the file's actual content matches an expected image type, blocking polyglot files and scripts disguised with image extensions. This directly prevents a PHP or JSP payload from being accepted as a JPEG, which is a prerequisite for the upload-to-RCE chain described in the scenario.

Why this answer

Preventing upload-based remote code execution requires both validating that the content is genuinely an allowed image type and ensuring stored files can never be interpreted as executable code. Content inspection and an extension allowlist establish the first barrier, while storing files outside the web root with safe response headers removes the execution path entirely.

Exam trap

The trap here is treating operational hygiene such as filename randomization or logging as sufficient prevention, when the decisive controls are content validation and removing the file from any executable path.

562
MCQeasy

Which of the following is the primary purpose of network segmentation?

A.Increase bandwidth
B.Improve network performance
C.Simplify IP address management
D.Enhance security by isolating sensitive systems
E.Reduce hardware cost
AnswerD

Segmenting a network places sensitive systems in separate zones behind controlled conduits, so lateral movement after a breach is contained. This directly satisfies the stem's isolation constraint, limiting blast radius rather than merely boosting throughput or simplifying addressing.

Why this answer

The primary purpose of network segmentation is to enhance security by isolating sensitive systems and limiting lateral movement of threats. Option D is correct. Option A is incorrect because segmentation does not directly increase bandwidth.

Option B is incorrect; while performance may improve due to reduced broadcast domains, security is the primary goal. Option C is incorrect because segmentation can complicate IP address management. Option E is incorrect because segmentation often increases hardware cost.

563
MCQmedium

A healthcare organization uses a mandatory access control (MAC) system to protect patient records. A nurse with a Secret clearance attempts to access a file classified as Top Secret. According to the Bell-LaPadula model, what will happen?

A.The access will be allowed but the nurse will be required to sign an additional non-disclosure agreement.
B.The access will be denied because the nurse's clearance is lower than the file's classification.
C.The access will be denied because the nurse does not have Top Secret clearance, but the nurse can request a temporary upgrade.
D.The access will be allowed because the nurse has a legitimate need to know for patient care.
AnswerB

The Bell-LaPadula model enforces the no-read-up property: a subject cannot read an object with a higher sensitivity level. Since the nurse has Secret clearance and the file is Top Secret, the read is denied. This prevents unauthorized disclosure of classified information and is a core rule of MAC.

Why this answer

The Bell-LaPadula model is a mandatory access control model designed to protect confidentiality. Its no-read-up property states that a subject cannot read an object with a higher classification than the subject's clearance. Therefore, a nurse with Secret clearance cannot read a Top Secret file.

The other options either misunderstand the need-to-know principle, incorrectly assume that an NDA or temporary upgrade can bypass the rule, or misstate the model's behavior.

Exam trap

The trap here is confusing need to know with clearance level, assuming that a legitimate need to know can override the mandatory no-read-up rule.

564
Multi-Selecthard

A risk analyst is building a threat model for a new customer-facing web application. The analyst must identify threat sources and classify them appropriately. Which TWO of the following are examples of environmental or natural threat sources that should be documented in the risk assessment? (Choose two.)

Select 2 answers
A.A disgruntled former employee who retains knowledge of internal application architecture.
B.A prolonged power outage affecting the cloud region where the application is deployed.
C.An organized criminal group targeting the application for financial fraud.
D.A regional flood that could inundate the primary data center hosting the application.
E.An unstructured software error in a third-party payment library that causes data corruption.
AnswersB, D

Power loss is an environmental threat source, whether caused by grid failure or weather. It threatens availability of the application and its supporting infrastructure, so it must be documented alongside human threats. Mitigations include uninterruptible power supplies, generator testing, and multi-region failover.

Why this answer

Natural and environmental threat sources originate in the physical world and affect assets regardless of human intent. Flooding and extended power loss both threaten the web application's availability and supporting infrastructure, so they must be documented in the risk assessment to justify continuity, redundancy, and recovery investments.

Exam trap

The trap here is mixing human and technical threat sources into the environmental category, when only naturally occurring physical events qualify.

565
MCQeasy

During a risk assessment, the team identifies that a critical database server is not included in the backup schedule. Which risk term best describes this condition?

A.Threat
B.Risk
C.Exploit
D.Vulnerability
AnswerD

A vulnerability is a weakness or gap that a threat could exploit; the missing backup coverage is precisely such a weakness in the database server's protective controls. It is not a threat (no actor or event) nor a risk (no combined likelihood/impact), so it correctly names the condition itself.

Why this answer

A vulnerability is a weakness in a system that can be exploited by a threat. The database server missing from the backup schedule represents a weakness in the organization's data protection and disaster recovery posture, making it susceptible to data loss. This absence of a control (backup) is a classic example of a vulnerability, not an active threat or an exploit.

Exam trap

ISC2 often tests the distinction between a vulnerability (a weakness) and a threat (a potential danger), tricking candidates into selecting 'Threat' because they associate the missing backup with a potential data loss event, rather than recognizing it as the underlying weakness.

How to eliminate wrong answers

Option A is wrong because a threat is a potential event or actor (like a ransomware attack or a natural disaster) that could cause harm, not the absence of a backup. Option B is wrong because risk is the potential for loss or damage when a threat exploits a vulnerability; the missing backup is the vulnerability itself, not the calculated risk. Option C is wrong because an exploit is a specific method or code used to take advantage of a vulnerability (e.g., a SQL injection payload), not the condition of being unbacked.

566
MCQmedium

A company wants to implement a firewall that can track the state of network connections and make decisions based on the context of traffic (e.g., allowing return packets for an established connection). Which type of firewall should they choose?

A.Application proxy firewall
B.Stateless packet filter
C.Next-generation firewall
D.Stateful firewall
AnswerD

A stateful firewall maintains a connection state table, tracking each session's source, destination and sequence so return packets for established connections are permitted automatically. This context-aware inspection satisfies the requirement, unlike stateless packet filtering, which evaluates each packet in isolation.

Why this answer

A stateful firewall tracks the state of network connections in a state table, allowing return packets for established sessions without requiring explicit inbound rules. This context-aware behavior is exactly what the question describes.

Exam trap

SSCP often tests the distinction between stateless packet filters (per-packet ACLs) and stateful firewalls (connection tracking) — the trap is picking NGFW because it sounds more advanced, but the question's defining criterion is state tracking, which is the stateful firewall.

How to eliminate wrong answers

Option A is wrong because an application proxy firewall operates at Layer 7 and brokers application-specific traffic, but the question emphasizes connection state tracking, which is the defining feature of a stateful firewall. Option B is wrong because a stateless packet filter evaluates each packet in isolation against ACLs and cannot track connection state. Option C is wrong because a next-generation firewall (NGFW) includes stateful inspection plus additional features (IPS, application awareness), but the question asks for the type defined by state tracking — stateful firewall is the precise answer.

567
Multi-Selecthard

Which THREE of the following are key steps in performing a business impact analysis (BIA)?

Select 3 answers
A.Assigning likelihood ratings to threats
B.Selecting backup and recovery solutions
C.Assessing the financial and operational impact of disruptions
D.Identifying critical business processes
E.Determining maximum tolerable downtime (MTD)
AnswersC, D, E

Quantifying financial and operational consequences of disruption determines which processes demand priority recovery, directly satisfying the BIA's purpose of measuring impact severity. This step translates outage effects into business terms, feeding RTO and continuity decisions.

Why this answer

A BIA is fundamentally about identifying what the business needs to keep running and what happens if it stops, so option D (identifying critical business processes) is a core step because you must first determine which processes, systems, and functions are essential to delivering products and services. Option C (assessing the financial and operational impact of disruptions) is also central, since the BIA quantifies the consequences of outages in terms of revenue loss, regulatory penalties, customer impact, and operational degradation. Option E (determining maximum tolerable downtime, MTD) belongs because the BIA establishes how long each critical process can be unavailable before the impact becomes unacceptable, which later drives RTO/RPO decisions.

Option A (assigning likelihood ratings to threats) is part of a risk assessment rather than a BIA, which focuses on impact and criticality rather than threat probability. Option B (selecting backup and recovery solutions) is a subsequent recovery-strategy and solution-design activity that follows the BIA, not a step within it.

Exam trap

ISC2 often tests the distinction between BIA steps (impact-focused) and risk assessment steps (likelihood-focused), so candidates mistakenly include threat likelihood ratings as a BIA step.

568
Multi-Selecteasy

A security analyst notices unusual outbound traffic from a server. Which TWO actions should be taken immediately as part of the incident response process?

Select 2 answers
A.Conduct a full vulnerability scan on the system.
B.Isolate the affected system from the network.
C.Reimage the system to remove any malware.
D.Capture memory and network traffic for analysis.
E.Notify law enforcement authorities.
AnswersB, D

Isolating the affected system from the network contains the incident, preventing further data exfiltration or command-and-control communication while preserving the host for investigation. Containment is an immediate priority once unusual outbound traffic confirms possible compromise.

Why this answer

Isolating the affected system (B) prevents further damage or data exfiltration. Capturing memory and network traffic (D) preserves volatile evidence for analysis. Conducting a vulnerability scan (A) is not immediate.

Reimaging (C) is premature before investigation. Notifying law enforcement (E) is not an immediate step.

569
MCQhard

A financial services firm classifies its customer database as its most critical asset. The risk register shows a single entry for "unauthorized database access" with an annualized loss expectancy of $2,000,000. Management approves a database activity monitoring (DAM) solution plus tokenization of account numbers, which reduces the annualized loss expectancy to $300,000. Which of the following BEST describes the $300,000 figure in risk terms?

A.The risk appetite threshold approved by the board for this asset
B.The total cost of ownership of the implemented controls
C.The inherent risk of the database before any controls existed
D.The residual risk remaining after the controls are applied
AnswerD

Residual risk is the expected loss that persists after mitigation. The original annualized loss expectancy was $2,000,000, and the approved controls reduced it to $300,000; that remaining exposure is precisely the residual risk. Recording it lets management compare it against the organization's risk appetite and decide whether further treatment, transfer, or acceptance is warranted.

Why this answer

Annualized loss expectancy quantifies expected yearly loss for a given risk. Applying controls that cut the figure from $2,000,000 to $300,000 leaves $300,000 of expected annual loss still present, which is the residual risk. Documenting that value allows comparison with the organization's risk tolerance and supports decisions about accepting or further treating the remaining exposure.

Exam trap

The trap here is treating any post-control dollar figure as control cost or as inherent risk, when a reduced expected loss is by definition residual risk.

570
MCQmedium

An organization wants to implement an access control model where data owners decide who can access resources. Which model should they choose?

A.Attribute-Based Access Control (ABAC)
B.Mandatory Access Control (MAC)
C.Role-Based Access Control (RBAC)
D.Discretionary Access Control (DAC)
AnswerD

DAC lets the data owner set permissions on each resource, matching the requirement that owners decide access. Unlike MAC or RBAC, control is discretionary and not centrally enforced, so ownership directly governs who may read or modify the resource.

Why this answer

Discretionary Access Control (DAC) is the correct model because it allows data owners (the users who create or own the resource) to decide who can access their resources. In DAC, the owner sets permissions (e.g., read, write, execute) on objects like files or directories, typically using Access Control Lists (ACLs). This directly matches the requirement where data owners control access decisions.

Exam trap

ISC2 often tests the misconception that 'data owners decide' implies a role-based or attribute-based model, but the key distinction is that DAC explicitly grants ownership-based control, while RBAC and ABAC centralize decisions with administrators or policies.

How to eliminate wrong answers

Option A is wrong because Attribute-Based Access Control (ABAC) uses policies based on attributes (e.g., user role, time, location) evaluated by a central policy engine, not by the data owner. Option B is wrong because Mandatory Access Control (MAC) enforces system-wide policies set by a central authority (e.g., security labels like Top Secret), and users (including data owners) cannot override these rules. Option C is wrong because Role-Based Access Control (RBAC) assigns permissions based on predefined roles (e.g., 'Manager'), and access decisions are made by administrators, not by the data owner.

571
Multi-Selecthard

During a post-incident review of a data breach, the incident response team is evaluating the chain of custody for forensic evidence. Which THREE practices demonstrate proper evidence handling? (Choose three.)

Select 3 answers
A.The original hard drive was used directly for analysis to avoid delays.
B.A write blocker was used when creating a forensic image of the disk.
C.MD5 hashes were computed only after the analysis was complete.
D.The forensic image was verified by comparing its hash to the hash of the original disk.
E.Each person who handled the evidence documented their name, date, time, and purpose.
AnswersB, D, E

Using a hardware or software write blocker prevents any modification to the source disk during imaging, preserving its integrity as evidence. This directly satisfies the chain-of-custody requirement that forensic copies be bit-for-bit accurate and unaltered, ensuring the image remains admissible and defensible during the post-incident review.

Why this answer

Option B is correct because a hardware or software write blocker prevents any modification to the original disk during imaging, preserving its integrity and admissibility as evidence. Option D is correct because comparing the hash (e.g., MD5 or SHA-256) of the forensic image to the hash of the original disk proves the image is a bit-for-bit duplicate and has not been altered. Option E is correct because maintaining an unbroken chain of custody requires every handler to record their name, date, time, and purpose of access, ensuring accountability and traceability.

Option A is wrong because analyzing the original drive directly risks altering metadata and destroying evidence; instead, a forensic image should be analyzed. Option C is wrong because hashes must be computed immediately upon acquisition (before analysis) to establish a baseline for integrity verification, not only afterward.

Exam trap

A common trap in this question is the misconception that hashing can be done at any point during the investigation, but integrity verification must occur before analysis begins to establish a baseline, not after the fact.

572
MCQeasy

What is the primary purpose of a Privileged Access Management (PAM) solution?

A.Controlling and monitoring access to privileged accounts
B.Managing user password resets
C.Implementing single sign-on for all applications
D.Enforcing password complexity policies
AnswerA

PAM vaults privileged credentials, brokers sessions and records activity, so administrative access is granted only when required and fully auditable. This directly satisfies the requirement to control and monitor privileged accounts, rather than merely authenticating ordinary users.

Why this answer

A Privileged Access Management (PAM) solution is specifically designed to secure, control, and monitor the use of privileged accounts (e.g., root, administrator, service accounts) that have elevated permissions. It provides features like credential vaulting, session recording, just-in-time access, and approval workflows to prevent misuse and detect malicious activity. Unlike general identity management, PAM focuses on the high-risk accounts that can alter system configurations, access sensitive data, or disrupt operations.

Thus, controlling and monitoring access to privileged accounts is its primary purpose.

Exam trap

SSCP often tests the confusion between PAM and IAM, where candidates might select options related to general user management (like password resets or SSO) instead of recognizing that PAM specifically targets privileged accounts.

How to eliminate wrong answers

Option B is wrong because managing user password resets is a function of self-service password reset tools or identity and access management (IAM) systems, not PAM; PAM may include password rotation for privileged accounts but not general user resets. Option C is wrong because implementing single sign-on (SSO) for all applications is the role of an SSO or federated identity solution, which provides convenience and centralized authentication, whereas PAM focuses on securing privileged access, often with additional controls like session isolation. Option D is wrong because enforcing password complexity policies is typically handled by Group Policy, LDAP directory settings, or IAM platforms; PAM may enforce stronger policies for privileged credentials but its primary purpose is not general password policy enforcement.

573
MCQeasy

An organization uses smart cards combined with a PIN to access secure facilities. This is an example of which type of authentication factor?

A.Token-based authentication
B.Single-factor authentication
C.Two-factor authentication
D.Biometric authentication
AnswerC

A smart card supplies a possession factor, while the PIN supplies a knowledge factor. Combining two different factor categories satisfies two-factor authentication; two passwords or two tokens would not, since they share the same factor type.

Why this answer

Smart cards are a possession factor (something you have), and the PIN is a knowledge factor (something you know). Combining both satisfies the requirement for two distinct authentication factors, making this a textbook example of two-factor authentication (2FA). This is not single-factor because two separate categories of credentials are used, and it is not biometric because no physical characteristic is measured.

Exam trap

The trap here is that candidates often confuse 'something you have' (possession factor) with 'something you know' (knowledge factor) and mistakenly classify the combination as single-factor because they think the smart card alone is the authentication, ignoring that the PIN adds a second distinct factor.

How to eliminate wrong answers

Option A is wrong because token-based authentication typically refers to a device that generates a one-time password (OTP) or cryptographic token, not a smart card with a PIN; while a smart card can be considered a token, the combination with a PIN specifically makes it two-factor, not merely token-based. Option B is wrong because single-factor authentication uses only one category of credential (e.g., just a password or just a smart card), but here both a smart card (possession) and a PIN (knowledge) are required, so it is multi-factor. Option D is wrong because biometric authentication relies on unique physical traits such as fingerprints, iris patterns, or voice recognition, not on a smart card and PIN combination.

574
MCQeasy

According to the shared responsibility model in cloud computing, which security responsibility belongs to the customer in a SaaS deployment?

A.Physical security of data centers
B.Securing the application code
C.Data classification and access controls
D.Managing the underlying operating system
AnswerC

In SaaS, the provider secures the application, runtime and underlying infrastructure, while the customer retains ownership of its data. Classifying that data and controlling who may access it therefore remain customer responsibilities, since only the customer understands its sensitivity and business access requirements.

Why this answer

In the shared responsibility model, the cloud provider always owns security *of* the cloud (physical facilities, hypervisor, host OS, and for SaaS the application itself), while the customer always owns security *in* the cloud — their data, identities, and access decisions. Data classification and access controls are therefore unambiguously customer responsibilities in every cloud service model, including SaaS. This is the one responsibility that never transfers to the provider.

Exam trap

The trap is that candidates assume SaaS means 'the provider secures everything' and pick an option like application code or OS management, forgetting that data and access control always stay with the customer.

How to eliminate wrong answers

Option A is wrong because physical security of data centers is always the cloud provider's responsibility in every deployment model (IaaS, PaaS, SaaS). Option B is wrong because in SaaS the provider develops, hosts, and maintains the application code — the customer only configures and uses it. Option D is wrong because managing the underlying operating system is the provider's job in SaaS and PaaS; it only becomes the customer's responsibility in IaaS.

575
MCQeasy

Refer to the exhibit. Which component of the cipher suite provides perfect forward secrecy?

A.ECDHE
B.TLS 1.2
C.AES256-GCM
D.SHA384
AnswerA

ECDHE is an ephemeral elliptic-curve Diffie-Hellman key exchange. Because a fresh key pair is generated per session and discarded afterwards, compromise of the server's long-term private key cannot decrypt previously captured sessions, which is precisely perfect forward secrecy.

Why this answer

ECDHE (Elliptic Curve Diffie-Hellman Ephemeral) provides perfect forward secrecy (PFS) because it generates a unique, ephemeral session key for each TLS session. If the long-term private key is compromised, past session keys cannot be derived, as the ephemeral keys are discarded after use. This is defined in RFC 4492 and is a core property of ephemeral Diffie-Hellman key exchange.

Exam trap

ISC2 often tests the distinction between the protocol version (TLS 1.2) and the cipher suite components that actually implement PFS, leading candidates to incorrectly select TLS 1.2 because they associate it with modern security features.

How to eliminate wrong answers

Option B (TLS 1.2) is wrong because TLS 1.2 is a protocol version, not a component that provides PFS; it can support PFS if ECDHE or DHE cipher suites are negotiated, but the protocol itself does not guarantee PFS. Option C (AES256-GCM) is wrong because AES256-GCM is a symmetric encryption and authenticated encryption algorithm (AEAD) that protects data confidentiality and integrity, but it does not influence key exchange or provide PFS. Option D (SHA384) is wrong because SHA384 is a hash function used for message authentication in HMAC or for integrity checks in TLS, and it has no role in establishing ephemeral keys or PFS.

576
MCQhard

A security analyst is reviewing a mobile application that stores authentication tokens in a location accessible to other applications on the same device. The development team wants to remediate this finding for both Android and iOS. Which change BEST addresses the vulnerability?

A.Keep tokens in memory only and require reauthentication whenever the application restarts.
B.Store tokens in a shared preferences file with file permissions restricted to the application's user ID.
C.Store tokens in the platform-provided secure storage such as the Android Keystore and iOS Keychain.
D.Encrypt the tokens with a hardcoded symmetric key embedded in the application binary.
AnswerC

Platform secure storage is designed to isolate secrets from other applications and, on supported hardware, to protect them with hardware-backed keys. Moving tokens there prevents other apps from reading them and addresses the finding directly on both platforms. This is the recommended remediation for insecure local storage of credentials or tokens.

Why this answer

The vulnerability is that tokens are readable by other applications. The platform secure storage mechanisms on Android and iOS are purpose-built to isolate secrets, and on capable hardware they can bind keys to the device's secure element. Hardcoded keys, permission-based files, and memory-only approaches either fail under realistic attacks or do not leverage the strongest available protection.

Exam trap

The trap here is accepting application-level encryption with a key embedded in the binary as equivalent to platform secure storage, when the key can be extracted by reverse engineering.

577
Multi-Selecthard

A security team is implementing a vulnerability management program. According to industry best practices, which THREE of the following are essential components of a mature vulnerability management process?

Select 3 answers
A.Manual patch management
B.Quarterly vulnerability scans
C.False positive management process
D.Remediation SLAs based on severity
E.Continuous scanning capability
AnswersC, D, E

A false positive management process is essential because it triages scanner findings that incorrectly flag benign activity, preventing analyst fatigue and wasted remediation effort. Without it, genuine vulnerabilities get buried, so the programme cannot mature or prioritise accurately.

Why this answer

Option C (False positive management process) is essential because scanners inevitably generate findings that are not genuine vulnerabilities, and a mature program must triage, validate, and document these to prevent wasted remediation effort and alert fatigue. Option D (Remediation SLAs based on severity) is correct because best practices such as those in NIST SP 800-40 and CIS Controls require risk-based timeframes (for example, critical vulnerabilities remediated in days versus low-severity in weeks) to prioritize limited resources. Option E (Continuous scanning capability) is correct because mature programs move beyond point-in-time assessments to ongoing discovery and monitoring, enabling timely detection of new vulnerabilities and asset changes.

Option A (Manual patch management) does not belong because mature programs automate patching and configuration management rather than relying on manual processes, which are error-prone and unscalable. Option B (Quarterly vulnerability scans) does not belong because quarterly scanning alone is insufficient and outdated; mature programs scan continuously or at least much more frequently, and quarterly scans are typically only a compliance minimum, not a best-practice component.

Exam trap

A common misconception in vulnerability management is that meeting compliance requirements (e.g., quarterly scans) is sufficient for maturity. However, a mature program requires continuous scanning, remediation SLAs based on severity, and a false positive management process to ensure efficiency and effectiveness.

578
MCQmedium

A security analyst reviews the health dashboard of the organization's Security Information and Event Management (SIEM) platform and notices that event ingestion from the primary domain controllers stopped at 02:00, while all other log sources continue to report normally. Which of the following should the analyst investigate FIRST to determine why domain controller logs are missing?

A.The network firewall rules governing outbound syslog traffic from all monitored hosts
B.The SIEM correlation rules that map domain controller event IDs to alert severity levels
C.The Windows Event Forwarding subscription and the collector service status on the domain controllers
D.The retention and rollover settings on the SIEM storage volumes
AnswerC

Missing events from a single source class while all other sources report normally points to the collection path specific to those hosts. Windows Event Forwarding subscriptions, the Windows Event Collector service, and the source-side forwarding service are the components that deliver domain controller events to the SIEM, so verifying their status and subscription health is the correct first diagnostic step.

Why this answer

When one log source class stops feeding a SIEM while others continue, the fault lies in the collection pipeline unique to that source, not in shared infrastructure. Windows Event Forwarding subscriptions and the Windows Event Collector service are the exact mechanisms that transport domain controller events, so checking subscription health and collector service state isolates the failure quickly before broader troubleshooting.

Exam trap

The trap here is assuming that a monitoring gap means the SIEM platform itself is broken, when a single silent source usually indicates a source-side collection or forwarding failure.

579
MCQeasy

A small business wants employees to authenticate to the corporate VPN using a hardware token that generates a time-based one-time code in addition to their password. Which authentication factor category does the hardware token represent?

A.Something you are
B.Something you know
C.Something you have
D.Somewhere you are
AnswerC

A hardware token that generates time-based one-time codes is a possession factor, meaning the user must physically hold the device to authenticate. Combined with a password, which is a knowledge factor, this creates true multi-factor authentication because it draws on two different categories. The possession factor is exactly what the token contributes in this VPN scenario.

Why this answer

Authentication factors fall into categories including knowledge, possession, inherence, and location. A hardware token that generates time-based one-time codes must be physically held by the user, making it a possession factor. Pairing it with a password, which is a knowledge factor, satisfies multi-factor authentication because two different categories are required, rather than two instances of the same category.

Exam trap

The trap here is counting two credentials from the same category, such as a password plus a security question, as multi-factor authentication when only a single factor category is actually present.

580
Multi-Selectmedium

A security engineer is implementing a Network Access Control (NAC) solution to enforce endpoint compliance before allowing devices onto the corporate network. Which TWO of the following are common NAC enforcement methods? (Choose two.)

Select 2 answers
A.802.1X with RADIUS authentication
B.VLAN hopping prevention
C.MAC address filtering
D.Captive portal with posture assessment
E.DHCP snooping with IP source guard
AnswersA, D

802.1X is a port-based network access control standard that uses RADIUS for authentication. It is a common NAC enforcement method, allowing or denying network access based on credentials and endpoint posture. When a device connects, the switch port remains unauthorized until authentication succeeds. This method is widely used in enterprise NAC deployments to enforce compliance and identity-based access.

Why this answer

Common NAC enforcement methods include 802.1X with RADIUS authentication and captive portals with posture assessment. 802.1X provides port-based access control using authentication, while captive portals redirect users to a web page for authentication and compliance checks. Both methods can enforce endpoint compliance before granting network access. DHCP snooping, VLAN hopping prevention, and MAC filtering are security features but do not provide the identity and posture assessment typical of NAC.

Exam trap

The trap here is assuming that any access control mechanism, such as MAC filtering, qualifies as NAC, but NAC specifically involves authentication and posture assessment.

581
MCQeasy

What is the primary purpose of account deprovisioning?

A.To revoke access and disable accounts when no longer needed
B.To create new user accounts
C.To audit user activity
D.To modify user roles
AnswerA

Deprovisioning removes or disables identities and revokes their entitlements once employment or the business need ends, closing the standing access that could otherwise be abused. It is the lifecycle counterpart to provisioning, not a password or permission review.

Why this answer

Account deprovisioning is the process of removing or disabling user accounts and revoking associated access rights when they are no longer required, such as when an employee leaves the organization or changes roles. The primary goal is to ensure that former users cannot access systems, data, or resources, thereby reducing the attack surface and preventing unauthorized access. This is a fundamental control in identity and access management (IAM) and is required by regulations like SOX, HIPAA, and PCI DSS.

Exam trap

SSCP often tests the distinction between provisioning and deprovisioning, and candidates may confuse deprovisioning with auditing or role changes, leading them to select an incorrect option that describes a related but different IAM function.

How to eliminate wrong answers

Option B is wrong because creating new user accounts is the purpose of account provisioning, not deprovisioning. Option C is wrong because auditing user activity is a monitoring function performed by logging and auditing systems, not the primary purpose of deprovisioning. Option D is wrong because modifying user roles is part of access management or role changes, which may trigger deprovisioning but is not its primary purpose.

582
MCQeasy

A system administrator needs to assign permissions to a new employee who will be performing database backups. The employee should only be able to execute the backup command but not read or modify the data. Which access control principle should be applied?

A.Need to know
B.Least privilege
C.Separation of duties
D.Defense in depth
AnswerB

Least privilege grants only the minimum rights needed to perform the backup task, so the account receives execute permission on the backup command without read or modify rights on the underlying data. This directly satisfies the stem's constraint of execution-only access.

Why this answer

The least privilege principle dictates that a user should be granted only the minimum permissions necessary to perform their job function. In this scenario, the employee needs only the ability to execute the backup command (e.g., using a tool like `pg_dump` or `mysqldump` with a read-only snapshot), not read or modify the underlying data files. Applying least privilege ensures the backup process can run without granting broader SELECT or FILE privileges that would allow data access or alteration.

Exam trap

The trap here is that candidates often confuse 'least privilege' with 'need to know' because both limit access, but least privilege focuses on the minimum permissions to perform an action (execute a command), while need to know focuses on whether the user requires access to specific data content.

How to eliminate wrong answers

Option A is wrong because 'need to know' is a confidentiality principle that restricts access to information based on whether the user requires that specific data to perform their duties, not the minimum permissions to execute a command; it does not address the granularity of execute-only versus read/modify. Option C is wrong because separation of duties divides critical tasks among multiple people to prevent fraud (e.g., the backup operator cannot also restore), but the question is about limiting the backup operator's own permissions, not splitting tasks. Option D is wrong because defense in depth is a layered security strategy using multiple controls (firewalls, IDS, encryption), not a principle for assigning a single user's permissions to a specific command.

583
MCQmedium

A security administrator is reviewing an incident response plan and finds that the team has no agreed way to classify how severe a detected event is before deciding whether to escalate. Which artifact should be created to standardize this decision?

A.A vulnerability management scanning schedule.
B.A memorandum of understanding with the legal department.
C.A service level agreement with the managed security service provider.
D.An incident severity matrix that maps impact and scope to response tiers.
AnswerD

A severity matrix defines levels such as low, medium, high, and critical based on factors like business impact, data sensitivity, and number of affected systems. It gives responders a consistent, repeatable way to decide escalation and notification. Because the gap is inconsistent triage, a documented classification scheme directly resolves the problem and supports metrics reporting.

Why this answer

Consistent incident triage depends on predefined criteria that translate technical indicators and business impact into response tiers. A severity matrix supplies those criteria, so different analysts reach the same escalation decision. It also enables meaningful metrics, since severity levels become comparable across incidents and reporting periods.

Exam trap

The trap here is confusing documents that govern vendor or legal relationships with the operational standard needed to classify incident severity.

584
MCQmedium

A security team is implementing Network Access Control (NAC) to enforce endpoint compliance before granting network access. Which technology allows port-based authentication on wired networks?

A.RADIUS
B.WPA2-Enterprise
C.802.1X
D.MAC filtering
AnswerC

802.1X is the IEEE standard for port-based network access control, authenticating a supplicant via EAP before the switch port grants access. It satisfies the requirement for wired port-based authentication, unlike MAC filtering or captive portals.

Why this answer

802.1X is an IEEE standard for port-based network access control that provides authentication to devices trying to connect to a wired or wireless network. It uses the Extensible Authentication Protocol (EAP) over LAN (EAPOL) to encapsulate authentication messages between the supplicant (client) and the authenticator (switch or access point), which then relays them to an authentication server (typically RADIUS). This ensures that no traffic can pass through the port until the device is authenticated and authorized.

Exam trap

The trap here is confusing the authentication protocol (RADIUS) with the port-based access control mechanism (802.1X); candidates often select RADIUS because it is commonly used in NAC, but the question specifically asks for the technology that enables port-based authentication on wired networks.

How to eliminate wrong answers

Option A is wrong because RADIUS is an authentication, authorization, and accounting (AAA) protocol that verifies credentials but does not itself enforce port-based access control; it works in conjunction with 802.1X. Option B is wrong because WPA2-Enterprise is a wireless security standard that uses 802.1X for authentication but is not a wired port-based authentication technology. Option D is wrong because MAC filtering is a weak access control method that allows or denies based on MAC addresses but does not provide port-based authentication or dynamic authorization.

585
Multi-Selecthard

A security analyst is hardening a wireless network that uses WPA2-Enterprise with a RADIUS server. The analyst wants to mitigate the risk of an attacker setting up a rogue access point to capture user credentials. Which TWO measures should be implemented? (Choose two.)

Select 2 answers
A.Deploy a Wireless Intrusion Prevention System (WIPS) to detect and contain rogue access points.
B.Enable Protected Management Frames (PMF) to prevent deauthentication attacks.
C.Use a preshared key (PSK) instead of 802.1X to simplify authentication.
D.Configure 802.1X authentication with EAP-TLS, requiring client certificates.
E.Disable SSID broadcasting to hide the network name.
AnswersA, D

A WIPS monitors the wireless spectrum for unauthorized access points and can automatically contain them by sending deauthentication frames or alerting administrators. This directly mitigates the risk of a rogue AP capturing credentials by identifying and blocking it. It is a proactive measure that addresses the specific threat of rogue access points in the environment.

Why this answer

Deploying a WIPS detects and contains rogue access points, directly addressing the threat. Configuring 802.1X with EAP-TLS ensures mutual authentication, so clients verify the server's certificate and will not connect to a rogue AP. Together, these measures prevent credential harvesting.

PMF, hidden SSIDs, and PSKs do not adequately mitigate the risk of a rogue AP capturing credentials.

Exam trap

The trap here is assuming that hiding the SSID or using PMF is sufficient to prevent rogue access points, when in fact mutual authentication and active monitoring are required.

586
MCQhard

After a patch is deployed to a critical server, the system becomes unstable. The change management plan includes a rollback procedure. What should be done FIRST?

A.Create a new change request for the rollback
B.Conduct a post-implementation review
C.Execute the rollback procedure
D.Notify the Change Advisory Board
AnswerC

Executing the documented rollback restores the unstable server to its last known-good state, immediately containing the outage. The change management plan already authorises this procedure, so it takes precedence over investigation, which can follow once service is restored.

Why this answer

When a patch deployment causes system instability, the immediate priority is to restore service stability by executing the pre-approved rollback procedure. The change management plan already includes this procedure, so no new approvals are needed; acting quickly minimizes downtime and risk.

Exam trap

Candidates may incorrectly think that a new change request is required for the rollback, but the change management plan already includes the rollback procedure, so it can be executed immediately without additional approvals.

How to eliminate wrong answers

Option A is wrong because creating a new change request would introduce unnecessary delay; the rollback is already authorized under the original change plan. Option B is wrong because a post-implementation review is conducted after stability is restored, not during an active incident. Option D is wrong because notifying the Change Advisory Board (CAB) is not the first action; the rollback should be executed immediately, and notification can follow as per the plan.

587
MCQmedium

A database administrator notices unusual queries that seem to be trying to extract data via SQL injection. The application uses parameterized queries for most queries, but some dynamic queries are built using string concatenation. What is the BEST remediation?

A.Restrict database user permissions to only necessary tables
B.Implement strict input validation for all user inputs
C.Deploy a web application firewall (WAF) in front of the application
D.Rewrite all dynamic queries to use parameterized queries
AnswerD

Parameterised queries bind user input as data, not executable SQL, eliminating the concatenation weakness that permits injection. Rewriting every dynamic query removes the vulnerable construction entirely, satisfying the stem's requirement to remediate the root cause rather than patch individual queries.

Why this answer

The BEST remediation is to rewrite all dynamic queries to use parameterized queries, as this eliminates the root cause of SQL injection by ensuring that user input is treated as data, not executable code. Parameterized queries (prepared statements) separate SQL logic from data, preventing attackers from altering the query structure. While other measures like input validation and WAFs add defense in depth, they do not fix the underlying vulnerability.

Exam trap

SSCP often tests the difference between root-cause fixes and compensating controls — candidates may choose input validation or WAFs, but the BEST remediation is always to eliminate the vulnerability by using parameterized queries.

How to eliminate wrong answers

Option A is wrong because restricting database permissions reduces the impact of a successful injection but does not prevent the injection itself; the vulnerable code remains. Option B is wrong because input validation can be bypassed and is not a complete solution; it should be used as an additional layer, not the primary remediation. Option C is wrong because a WAF can block some attacks but is a compensating control that can be evaded and does not fix the insecure code.

588
MCQmedium

A security team uses a risk matrix with likelihood (Low, Medium, High) and impact (Low, Medium, High). A vulnerability scan finds a buffer overflow in a customer-facing web application. The application is not critical but has high availability requirements. The likelihood of exploitation is considered Medium due to internal network segmentation. What is the risk level?

A.Medium
B.Extreme
C.High
D.Low
AnswerC

Medium likelihood combined with high impact maps to High on a standard three-by-three matrix. The application's high availability requirement raises impact despite segmentation lowering likelihood, and the matrix defines risk level from those two axes alone.

Why this answer

The risk level is High because the likelihood is Medium (due to internal network segmentation reducing but not eliminating the chance of exploitation) and the impact is High (the application has high availability requirements, so a buffer overflow could cause a denial of service or code execution, severely affecting availability). In a standard 3x3 risk matrix, Medium likelihood combined with High impact yields a High risk rating.

Exam trap

ISC2 often tests the misconception that internal network segmentation automatically lowers the risk to Medium or Low, but the high availability requirement elevates the impact, resulting in a High risk level despite the reduced likelihood.

How to eliminate wrong answers

Option A is wrong because Medium risk would require either Low likelihood with High impact, or Medium likelihood with Medium impact, but here the impact is High due to the application's high availability requirements. Option B is wrong because Extreme risk typically requires both High likelihood and High impact, or a combination like High likelihood with Medium impact in some matrices, but the likelihood is only Medium. Option D is wrong because Low risk would require Low likelihood and Low impact, or Low likelihood with Medium impact, but the impact is High and the likelihood is Medium.

589
MCQeasy

A small business wants to implement an access control system where employees can access files based on their department (e.g., HR, Finance). They want simplicity and ease of administration. Which access control model is BEST suited?

A.Mandatory Access Control (MAC)
B.Attribute-Based Access Control (ABAC)
C.Discretionary Access Control (DAC)
D.Role-Based Access Control (RBAC)
AnswerD

RBAC assigns permissions to roles rather than individuals, so department-based access (HR, Finance) is granted by role membership. This satisfies the stated need for simplicity and ease of administration, since adding or moving an employee means changing one role assignment rather than editing many file access control lists.

Why this answer

Role-Based Access Control (RBAC) is best suited because it maps access permissions directly to job functions (roles) such as HR or Finance, rather than to individual users. This simplifies administration: when an employee changes departments, the administrator simply updates their role assignment, and all associated permissions are automatically applied or revoked. RBAC is designed for environments where access decisions are based on organizational roles, providing a balance of security and ease of management.

Exam trap

The trap here is that candidates often confuse RBAC with DAC because both involve user-based permissions, but RBAC centralizes control through roles while DAC delegates control to individual resource owners, making RBAC the correct choice for department-based access.

How to eliminate wrong answers

Option A is wrong because Mandatory Access Control (MAC) uses system-enforced labels (e.g., security classifications like Top Secret) and is typically used in military or high-security environments, not for simple department-based access in a small business. Option B is wrong because Attribute-Based Access Control (ABAC) evaluates multiple attributes (e.g., time, location, resource type) using policy rules, which adds complexity and administrative overhead beyond what is needed for straightforward department-based access. Option C is wrong because Discretionary Access Control (DAC) allows individual users to control access to their own files (e.g., via file permissions), which does not scale well for department-wide access and can lead to inconsistent enforcement.

590
MCQeasy

Which of the following physical security controls is designed to prevent tailgating by requiring two doors to be interlocked?

A.Security guard
B.Biometric reader
C.Mantrap
D.CCTV
AnswerC

A mantrap interposes two interlocked doors so only one opens at a time, holding each person alone in the vestibule before the second door releases. This directly satisfies the requirement to prevent tailgating, since a follower cannot pass through while the first door remains secured.

Why this answer

A mantrap is a physical security control consisting of two interlocking doors that create a small vestibule. Only one door can be opened at a time, preventing an unauthorized person from following an authorized person through a single entry point (tailgating). This design forces each individual to be authenticated before the second door unlocks, ensuring only one person passes per authentication event.

Exam trap

Candidates often mistake a mantrap for a simple turnstile or revolving door, but the defining characteristic of a mantrap is the interlocking mechanism that prevents both doors from opening simultaneously, ensuring only one authenticated person passes at a time.

How to eliminate wrong answers

Option A is wrong because a security guard can deter tailgating through observation but does not mechanically enforce the interlocking of two doors; tailgating can still occur if the guard is distracted. Option B is wrong because a biometric reader authenticates identity but does not physically prevent a second person from slipping through the same door; it lacks the interlocking door mechanism. Option D is wrong because CCTV provides surveillance and recording of tailgating incidents but does not actively prevent the act; it is a detective control, not a preventive one.

591
MCQhard

A financial services organization deploys a new web application that allows customers to check account balances and transfer funds. The application uses a RESTful API with JSON payloads. Shortly after deployment, the security team notices unusual traffic patterns: many requests contain excessively long JSON strings in the 'amount' field, and some of these requests return 500 Internal Server Errors. The application logs show that these requests cause high CPU usage on the application server. The developers confirm that the input validation only checks for negative numbers and characters. Which type of attack is most likely occurring, and what is the best immediate mitigation?

A.The attack is a brute-force attempt on the amount field; implement rate limiting.
B.The attack is cross-site scripting; sanitize output.
C.The attack is a Denial of Service using large payloads; implement input size limits and validation.
D.The attack is SQL injection; use parameterized queries.
AnswerC

Oversized JSON payloads consuming CPU and triggering 500 errors indicate resource exhaustion via large request bodies, not injection. Enforcing input size limits and strict validation caps the 'amount' field, preventing the server from processing payloads that exhaust CPU, satisfying the need to stop the attack immediately.

Why this answer

The symptoms indicate a Denial of Service attack via large payloads that consume server resources. Excessive JSON string length in the 'amount' field causes high CPU usage during parsing and processing, leading to 500 errors. The best immediate mitigation is to implement input size limits and strict validation to reject oversized payloads.

Option A is incorrect because brute-force attacks typically involve repeated attempts with different values, not large payloads causing CPU exhaustion; rate limiting would not address the root cause. Option B is incorrect because cross-site scripting (XSS) targets client-side script execution in the browser, not server-side CPU spikes. Option D is incorrect because SQL injection would likely return database error messages or cause data manipulation, not high CPU from JSON parsing.

592
Multi-Selecthard

Which TWO protocols are used to secure email communication at the message level?

Select 2 answers
A.IPsec
B.PGP
C.S/MIME
D.SSL/TLS
E.SSH
AnswersB, C

PGP provides message-level email security through encryption and digital signatures applied to the message content using a web-of-trust key model. This satisfies the stem's message-level constraint, since the payload remains protected end-to-end, unlike transport-layer mechanisms such as TLS that secure only the delivery channel.

Why this answer

PGP (Pretty Good Privacy) and S/MIME (Secure/Multipurpose Internet Mail Extensions) are the two primary protocols that secure email at the message level. They encrypt the entire email body and attachments, ensuring end-to-end confidentiality and integrity regardless of the transport path. PGP uses a web of trust model, while S/MIME relies on a hierarchical public key infrastructure (PKI) with X.509 certificates.

Exam trap

ISC2 often tests the distinction between transport-layer security (SSL/TLS) and message-level security (PGP/SMIME), so candidates mistakenly choose SSL/TLS because they associate it with email security (e.g., SMTPS), but it does not provide end-to-end message encryption.

593
MCQhard

During a risk assessment, a company identifies that a legacy system has a known CVE with a CVSS score of 9.8. The system is critical but cannot be patched immediately. The management decides to implement strict network segmentation and monitor the system continuously. This risk response is best described as:

A.Risk acceptance
B.Risk avoidance
C.Risk transfer
D.Risk mitigation
AnswerD

Risk mitigation reduces the likelihood or impact of a threat. Since patching is impossible, segmentation limits the attack surface and continuous monitoring shortens detection time, directly lowering the CVE's exploitability while the system remains critical and unpatched.

Why this answer

Risk mitigation, because the company is implementing strict network segmentation and continuous monitoring to reduce the likelihood and impact of the vulnerability being exploited. This reduces the risk without eliminating it entirely, which is the essence of mitigation. The CVSS score of 9.8 indicates critical severity, and the controls (e.g., ACLs, VLANs, IDS/IPS) directly address the attack surface.

Exam trap

The trap here is that candidates confuse 'risk mitigation' with 'risk acceptance' because the system remains vulnerable, but the key distinction is that active controls are applied to reduce risk, not merely acknowledged.

How to eliminate wrong answers

Option A is wrong because risk acceptance would involve acknowledging the risk without taking any active controls, but here the company actively deploys segmentation and monitoring. Option B is wrong because risk avoidance would require removing the system or ceasing its operation entirely, which is not done since the system remains in use. Option C is wrong because risk transfer would involve shifting the financial burden or liability to a third party (e.g., insurance or outsourcing), not implementing technical controls.

594
MCQmedium

Which of the following encryption protocols should be used to secure wireless traffic in an enterprise environment?

A.WPA3-Enterprise
B.WEP
C.WPA3-PSK
D.WPA2-PSK
E.WPA2-Enterprise
AnswerA

Provides the strongest security with 802.1X authentication and GCMP-256 encryption.

Why this answer

WPA3-Enterprise is the correct choice because it provides the highest level of security for enterprise wireless networks, incorporating mandatory 192-bit Suite B cryptographic suites (AES-256 in GCM mode, HMAC-SHA384, and ECDHE key exchange) to protect against offline dictionary attacks, forward secrecy, and brute-force attempts. It also uses Simultaneous Authentication of Equals (SAE) for the handshake, replacing the vulnerable 4-way handshake of WPA2, and supports 802.1X/EAP authentication with RADIUS for centralized user management.

Exam trap

ISC2 often tests the distinction between 'PSK' and 'Enterprise' modes, trapping candidates who see 'WPA3' and assume it is always best, but the question's 'enterprise environment' requirement specifically demands the Enterprise mode (with 802.1X/RADIUS), not the PSK variant, even though both use SAE.

How to eliminate wrong answers

Option B (WEP) is wrong because it uses the insecure RC4 stream cipher with a static 40- or 104-bit key, making it trivially crackable with tools like aircrack-ng in minutes. Option C (WPA3-PSK) is wrong because it uses a pre-shared key (PSK) mode, which lacks the per-user authentication and centralized management required in an enterprise environment, and is more suited for small office/home office (SOHO) deployments. Option D (WPA2-PSK) is wrong because it relies on the vulnerable 4-way handshake with a pre-shared key, making it susceptible to offline dictionary attacks (e.g., using hashcat) and KRACK attacks, and it lacks enterprise-grade user authentication.

Option E (WPA2-Enterprise) is wrong because while it supports 802.1X/EAP, it uses the older 4-way handshake which is vulnerable to KRACK (CVE-2017-13077) and lacks forward secrecy and the stronger cryptographic suites mandated in WPA3-Enterprise.

595
MCQmedium

A security administrator needs to ensure that only authorized personnel can reset user passwords in Active Directory. Which of the following is the BEST method to delegate this responsibility without granting unnecessary privileges?

A.Place the personnel in the Account Operators group.
B.Add the personnel to the Domain Admins group.
C.Use Delegation of Control wizard to assign the 'Reset user passwords and force password change at next logon' permission.
D.Give the personnel physical access to the domain controller.
AnswerC

The Delegation of Control wizard grants only the 'Reset user passwords and force password change at next logon' permission on the target organisational unit, avoiding broader rights such as Account Operators or Domain Admin that would violate least privilege.

Why this answer

The Delegation of Control wizard allows granular assignment of specific Active Directory permissions, such as 'Reset user passwords and force password change at next logon', without granting broader administrative rights. This follows the principle of least privilege by limiting the delegated personnel to only the necessary task. Option C is correct because it directly addresses the requirement with a built-in, secure delegation mechanism.

Exam trap

The trap here is that candidates often assume built-in groups like Account Operators are the simplest delegation method, overlooking that they grant far more permissions than the specific task requires, which is a common violation of the principle of least privilege tested on the SSCP.

How to eliminate wrong answers

Option A is wrong because the Account Operators group can create, delete, and modify most user accounts and groups, which includes the ability to reset passwords but also grants excessive privileges beyond the required task. Option B is wrong because Domain Admins have full administrative control over the entire domain, including all user and computer objects, which is far more privilege than needed and violates least privilege. Option D is wrong because physical access to a domain controller does not inherently grant the ability to reset passwords; it could allow unauthorized actions but is not a controlled delegation method and introduces significant security risks.

596
Multi-Selectmedium

During a wireless site survey, a security engineer identifies several security weaknesses. Which TWO measures should be implemented to improve wireless security for a corporate network using WPA2-Enterprise?

Select 2 answers
A.Use 802.1X authentication with EAP-TLS and certificate-based authentication
B.Implement MAC address filtering to allow only known devices
C.Disable SSID broadcast to hide the network
D.Ensure the RADIUS server uses a trusted certificate and validate client certificates
E.Enable WPS for easy client configuration
AnswersA, D

802.1X with EAP-TLS satisfies WPA2-Enterprise's requirement for per-user authentication against a RADIUS server, using mutual certificate validation rather than shared credentials. This defeats rogue access points and credential-capture attacks, since the client verifies the server's certificate and each session derives unique encryption keys.

Why this answer

Option A is correct because WPA2-Enterprise relies on 802.1X for port-based network access control, and EAP-TLS with certificate-based authentication provides strong mutual authentication using digital certificates rather than weaker credential-based methods like PEAP-MSCHAPv2. Option D is correct because the RADIUS server must present a certificate from a trusted CA so supplicants can validate it and prevent rogue-AP/evil-twin attacks, while validating client certificates ensures only authorized devices/users complete the EAP-TLS exchange. Option B is not appropriate because MAC address filtering is trivially bypassed via spoofing and adds no real cryptographic protection.

Option C is not appropriate because hiding the SSID is security through obscurity and the SSID is still discoverable in management frames. Option E is not appropriate because WPS is vulnerable to brute-force PIN attacks and should be disabled on corporate WPA2-Enterprise networks.

Exam trap

SSCP often tests the misconception that hiding the SSID or using MAC filtering adds security, when in fact these are easily bypassed and not part of a robust WPA2-Enterprise implementation.

597
MCQmedium

A software developer wants to ensure the authenticity and integrity of an API request but does not require non-repudiation. Which cryptographic method should be used?

A.Digital signature using RSA
B.Symmetric encryption with CBC mode
C.Hash-based message authentication code (HMAC)
D.Elliptic curve Diffie-Hellman (ECDH)
AnswerC

HMAC combines a shared secret key with a hash function, providing both integrity and authenticity of the API request. It uses symmetric keying, so it does not deliver non-repudiation, precisely matching the stem's constraint that non-repudiation is not required.

Why this answer

HMAC uses a shared secret key combined with a cryptographic hash function to produce a fixed-size authentication tag. This ensures both authenticity (the request came from a party knowing the key) and integrity (the data has not been altered) without providing non-repudiation, because the same key is shared between sender and receiver, so the receiver could also have generated the tag.

Exam trap

ISC2 often tests the distinction between authentication/integrity (HMAC) and non-repudiation (digital signatures), leading candidates to incorrectly choose digital signatures when non-repudiation is explicitly not required.

How to eliminate wrong answers

Option A is wrong because a digital signature using RSA provides non-repudiation (the sender cannot deny signing) and is computationally heavier than necessary when non-repudiation is not required. Option B is wrong because symmetric encryption with CBC mode provides confidentiality, not authenticity or integrity; CBC mode alone does not prevent an attacker from modifying ciphertext blocks. Option D is wrong because Elliptic Curve Diffie-Hllman (ECDH) is a key exchange protocol used to establish a shared secret over an insecure channel, not a method for authenticating or verifying the integrity of an API request.

598
MCQeasy

What is the primary purpose of account deprovisioning in the account lifecycle?

A.To modify user roles and permissions
B.To immediately disable accounts and preserve evidence
C.To enforce password policies
D.To create new user accounts
AnswerB

Deprovisioning immediately disables or removes access rights when a user leaves or changes roles, and retaining the account data preserves audit evidence for investigations. This containment-first approach satisfies the lifecycle requirement to revoke access promptly while keeping records intact for forensic or compliance review.

Why this answer

Deprovisioning is the formal process of removing a user's access when they leave or change roles. Its primary purpose is to immediately disable accounts to prevent unauthorized access while preserving the account and associated data as evidence for audits, investigations, or legal holds.

Exam trap

The trap is confusing deprovisioning with role modification or password policy enforcement — candidates forget that deprovisioning is specifically about terminating access while retaining records for audit and legal purposes.

How to eliminate wrong answers

Option A is wrong because modifying roles and permissions is part of access review or role change management, not deprovisioning — deprovisioning removes access entirely. Option C is wrong because enforcing password policies is a preventive access control applied during account provisioning and use, not during termination. Option D is wrong because creating new user accounts is provisioning — the opposite end of the lifecycle from deprovisioning.

599
MCQhard

A network engineer configures a VLAN hopping attack prevention by setting all unused switch ports to an unused VLAN and disabling trunking. What vulnerability is being mitigated?

A.STP manipulation
B.ARP spoofing
C.MAC flooding
D.DTP spoofing
E.DHCP starvation
AnswerD

DTP spoofing lets an attacker negotiate a trunk link from an access port, gaining access to all VLANs. Setting unused ports to an unused VLAN and disabling trunking (switchport nonegotiate) blocks DTP frame exchange, preventing the rogue trunk from forming and stopping VLAN hopping.

Why this answer

DTP spoofing is the correct answer because VLAN hopping attacks often exploit Dynamic Trunking Protocol (DTP) to negotiate a trunk link between a switch and an attacker's device, allowing the attacker to send and receive traffic on multiple VLANs. By disabling trunking on all unused ports and assigning them to an unused VLAN, the switch will not respond to DTP negotiation requests, preventing unauthorized trunk establishment.

Exam trap

ISC2 often tests the distinction between DTP spoofing (VLAN hopping via trunk negotiation) and double-tagging attacks (another VLAN hopping method), so candidates may confuse the two or incorrectly associate VLAN hopping with MAC flooding or ARP spoofing.

How to eliminate wrong answers

Option A is wrong because STP manipulation attacks target Spanning Tree Protocol to cause network loops or traffic redirection, not VLAN hopping. Option B is wrong because ARP spoofing involves sending forged ARP replies to associate an attacker's MAC with a legitimate IP address, which is a man-in-the-middle technique unrelated to trunk negotiation. Option C is wrong because MAC flooding overwhelms a switch's CAM table to force it into fail-open mode, causing frames to flood out all ports, but it does not involve trunking or VLAN tagging.

Option E is wrong because DHCP starvation exhausts the DHCP server's address pool by sending many fake DHCP requests, preventing legitimate clients from obtaining IP addresses, and has no connection to DTP or VLAN hopping.

600
MCQmedium

An attacker is performing a man-in-the-middle attack at Layer 2 by sending forged ARP messages to associate their MAC address with the IP address of a legitimate host on the same subnet. This attack is known as:

A.ARP spoofing
B.DNS poisoning
C.DHCP spoofing
D.MAC flooding
AnswerA

ARP spoofing sends forged ARP replies that bind the attacker's MAC address to a legitimate host's IP, redirecting Layer 2 traffic through the attacker. This precisely matches the stem's man-in-the-middle mechanism, poisoning neighbours' ARP caches on the same subnet.

Why this answer

ARP spoofing (also called ARP poisoning) involves an attacker sending forged ARP replies to associate their MAC address with the IP address of a legitimate host, causing traffic intended for that host to be sent to the attacker. This enables man-in-the-middle attacks at Layer 2. The scenario described exactly matches ARP spoofing.

Exam trap

The trap is confusing ARP spoofing with other Layer 2 attacks like MAC flooding or DHCP spoofing; candidates must distinguish between attacks that manipulate ARP caches versus those that flood switch tables or provide rogue DHCP services.

How to eliminate wrong answers

Option B is wrong because DNS poisoning involves corrupting DNS cache entries to redirect domain name resolution, not manipulating ARP tables at Layer 2. Option C is wrong because DHCP spoofing involves a rogue DHCP server providing false IP configuration (including gateway), not forging ARP messages to impersonate a host. Option D is wrong because MAC flooding involves overwhelming a switch's CAM table with bogus MAC addresses to force it into hub mode, not sending forged ARP messages to associate a MAC with an IP.

Page 7

Page 8 of 13

Page 9