Courseiva

Systems Security Certified Practitioner SSCP (SSCP) — Questions 601–675

971 questions total · 13pages · All types, answers revealed

Page 8

Page 9 of 13

Page 10
601
MCQhard

A security operations center (SOC) receives an alert from its intrusion detection system (IDS) about a possible SQL injection attack against a web server. The SOC analyst reviews the IDS signature and sees that it triggered on a request containing the string 'OR 1=1'. However, the web application logs show that the request was blocked by a web application firewall (WAF) and returned a 403 error. Which of the following BEST describes the nature of this alert?

A.True positive; the IDS correctly detected an attack, and the WAF successfully blocked it.
B.True positive; the IDS correctly detected an attack, and the WAF failed to block it.
C.False negative; the IDS failed to detect the attack, but the WAF blocked it.
D.False positive; the request was legitimate and the IDS misclassified it.
AnswerA

The IDS correctly identified a SQL injection attempt (true positive). The WAF then blocked the request, as evidenced by the 403 error. This means the attack was detected and prevented. The alert is a true positive because the IDS accurately flagged malicious activity, even though the attack was stopped. The SOC should still investigate the source and consider tuning.

Why this answer

The IDS correctly identified a SQL injection attempt, making it a true positive. The WAF then blocked the request, as shown by the 403 error, so the attack was prevented. This is a true positive detection with successful mitigation.

It is not a false positive because the traffic was malicious, and not a false negative because the IDS did alert. The SOC should investigate the source and consider whether the IDS signature needs tuning to reduce noise.

Exam trap

The trap here is equating a true positive alert with a successful attack, but a true positive can occur even when the attack is blocked by another control.

602
Multi-Selecthard

A security analyst is reviewing Linux audit logs with auditd. Which TWO events would be of greatest concern for a server that should not have interactive logins? (Select TWO.)

Select 2 answers
A.Successful root login via SSH
B.System reboot logs
C.Multiple failed su attempts
D.Successful cron job execution
E.File permission changes by a non-root user
AnswersA, C

A successful root SSH login directly violates the no-interactive-logins constraint, since it establishes an authenticated remote shell on the server. Root access also bypasses the least-privilege boundaries that should restrict administrative activity, making this event a high-priority indicator of compromise or misconfiguration.

Why this answer

Option A (Successful root login via SSH) is correct because a server that should not permit interactive logins should never show a successful root SSH session; this indicates either a policy violation or compromised credentials granting direct privileged interactive access. Option C (Multiple failed su attempts) is correct because repeated su failures signal an active attempt to escalate to another account (often root) interactively, which is a strong indicator of brute-force or unauthorized privilege-escalation activity on a host that should have no interactive users. Option B (System reboot logs) is not inherently concerning, as reboots are routine operational events and do not by themselves indicate interactive login or compromise.

Option D (Successful cron job execution) is normal scheduled behavior and does not represent an interactive login. Option E (File permission changes by a non-root user) may be worth reviewing, but a non-root user changing permissions on files they own is not as directly indicative of unauthorized interactive access as a successful root SSH login or repeated su failures.

Exam trap

The trap here is focusing on generic system events (reboots, cron) as security concerns while missing that the question specifically asks about a server that should not have interactive logins, making root SSH and su attempts the clear anomalies.

603
MCQhard

A security administrator is implementing a new system that will process credit card payments. The organization must comply with PCI DSS. Which of the following controls is specifically required by PCI DSS to protect stored cardholder data?

A.Implementing a web application firewall (WAF) in front of the payment application
B.Encrypting cardholder data at rest using strong cryptography
C.Conducting quarterly external network scans by an Approved Scanning Vendor (ASV)
D.Enforcing a minimum password length of eight characters for all users
AnswerB

PCI DSS requires that stored cardholder data be rendered unreadable, typically through strong encryption, truncation, or tokenization. Encryption at rest is a direct requirement to protect data if storage media is compromised. This control is explicitly mandated and is essential for compliance.

Why this answer

PCI DSS requires that stored cardholder data be protected by rendering it unreadable, commonly through strong encryption. This directly addresses the risk of data exposure from compromised storage. A WAF, ASV scans, and password policies are required or recommended for other aspects of PCI DSS but do not fulfill the specific stored-data protection requirement.

Exam trap

The trap here is selecting a general security control like a WAF or password policy when the question asks specifically about protecting stored cardholder data.

604
MCQeasy

An organization requires users to authenticate using a password and a one-time code from a mobile app. Which authentication method is being used?

A.Time-based One-Time Password (TOTP)
B.Smart card
C.Hardware token
D.Biometrics
AnswerA

TOTP generates a code from a shared secret and the current time, so the mobile app produces a fresh one-time code every 30 seconds. Combined with the password, this delivers the two distinct factors the stem requires, satisfying the multi-factor authentication constraint.

Why this answer

A password combined with a one-time code generated by a mobile app is the textbook definition of Time-based One-Time Password (TOTP), where the code is derived from a shared secret and the current time (typically 30-second windows, per RFC 6238). This is a form of multi-factor authentication combining something you know (password) with something you have (the app/device).

Exam trap

The trap is conflating TOTP with hardware tokens — both generate one-time codes, but TOTP is software-based (mobile app) while hardware tokens are dedicated physical devices, and the exam expects you to key on the 'mobile app' detail.

How to eliminate wrong answers

Option B is wrong because a smart card is a physical card with an embedded chip used for authentication, not a software-generated time-based code on a mobile app. Option C is wrong because a hardware token is a dedicated physical device (like an RSA SecurID fob) that generates codes — the question specifies a mobile app, not dedicated hardware. Option D is wrong because biometrics uses physiological traits (fingerprint, face, iris) and does not involve a one-time code.

605
MCQhard

An organization experiences malware that injects code into legitimate processes. Which security feature should be enabled to prevent code execution in memory pages?

A.Encrypted File System (EFS)
B.Address Space Layout Randomization (ASLR)
C.Mandatory Access Control (MAC)
D.Data Execution Prevention (DEP)
AnswerD

DEP marks memory pages as non-executable, so injected code placed in data regions cannot run. This blocks the mechanism described, where malware injects code into legitimate processes and attempts execution from those pages, satisfying the requirement to prevent code execution in memory.

Why this answer

Data Execution Prevention (DEP) is a hardware and software security feature that marks memory pages as non-executable unless they explicitly contain executable code. By preventing code execution in data-only memory regions (such as the heap and stack), DEP stops malware that attempts to inject and run shellcode within legitimate processes, even if the process is compromised.

Exam trap

The trap here is that candidates often confuse ASLR with DEP, thinking randomization alone prevents code execution, but ASLR only makes addresses unpredictable while DEP actively blocks execution from non-executable pages.

How to eliminate wrong answers

Option A is wrong because Encrypted File System (EFS) protects data at rest by encrypting files on NTFS volumes, but it does not control memory execution permissions or prevent code injection into running processes. Option B is wrong because Address Space Layout Randomization (ASLR) randomizes the memory addresses of process components to make exploitation harder, but it does not enforce non-execution of memory pages; it works alongside DEP but is not a direct prevention mechanism against code execution in memory. Option C is wrong because Mandatory Access Control (MAC) enforces system-wide security policies based on labels and subjects, but it does not manage memory page execution permissions at the hardware or kernel level.

606
MCQmedium

During a qualitative risk analysis, an organization assigns a risk rating of 'High' for a specific threat. Which combination of factors most directly leads to this rating?

A.High probability and high impact
B.Low probability and low impact
C.High probability and low impact
D.Low probability and high impact
AnswerA

Qualitative risk matrices derive ratings from likelihood and consequence, so high probability combined with high impact maps directly to a High rating. This satisfies the stem's request for the factor combination producing that specific rating.

Why this answer

In qualitative risk analysis, risk rating is determined by the product of probability and impact. A 'High' rating directly results from both high probability and high impact, as this combination represents the greatest potential for loss. This aligns with the risk matrix approach where the highest risk scores occupy the top-right quadrant.

Exam trap

ISC2 often tests the misconception that high impact alone is sufficient for a 'High' risk rating, ignoring that probability must also be high to reach the top risk level.

How to eliminate wrong answers

Option B is wrong because low probability and low impact produce a 'Low' risk rating, not 'High'. Option C is wrong because high probability combined with low impact typically yields a 'Medium' or 'Moderate' rating, as the low impact reduces overall risk severity. Option D is wrong because low probability with high impact often results in a 'Medium' risk rating, as the low likelihood mitigates the overall risk despite the high potential damage.

607
Multi-Selectmedium

A security engineer is hardening a Windows workstation. Which TWO configurations reduce the attack surface by limiting execution of unauthorized code? (Select TWO.)

Select 2 answers
A.Configure AppLocker rules
B.Enable Windows Firewall with Advanced Security
C.Enable BitLocker full-disk encryption
D.Enable Windows Defender Application Control (WDAC)
E.Disable AutoPlay
AnswersA, D

AppLocker enforces allow or deny rules based on publisher signature, file path or hash, so only approved executables, scripts and installers run. This directly limits execution of unauthorised code, satisfying the stem's attack-surface reduction constraint on the Windows workstation.

Why this answer

AppLocker (A) is correct because it uses allow/deny rules based on publisher, path, or file hash to control which executables, scripts, and installers users can run, directly restricting unauthorized code execution. Windows Defender Application Control (D) is also correct because WDAC enforces code integrity policies at the kernel level, allowing only trusted, signed binaries to execute and blocking unauthorized or tampered code. Windows Firewall with Advanced Security (B) filters network traffic by port, protocol, and profile but does not govern local code execution, so it does not meet the requirement.

BitLocker (C) provides full-disk encryption for data-at-rest confidentiality and does not prevent execution of unauthorized programs. Disabling AutoPlay (E) reduces a minor vector for automatic execution from removable media but is not a general code-execution control like AppLocker or WDAC.

Exam trap

SSCP often tests whether candidates can distinguish application control (AppLocker/WDAC) from network controls (firewall) and data protection (BitLocker) — a common mistake is selecting firewall or BitLocker as a way to limit code execution.

608
Multi-Selecthard

Which TWO of the following are effective measures to prevent buffer overflow attacks in software development?

Select 2 answers
A.Validate all input to ensure it meets length constraints
B.Implement stack canaries
C.Obfuscate the code to make exploitation harder
D.Enable Address Space Layout Randomization (ASLR)
E.Use functions that perform bounds checking (e.g., strncpy instead of strcpy)
AnswersA, E

Enforcing length constraints during input validation rejects oversized payloads before they reach fixed-size buffers, directly satisfying the stem's requirement to prevent buffer overflow. Combined with bounds checking, this stops attackers writing past allocated memory, the core mechanism of such attacks.

Why this answer

Option A is correct because validating input against strict length constraints ensures that data written into fixed-size buffers never exceeds their allocated capacity, which is the root cause of buffer overflows. Option E is correct because bounds-checking functions such as strncpy (or safer alternatives like snprintf and strlcpy) limit the number of bytes copied, preventing writes past the end of a buffer that unchecked functions like strcpy and strcat allow. Option B is not a preventive development measure in the same sense; stack canaries are a compiler/runtime mitigation that detects a corrupted return address after the fact rather than stopping the overflow from occurring.

Option C is incorrect because code obfuscation only raises the effort of reverse engineering and does not address the memory-safety flaw itself. Option D is incorrect here because ASLR is an operating-system-level randomization mitigation that makes exploitation less reliable, but it does not prevent the buffer overflow vulnerability from existing in the code.

609
MCQhard

A security administrator is configuring a wireless network for a branch office. The office has legacy devices that only support WPA2-PSK. The administrator wants to provide the highest level of security while maintaining compatibility. Which configuration should be used?

A.WPA2-Enterprise with RADIUS
B.WPA2-PSK with AES (CCMP)
C.WPA3-SAE only
D.WPA2-PSK with TKIP
AnswerB

WPA2-PSK with AES (CCMP) satisfies the legacy compatibility constraint while delivering strong encryption. CCMP uses AES in counter mode with CBC-MAC for integrity, replacing the weaker TKIP. Since the devices only support WPA2-PSK, this pairing provides the highest security available within that constraint.

Why this answer

WPA2-PSK with AES (CCMP) is correct because it provides the highest security level compatible with legacy devices that only support WPA2-PSK. AES-CCMP is the mandatory encryption protocol for WPA2, offering strong data confidentiality and integrity, whereas TKIP is deprecated due to known vulnerabilities. This configuration avoids the need for a RADIUS server (required by WPA2-Enterprise) and does not force an upgrade to WPA3, which legacy devices cannot support.

Exam trap

The trap here is that candidates often assume WPA2-Enterprise is always more secure than WPA2-PSK, but the question explicitly requires compatibility with legacy devices that only support WPA2-PSK, making WPA2-Enterprise an invalid choice despite its stronger authentication model.

How to eliminate wrong answers

Option A is wrong because WPA2-Enterprise with RADIUS requires an authentication server and is not supported by legacy devices that only support WPA2-PSK; it would break compatibility. Option C is wrong because WPA3-SAE is not supported by legacy WPA2-only devices, so it would render the network inaccessible to them. Option D is wrong because WPA2-PSK with TKIP uses the deprecated TKIP cipher, which is vulnerable to attacks like Michael and Beck-Tews, and provides weaker security than AES-CCMP.

610
MCQeasy

Which of the following is a primary purpose of a security baseline, such as the CIS Benchmarks?

A.To provide a secure configuration standard for systems
B.To calculate annualized loss expectancy
C.To replace the need for vulnerability scanning
D.To detect intrusions in real-time
AnswerA

CIS Benchmarks codify hardened, vendor-neutral configuration settings for operating systems, applications and cloud platforms. A security baseline supplies that documented secure configuration standard, giving administrators a measurable reference to assess and remediate deviations, which is precisely the purpose the question asks for.

Why this answer

A security baseline like the CIS Benchmarks establishes a hardened, consistent configuration standard for operating systems, applications, and network devices. This reduces the attack surface by disabling unnecessary services, enforcing least privilege, and applying specific registry or file permission settings. It is a foundational step in secure system deployment and ongoing compliance.

Exam trap

ISC2 SSCP emphasizes the distinction between proactive configuration standards (baselines) and ongoing operational controls like vulnerability scanning and intrusion detection. Candidates often mistakenly think a baseline replaces scanning or detection, when in fact it is a preventative measure.

How to eliminate wrong answers

Option B is wrong because annualized loss expectancy (ALE) is a quantitative risk analysis formula (SLE × ARO) used in risk management, not a function of a security baseline. Option C is wrong because a security baseline does not replace vulnerability scanning; baselines define secure configurations, while scanning actively identifies missing patches or misconfigurations. Option D is wrong because intrusion detection in real-time is performed by IDS/IPS systems (e.g., Snort, Suricata) that analyze network traffic or host logs, not by a static configuration baseline.

611
Multi-Selectmedium

An organization is implementing system hardening. Which of the following actions are recommended by CIS Benchmarks? (Select all that apply.)

Select 3 answers
A.Remove unnecessary services and accounts
B.Enable DHCP for all network interfaces
C.Disable autorun and autoplay features
D.Enable User Account Control (UAC)
E.Disable the host-based firewall
AnswersA, C, D

Removing unnecessary services and accounts shrinks the attack surface by eliminating unused daemons, listening ports and dormant credentials that attackers exploit for lateral movement or privilege escalation. This directly satisfies the CIS Benchmarks' hardening objective of reducing exploitable components to only those required for the system's documented business function.

Why this answer

Option A is correct because CIS Benchmarks emphasize reducing the attack surface by removing or disabling unnecessary services, applications, and accounts that are not required for the system's role. Option C is correct because CIS Benchmarks recommend disabling autorun and autoplay to prevent automatic execution of potentially malicious code from removable media and network drives. Option D is correct because enabling User Account Control (UAC) ensures administrative actions require explicit elevation and helps enforce least privilege on Windows systems.

Option B is incorrect because CIS Benchmarks generally recommend static IP configuration or controlled network settings for servers rather than enabling DHCP on all interfaces, which can introduce unauthorized or unpredictable network configuration. Option E is incorrect because CIS Benchmarks recommend enabling and properly configuring host-based firewalls, not disabling them, to filter inbound and outbound traffic.

Exam trap

SSCP often tests the difference between hardening actions and general system configurations; candidates may confuse enabling DHCP or disabling firewalls as security measures when they are not recommended by CIS Benchmarks.

612
Multi-Selecthard

A cloud operations team is hardening the management plane of its Infrastructure as a Service (IaaS) environment. The team wants to reduce the risk of unauthorized administrative access to the cloud console and APIs. Which TWO of the following controls best address this objective? (Choose two.)

Select 2 answers
A.Configure a content delivery network in front of public web endpoints
B.Enforce multi-factor authentication for all privileged accounts
C.Apply least-privilege identity and access management policies to administrative roles
D.Enable object storage versioning on application data buckets
E.Increase the size of the managed database instance class
AnswersB, C

Multi-factor authentication requires a second factor beyond a password, so a stolen or guessed credential alone cannot grant console or API access. Applying it to privileged accounts directly reduces the risk of unauthorized administrative access, which is the stated objective. This is a foundational control for protecting the management plane of any IaaS environment.

Why this answer

Protecting the cloud management plane requires strong authentication and tight authorization. Multi-factor authentication ensures that a compromised password alone cannot grant administrative access, while least-privilege IAM policies limit what any authenticated identity can do. Together they reduce the likelihood and impact of unauthorized administrative access.

The other choices concern storage durability, database sizing, and content delivery, none of which govern who can reach the console or APIs.

Exam trap

The trap here is treating any cloud hardening action as relevant to management-plane access, when controls like versioning or CDN configuration do not authenticate or authorize administrative identities.

613
MCQeasy

Which type of IDS uses a baseline of normal behavior to detect anomalies?

A.Host-based IDS (HIDS)
B.Anomaly-based IDS
C.Network-based IDS (NIDS)
D.Signature-based IDS
AnswerB

Anomaly-based IDS builds a statistical or behavioural baseline of normal activity, then flags deviations from it as potential intrusions. This directly satisfies the stem's requirement for a baseline of normal behaviour, unlike signature-based detection, which matches known attack patterns rather than profiling legitimate traffic.

Why this answer

Anomaly-based IDS (B) is correct because it establishes a baseline of normal network or system behavior through statistical modeling or machine learning, then flags deviations from that baseline as potential intrusions. This contrasts with signature-based systems that rely on predefined patterns of known attacks. The core mechanism involves profiling metrics such as CPU usage, network traffic volume, or protocol deviations over time to identify anomalies.

Exam trap

ISC2 SSCP often tests the distinction between detection methodology (anomaly vs. signature) and deployment type (host-based vs. network-based), leading candidates to mistakenly choose HIDS or NIDS because they associate them with behavioral monitoring, when the question specifically asks about the detection method that uses a baseline.

How to eliminate wrong answers

Option A is wrong because Host-based IDS (HIDS) monitors activity on a single host (e.g., system logs, file integrity) but does not inherently use a baseline of normal behavior; it can be signature-based or anomaly-based depending on implementation. Option C is wrong because Network-based IDS (NIDS) analyzes network traffic at the packet level but, like HIDS, is a deployment type, not a detection methodology; it can use signatures or anomalies. Option D is wrong because Signature-based IDS relies on a database of known attack signatures (e.g., Snort rules) and cannot detect novel or zero-day attacks without an existing pattern, whereas anomaly-based detection uses behavioral baselines.

614
MCQeasy

Which protocol is used to securely transfer files between a client and server, typically over TCP port 22?

A.SMTP
B.TFTP
C.SSH
D.FTP
AnswerC

SSH provides an encrypted channel over TCP port 22 and includes SFTP and SCP for secure file transfer. Unlike FTPS, which uses TLS on different ports, SSH natively satisfies the port 22 and encryption requirements stated in the question.

Why this answer

SSH (Secure Shell) operates over TCP port 22 and provides an encrypted channel for secure file transfer (via SFTP or SCP) as well as remote shell access. Its encryption and host authentication replace the cleartext credentials and data of legacy protocols like FTP and Telnet. This makes SSH the correct answer for secure file transfer on port 22.

Exam trap

SSCP often tests the port-to-protocol mapping and the secure-vs-insecure distinction — candidates may pick FTP because it is the 'file transfer' protocol, missing that the question specifies 'securely' and 'port 22'.

How to eliminate wrong answers

Option A is wrong because SMTP is the email transfer protocol, uses TCP port 25 (or 587/465 for submission), and has nothing to do with file transfer. Option B is wrong because TFTP is a trivial, unauthenticated UDP-based file transfer protocol on port 69 — it is neither secure nor TCP-based. Option D is wrong because FTP uses TCP ports 20/21 and transmits credentials and data in cleartext, so it is not secure; FTPS and SFTP are the secure variants, but plain FTP is not.

615
MCQmedium

A company's vulnerability scanner reports a critical vulnerability in a third-party library. The remediation SLA for critical vulnerabilities is 48 hours. However, the patch is not yet available from the vendor. Which of the following is the most appropriate immediate action?

A.Remove the vulnerable software immediately
B.Extend the SLA to 30 days
C.Accept the risk because the vendor has not released a patch
D.Implement compensating controls to mitigate the vulnerability
AnswerD

With no vendor patch available, compensating controls such as virtual patching, network segmentation or tightened access restrictions reduce exposure while the SLA clock runs. This satisfies the stem's immediate-action requirement without breaching the 48-hour critical remediation SLA.

Why this answer

When a patch is unavailable, implementing compensating controls (e.g., network segmentation, WAF rules, disabling unused features) is the immediate action to reduce risk exposure while awaiting an official fix. This aligns with the NIST SP 800-40 risk mitigation framework, which prioritizes compensating controls when patching is not feasible. Simply removing the software (A) may break business operations, extending the SLA (B) violates policy, and accepting risk (C) ignores the need for active mitigation.

Exam trap

The trap here is that candidates assume 'no patch available' means 'no action required' (Option C), but the SSCP exam expects proactive risk mitigation through compensating controls even when patching is delayed.

How to eliminate wrong answers

Option A is wrong because removing the vulnerable software immediately could cause significant operational disruption and is not required if compensating controls can reduce risk to an acceptable level. Option B is wrong because extending the SLA to 30 days violates the established 48-hour remediation policy and does not address the immediate threat; SLAs are not arbitrarily extended without formal risk acceptance. Option C is wrong because accepting risk without implementing any controls is negligent; the absence of a vendor patch does not justify inaction—compensating controls must be applied to reduce the likelihood of exploitation.

616
MCQmedium

A healthcare company must store backup tapes offsite for seven years. The tapes contain patient records, and the company wants a symmetric encryption algorithm that is fast, widely supported, and approved by NIST for protecting data at rest. Which algorithm best meets these requirements?

A.Diffie-Hellman key exchange with a 2048-bit group
B.AES with a 256-bit key
C.RSA with a 2048-bit key
D.SHA-256 hashing of each backup file
AnswerB

AES is a symmetric block cipher standardized by NIST and is the current approved algorithm for protecting sensitive data at rest. A 256-bit key provides a strong security margin, and AES performs efficiently on modern hardware, making it suitable for encrypting large backup tapes. It is widely supported across storage and backup platforms, matching the healthcare company's operational needs.

Why this answer

AES is a NIST-approved symmetric block cipher that provides strong confidentiality with high performance, which is essential for encrypting large volumes of backup data. A 256-bit key offers a conservative security margin for long-term storage. Hashing provides integrity only, RSA and Diffie-Hellman are asymmetric mechanisms not suited to bulk data-at-rest encryption, so AES is the appropriate choice.

Exam trap

The trap here is confusing integrity mechanisms such as hashing with confidentiality mechanisms, or assuming that any NIST-approved algorithm works for bulk encryption regardless of whether it is symmetric or asymmetric.

617
MCQhard

A security analyst is reviewing firewall logs and notices a high rate of TCP SYN packets to multiple ports on a server, but no corresponding ACK or RST packets. This is characteristic of which type of attack?

A.UDP flood
B.SYN flood
C.Smurf attack
D.Ping of death
AnswerB

A SYN flood exploits the TCP three-way handshake: the attacker sends numerous SYN packets, often with spoofed source addresses, so the server allocates resources and replies with SYN-ACK but never receives the final ACK. The absence of ACK or RST packets in the logs matches this half-open connection pattern.

Why this answer

A SYN flood exploits the TCP three-way handshake by sending many SYN packets, often with spoofed source addresses, so the server allocates half-open connection state and replies with SYN-ACK but never receives the final ACK. The absence of ACK or RST responses in the logs is the signature of this half-open connection exhaustion attack.

Exam trap

SSCP often tests the distinction between TCP-based and ICMP/UDP-based floods — candidates see 'high rate of packets' and jump to a generic flood, but the missing ACK/RST and the SYN-specific pattern are what identify a SYN flood.

How to eliminate wrong answers

Option A is wrong because a UDP flood sends connectionless UDP datagrams and would not produce TCP SYN packets or half-open TCP state at all. Option C is wrong because a Smurf attack uses ICMP echo requests sent to a broadcast address with a spoofed victim source, amplifying ICMP replies toward the victim — it involves ICMP, not TCP SYN/ACK behavior. Option D is wrong because a Ping of death relies on oversized or malformed ICMP packets that crash or destabilize a host during reassembly, not on incomplete TCP handshakes.

618
MCQeasy

Which term describes the risk that remains after implementing risk mitigation controls?

A.Accepted risk
B.Residual risk
C.Inherent risk
D.Control risk
AnswerB

Residual risk is the exposure that persists once mitigation controls are applied, since no control eliminates threat entirely. It directly satisfies the stem's requirement for risk remaining after implementation, distinguishing it from inherent risk (before controls) and total risk. Risk acceptance, transfer or avoidance address that remainder rather than describing it.

Why this answer

Residual risk is the risk that remains after all risk mitigation controls have been applied. It represents the portion of the original risk that cannot be eliminated or reduced further, and it must be accepted by management if it falls within the organization's risk appetite.

Exam trap

The trap here is that candidates confuse 'residual risk' with 'accepted risk,' but accepted risk is the subset of residual risk that management formally approves to tolerate, not the risk that remains after controls.

How to eliminate wrong answers

Option A is wrong because accepted risk is a decision to formally acknowledge and tolerate a specific risk, often after evaluating residual risk, not the risk that remains after controls. Option C is wrong because inherent risk is the level of risk before any controls are implemented, not after. Option D is wrong because control risk is the risk that a control may fail or be ineffective, not the leftover risk after controls are applied.

619
Multi-Selectmedium

A security analyst is reviewing the cryptographic controls for a new messaging application. The application must ensure that messages are encrypted in transit and that the sender cannot later deny having sent a message. Which two of the following cryptographic mechanisms should be implemented to meet these requirements? (Choose two.)

Select 2 answers
A.Digital signatures using the sender's private key
B.Keyed-hash message authentication code (HMAC)
C.TLS for encrypting messages in transit
D.Hashing messages with SHA-256
E.Symmetric encryption using a shared secret key
AnswersA, C

Digital signatures provide non-repudiation because they are generated with the sender's private key, which only the sender possesses. Anyone can verify the signature using the sender's public key, proving that the message originated from the sender and has not been altered. This directly meets the requirement that the sender cannot deny sending the message.

Why this answer

To encrypt messages in transit, TLS is appropriate as it provides confidentiality and integrity for data in transit. To ensure non-repudiation, digital signatures using the sender's private key are required because they uniquely bind the sender to the message. Symmetric encryption, hashing, and HMAC do not provide non-repudiation.

Exam trap

The trap here is confusing integrity mechanisms like HMAC or hashing with non-repudiation, which requires asymmetric cryptography.

620
MCQeasy

What is the PRIMARY purpose of a lessons learned meeting after an incident?

A.To assign blame for the incident
B.To satisfy regulatory compliance requirements
C.To calculate the financial cost of the incident
D.To identify improvements in the incident response process
AnswerD

Lessons learned exists to feed findings back into the incident response plan, refining procedures, tools and communication based on what actually happened. It satisfies the stem's primary-purpose constraint by targeting process improvement rather than blame, evidence preservation or immediate containment.

Why this answer

The primary purpose of a lessons learned meeting is to analyze the incident response process to identify what worked well and what did not, enabling the team to update procedures, playbooks, and tools to improve future responses. This aligns with the continuous improvement cycle mandated by frameworks like NIST SP 800-61, which emphasizes post-incident activity to refine detection and remediation capabilities.

Exam trap

The trap here is that candidates confuse the primary goal of process improvement with secondary outcomes like cost calculation or compliance, but the SSCP exam emphasizes that the core purpose is to enhance the incident response plan's effectiveness, not to assign blame or tally expenses.

How to eliminate wrong answers

Option A is wrong because lessons learned meetings are explicitly non-punitive and focus on process improvement, not assigning blame, which would discourage open reporting and hinder future incident handling. Option B is wrong while regulatory compliance may require documentation of post-incident reviews, the primary purpose is not compliance but operational improvement; compliance is a secondary benefit. Option C is wrong because calculating financial cost is typically part of a separate damage assessment or forensic accounting, not the core objective of a lessons learned meeting, which centers on process effectiveness.

621
MCQmedium

A security analyst receives an alert from the SIEM about a possible malware infection on a workstation. The analyst confirms the infection and begins containment. Which of the following actions BEST aligns with the containment phase of the NIST SP 800-61 incident response lifecycle?

A.Isolate the workstation from the network by disabling its switch port.
B.Immediately reimage the workstation to remove the malware.
C.Run a full antivirus scan on the workstation.
D.Document the incident in the ticketing system.
AnswerA

Isolating the workstation from the network prevents the malware from spreading to other systems, which is a primary goal of containment. Disabling the switch port effectively cuts off network communication while preserving the system state for later forensic analysis. This action directly limits the scope and impact of the incident, aligning with NIST SP 800-61 containment strategies.

Why this answer

Containment aims to limit the damage and prevent further spread of the incident. Isolating the infected workstation from the network achieves this by cutting off communication, which can stop lateral movement and command-and-control traffic. Other actions like reimaging or scanning are part of later phases such as eradication or recovery, and documentation, while necessary, does not contain the threat.

Exam trap

The trap here is confusing eradication actions like reimaging with containment, which is about stopping the spread.

622
MCQmedium

A security analyst notices a sudden increase in failed login attempts from a single IP address across multiple user accounts. Which risk response strategy is most appropriate to implement immediately?

A.Risk mitigation by blocking the IP address
B.Risk remediation by changing all user passwords
C.Risk transfer
D.Risk acceptance
AnswerA

Blocking the IP address at the firewall or Microsoft Entra ID sign-in policy immediately stops the brute-force attempts, directly satisfying the stem's demand for an immediate response. This is risk mitigation: applying a control to reduce the likelihood of credential compromise while investigation continues.

Why this answer

Blocking the offending IP address is a risk mitigation control that immediately reduces the likelihood of a brute-force or credential-stuffing attack succeeding. It directly addresses the active threat by cutting off the source, which is the fastest and most targeted response. Mitigation reduces risk impact or likelihood, which matches the scenario.

Exam trap

SSCP often tests risk response terminology, and candidates confuse mitigation (reduce likelihood/impact) with remediation (fix after an incident) or transfer (insurance), picking a disruptive but less appropriate action.

How to eliminate wrong answers

Option B is wrong because changing all user passwords is a remediation action that addresses the vulnerability after compromise but is disruptive and does not stop the ongoing attack — it is also not the immediate first step. Option C is wrong because risk transfer (e.g., cyber insurance) shifts financial impact but does nothing to stop an active attack. Option D is wrong because risk acceptance means acknowledging the risk without action, which is inappropriate for an active brute-force attempt.

623
MCQmedium

A security administrator is reviewing backup procedures for a database server. The current backup policy mandates a full backup every Sunday and differential backups Tuesday through Friday. On Wednesday, a failure occurs, and the database is lost. The last successful full backup was completed on Sunday, and the last differential backup was completed on Tuesday. How many backup sets are needed to restore the database to its state as of Tuesday?

A.4
B.3
C.2
D.1
AnswerC

Differential backups capture all changes since the last full backup, so restoring to Tuesday's state requires only the Sunday full backup plus the Tuesday differential. Two backup sets suffice; transaction logs or Wednesday's data are unnecessary for this recovery point.

Why this answer

To restore the database to its state as of Tuesday, you need the last full backup (Sunday) and the last differential backup (Tuesday). A differential backup contains all changes since the last full backup, so applying the Tuesday differential to the Sunday full backup recovers all data up to Tuesday. The Wednesday failure does not affect the Tuesday state, and no other backups are required.

Exam trap

The trap here is confusing differential backups with incremental backups, leading candidates to think they need all backups from Sunday through Tuesday (3 or 4 sets), when differential backups only require the last full and the most recent differential.

How to eliminate wrong answers

Option A is wrong because 4 backup sets would be needed only if you were using incremental backups (which require all backups since the last full), but the policy uses differential backups. Option B is wrong because 3 backup sets would be needed if you had to restore from Sunday full, Tuesday differential, and Wednesday differential (if it existed), but the Wednesday backup was never completed. Option D is wrong because 1 backup set (only the full backup) would restore the database to Sunday's state, not Tuesday's state, missing the changes captured in the Tuesday differential.

624
Multi-Selectmedium

A company is implementing single sign-on (SSO) for its internal applications. Which TWO of the following protocols are commonly used for SSO?

Select 2 answers
A.Kerberos
B.OAuth
C.LDAP
D.RADIUS
E.SAML
AnswersA, E

Kerberos provides ticket-based authentication within a trusted realm, issuing service tickets that let users access multiple internal applications without re-entering credentials. Its symmetric-key ticket exchange suits SSO for internal, domain-joined resources, satisfying the stem's requirement for a commonly used SSO protocol.

Why this answer

Kerberos (A) is a network authentication protocol that uses ticket-granting tickets (TGTs) and service tickets issued by a Key Distribution Center (KDC), enabling transparent single sign-on within a Windows/Active Directory domain environment. SAML (E) is an XML-based federation standard in which an identity provider (IdP) issues signed assertions to a service provider (SP), which is the classic browser-based SSO mechanism for internal and cloud applications. OAuth (B) is an authorization delegation framework (access tokens for APIs), not an authentication/SSO protocol by itself, so it does not fit the SSO requirement here.

LDAP (C) is a directory access protocol used to query and authenticate against a directory, but it does not provide cross-application SSO. RADIUS (D) is an AAA protocol for network access (VPN, Wi-Fi, 802.1X), not for application-level SSO.

Exam trap

The trap here is confusing authentication protocols with authorization or directory protocols; candidates often mistakenly select OAuth or LDAP because they are familiar with authentication concepts, but the question specifically asks for SSO protocols.

625
Multi-Selecthard

Which THREE of the following are considered cryptographic best practices for key management? (Select exactly 3.)

Select 3 answers
A.Separate keys used for encryption and digital signatures
B.Rotate keys periodically
C.Use hardware security modules (HSMs) for key storage
D.Publish symmetric keys on the company website for transparency
E.Store keys with the encrypted data for convenience
AnswersA, B, C

Using distinct keys for encryption and digital signatures enforces key separation, so compromise or misuse of one key does not undermine the other cryptographic function. This limits blast radius and preserves the assurance each operation depends on.

Why this answer

Option A is correct because key separation ensures that a key used for encryption is not reused for digital signatures, limiting the blast radius if one key is compromised and preventing cross-protocol attacks that arise from using the same key for different cryptographic purposes. Option B is correct because periodic key rotation limits the amount of data protected by any single key, so if a key is eventually compromised, only the data encrypted during that key's lifetime is exposed, which is a core requirement of frameworks like NIST SP 800-57. Option C is correct because HSMs provide tamper-resistant hardware that generates, stores, and performs cryptographic operations with keys in a protected boundary, so private or symmetric keys never exist in plaintext in general-purpose memory or on disk.

Option D is wrong because publishing symmetric keys destroys confidentiality entirely, since anyone could decrypt the data, and transparency is achieved through publishing algorithms or certificates, not secret keys. Option E is wrong because storing keys alongside the encrypted data means anyone who obtains the data also obtains the key, eliminating the protection that encryption is supposed to provide.

Exam trap

ISC2 often tests the misconception that convenience (like storing keys with data) is acceptable, when in fact it violates the core security principle of key separation and confidentiality.

626
Multi-Selecteasy

Which TWO of the following are examples of key risk indicators (KRIs)?

Select 2 answers
A.Number of unpatched critical vulnerabilities
B.Total number of employees
C.Percentage of systems with antivirus disabled
D.Average user satisfaction score
E.Number of security incidents this quarter
AnswersA, C

A high number indicates higher risk of exploitation.

Why this answer

The number of unpatched critical vulnerabilities directly measures the organization's exposure to known exploits. A KRI must be quantifiable and predictive of risk; unpatched vulnerabilities are a leading indicator of potential breaches, as attackers actively scan for and exploit such weaknesses. This metric is commonly tracked in vulnerability management programs to prioritize remediation efforts.

Exam trap

ISC2 often tests the distinction between leading indicators (KRIs) and lagging indicators (outcome metrics), so candidates mistakenly select 'Number of security incidents this quarter' because it seems risk-related, but it is a historical outcome, not a predictive risk indicator.

627
MCQhard

During a malware outbreak, a security analyst needs to contain the spread. The affected systems are on the same VLAN as critical servers. Which of the following containment actions should be performed FIRST to minimize impact?

A.Disable user accounts associated with the infected systems
B.Isolate the affected systems by applying VLAN quarantine or ACLs
C.Reboot the affected systems to clear malware from memory
D.Restore the affected systems from backup
AnswerB

VLAN quarantine or ACLs sever network reachability between the infected hosts and the critical servers sharing that VLAN, halting lateral spread without powering systems off and destroying volatile evidence. This directly satisfies the stem's requirement to minimise impact on the co-located critical servers first.

Why this answer

Isolating the affected systems by applying VLAN quarantine or ACLs is the correct first action because it immediately stops the malware from spreading laterally across the same VLAN to critical servers, while preserving forensic evidence. This network-level containment is faster and less disruptive than account or system-level changes, and it prevents the outbreak from propagating before any remediation begins.

Exam trap

The SSCP exam emphasizes that containment must occur at the network layer first, not at the host or user layer. The trap here is that candidates mistakenly choose to reboot or disable accounts, thinking they are stopping the infection, when in fact they are ignoring the immediate lateral spread risk.

How to eliminate wrong answers

Option A is wrong because disabling user accounts does not stop network-level propagation of malware; the infected systems can still communicate and spread the malware via network protocols even if the user account is disabled. Option C is wrong because rebooting may clear malware from memory but does not prevent reinfection from persistent components or lateral movement, and it can destroy volatile forensic evidence. Option D is wrong because restoring from backup is a recovery step, not a containment step; it should only be performed after the threat is contained and the root cause is understood, to avoid reintroducing the infection.

628
Multi-Selecthard

An organization is enhancing its backup strategy. According to the 3-2-1 rule, which THREE characteristics must the backup strategy include? (Select THREE)

Select 3 answers
A.At least two different media types
B.Daily full backups
C.At least one copy stored offsite
D.At least three copies of the data
E.Encryption of all backups
AnswersA, C, D

Two distinct media types ensure a single media failure cannot destroy every copy, satisfying the redundancy element of the 3-2-1 rule. This complements the three copies and one offsite copy the strategy must also include.

Why this answer

The 3-2-1 backup rule requires three copies of the data (option D), meaning the original plus two backups, which ensures redundancy if one copy is lost or corrupted. It also requires at least two different media types (option A), such as disk and tape or local disk and cloud storage, so a single media failure cannot destroy all backups. Finally, it requires at least one copy stored offsite (option C), protecting against site-wide disasters like fire, flood, or theft.

Option B (daily full backups) is a scheduling/retention choice, not part of the 3-2-1 rule, and option E (encryption) is a security best practice but not one of the 3-2-1 characteristics.

Exam trap

Candidates often confuse the 3-2-1 rule with other backup best practices like encryption or frequency. The rule strictly requires: three copies, two different media types, and one offsite copy. Security professionals may mistakenly think daily full backups or encryption are part of the rule, but they are not.

629
MCQhard

A cloud security team is deploying a new web application on an IaaS platform. According to the shared responsibility model, which of the following security tasks is the customer responsible for?

A.Network infrastructure security such as DDoS protection at the provider edge
B.Hypervisor security and vulnerability management
C.Patching the guest operating system and web server software
D.Physical security of the data center hosting the servers
AnswerC

In IaaS, the provider secures the physical hosts, network and hypervisor only. The customer retains control of everything above the hypervisor, so patching the guest OS and web server software falls to them. This satisfies the shared responsibility split for IaaS workloads.

Why this answer

Patching the guest operating system and web server software is correct because in the IaaS shared responsibility model, the customer controls and is responsible for everything from the guest OS upward — including OS patches, middleware, runtime, and application code. The provider secures the physical hosts, hypervisor, and network fabric beneath the virtualization layer.

Exam trap

SSCP often tests where the responsibility boundary sits in IaaS — candidates over-attribute security tasks to the provider, forgetting that the customer owns the guest OS and everything above it.

How to eliminate wrong answers

Option A is wrong because DDoS protection at the provider edge is part of the cloud provider's responsibility for the underlying network infrastructure, not the customer's. Option B is wrong because hypervisor security and vulnerability management are handled by the cloud provider, since the hypervisor sits below the customer's control boundary in IaaS. Option D is wrong because physical security of data centers is always the provider's responsibility in every cloud service model.

630
MCQhard

A security analyst discovers that an internal DNS server is returning incorrect IP addresses for legitimate domains. The analyst suspects that an attacker has compromised the DNS resolver's cache. Which type of attack has likely occurred?

A.DNS amplification attack
B.SYN flood
C.DNS tunneling
D.DNS poisoning
AnswerD

DNS poisoning corrupts a resolver's cache with forged records, causing legitimate domain names to resolve to attacker-supplied IP addresses, satisfying the stem's symptom of incorrect addresses for valid domains. Spoofing intercepts a single response; poisoning persists in the cache for the record's TTL.

Why this answer

DNS poisoning (also called DNS cache poisoning or spoofing) occurs when an attacker injects forged DNS records into a resolver's cache, causing it to return incorrect IP addresses for legitimate domain names. The symptom described — a compromised resolver cache returning wrong IPs — is the textbook definition of this attack.

Exam trap

SSCP often tests the difference between attacks that corrupt DNS data (poisoning/spoofing) and attacks that abuse DNS as a transport or amplifier (tunneling, amplification) — candidates confuse 'DNS attack' with 'DNS poisoning' without checking whether records were actually altered.

How to eliminate wrong answers

Option A is wrong because a DNS amplification attack abuses open resolvers to send large responses to a spoofed victim for volumetric DDoS, not to corrupt cached records. Option B is wrong because a SYN flood is a TCP-layer resource exhaustion attack and does not alter DNS resolution results. Option C is wrong because DNS tunneling encodes data inside DNS queries/responses to exfiltrate information or establish covert C2 channels; it does not typically cause legitimate domains to resolve to wrong addresses.

631
MCQhard

Based on the exhibit, if the user attempts to upload (write) a file to the shared data repository corporate-data, what is the result?

A.Allowed because the access policy likely allows public writes
B.Denied because the explicit deny overrides any allow
C.Denied because write permission is not explicitly allowed
D.Allowed because the policy also allows read access
AnswerB

In NTFS, an explicit deny entry takes precedence over any inherited or explicit allow, so the write attempt fails regardless of granted permissions. The deny ACE on the corporate-data repository therefore blocks the upload outright, satisfying the exhibit's constraint that write access is refused.

Why this answer

The resource's access control policy includes an explicit deny statement that denies write permission for the user's principal. In standard access control policy evaluation, an explicit deny always overrides any allow, regardless of other permissions. Therefore, even if other statements allow write access, the explicit deny blocks the upload.

Exam trap

The trap here is that candidates often assume an explicit allow for write would override a deny, but in access control policies, an explicit deny always wins, making the presence of any deny statement the decisive factor.

How to eliminate wrong answers

Option A is wrong because the bucket policy does not allow public puts; it contains an explicit deny that overrides any potential allow. Option C is wrong because the issue is not the absence of an explicit allow but the presence of an explicit deny, which takes precedence. Option D is wrong because GetObject permission is irrelevant to PutObject; each action is evaluated independently, and the explicit deny for PutObject still applies.

632
MCQeasy

When implementing a digital signature, which key is used to create the signature?

A.Receiver's private key
B.Sender's private key
C.Sender's public key
D.Receiver's public key
AnswerB

A digital signature is produced by encrypting a hash of the message with the sender's private key. Only the sender possesses that key, so any recipient using the corresponding public key can verify authenticity and integrity, providing non-repudiation.

Why this answer

In a digital signature scheme, the sender uses their own private key to create the signature. This ensures non-repudiation because only the sender possesses that private key, and the corresponding public key can verify the signature. The process involves encrypting a hash of the message with the sender's private key, as specified in standards like PKCS#1 and RFC 8017.

Exam trap

The trap here is that candidates often confuse the roles of keys in encryption versus signing, mistakenly thinking the receiver's private key or the sender's public key is used to create the signature because they associate 'private' with secrecy and 'public' with sharing, without understanding the specific asymmetric operations required for non-repudiation.

How to eliminate wrong answers

Option A is wrong because the receiver's private key is used for decryption in asymmetric encryption, not for creating a digital signature; using it would allow anyone with the receiver's public key to forge the signature. Option C is wrong because the sender's public key is used to verify the signature, not create it; using it to sign would allow anyone to create a valid signature since the public key is widely known. Option D is wrong because the receiver's public key is used for encrypting messages to the receiver, not for signing; it cannot provide non-repudiation as the sender does not possess the corresponding private key.

633
MCQeasy

A security administrator needs to ensure that a terminated employee loses access to all systems immediately upon departure. Which action best accomplishes this?

A.Remove the employee from the payroll system only.
B.Schedule the account for deletion at the next quarterly access review.
C.Disable the user account in the central directory and revoke active sessions and tokens.
D.Change the employee's password and notify the manager of the new credential.
AnswerC

Disabling the directory account stops new authentications, while revoking sessions and tokens terminates existing access that would otherwise persist. Together they provide immediate, comprehensive revocation across federated and single sign-on systems. This is the standard offboarding action for prompt access removal.

Why this answer

Immediate access removal requires disabling the identity in the central directory and revoking any active sessions or tokens. Directory disablement blocks new logins across connected systems, and session revocation closes the gap for already-authenticated connections. Password changes, payroll-only removal, or delayed deletion all leave exploitable access in place.

Exam trap

The trap here is believing that changing a password or removing payroll access terminates system access, when active sessions and directory identities remain valid.

634
Multi-Selectmedium

An organization wants to implement separation of duties to reduce the risk of fraud. Which THREE of the following are common techniques used to enforce separation of duties?

Select 3 answers
A.Audit logging and monitoring of privileged actions
B.Role-based access control with mutually exclusive roles
C.Enforcing complex password policies
D.Using biometric authentication
E.Requiring two or more people to approve a transaction
AnswersA, B, E

Logging and monitoring privileged actions creates accountability and detects abuse, deterring fraud because no single actor can act unobserved. This detective control supports separation of duties by exposing attempts to combine conflicting responsibilities, satisfying the stem's requirement.

Why this answer

Option A (audit logging and monitoring of privileged actions) is correct because separation of duties requires accountability: recording and reviewing who did what (e.g., via SIEM, Windows Event Log, or syslog) deters and detects fraud by ensuring no single actor can act unobserved. Option B (role-based access control with mutually exclusive roles) is correct because RBAC assigns permissions to roles rather than individuals, and defining mutually exclusive roles (e.g., a user cannot hold both 'accounts payable' and 'accounts receivable' roles) technically prevents one person from controlling an entire transaction lifecycle. Option E (requiring two or more people to approve a transaction) is correct because dual control / two-person integrity (also called the four-eyes principle) splits a critical action across multiple parties, so no single individual can authorize a fraudulent transaction alone.

Option C (enforcing complex password policies) is not a separation-of-duties technique; it strengthens authentication against guessing/brute-force but does nothing to divide duties among people. Option D (using biometric authentication) is also not a separation-of-duties control; it improves identity assurance for a single user but does not prevent that user from holding conflicting responsibilities.

Exam trap

The trap is confusing authentication hardening (passwords, biometrics) with authorization controls like SoD; candidates may select password policies or biometrics thinking they enforce separation, but they only verify identity.

635
Multi-Selectmedium

A security incident response team is reviewing their disaster recovery plan. They need to ensure that their backup strategy supports recovery from a ransomware attack that encrypts critical files. Which TWO of the following are essential characteristics of an effective backup strategy for this scenario? (Choose two.)

Select 2 answers
A.Backups are stored offline or in an immutable format.
B.Backup restoration procedures are tested regularly.
C.Backups are encrypted with a key stored on the same server.
D.Backups are retained for at least seven years.
E.Backups are performed daily to the same network share.
AnswersA, B

Offline or immutable backups prevent ransomware from encrypting the backup data, ensuring that a clean copy is available for restoration. This is critical because ransomware often targets connected backups. Storing backups offline or using write-once-read-many (WORM) storage ensures that even if the network is compromised, the backups remain intact and can be used to recover.

Why this answer

An effective backup strategy against ransomware must ensure that backups cannot be encrypted by the attacker and that they can be successfully restored. Offline or immutable backups provide protection from encryption, and regular testing verifies that restoration will work when needed. Other factors like retention period or encryption key management are important but not as directly critical for this specific threat.

Exam trap

The trap here is focusing on backup frequency or retention rather than on protecting backups from being encrypted.

636
MCQmedium

A financial services company is deploying a new VPN concentrator that must support perfect forward secrecy (PFS) for all client sessions. The security team is configuring the IPsec phase 2 (Quick Mode) proposals. Which of the following should be configured to achieve PFS?

A.Set the phase 1 lifetime to be shorter than the phase 2 lifetime.
B.Configure the phase 1 proposal to use RSA signatures for authentication.
C.Enable Diffie-Hellman group 14 in the phase 2 proposal.
D.Use AES-256-GCM for the phase 2 encryption algorithm.
AnswerC

Perfect forward secrecy in IPsec is achieved by performing a new Diffie-Hellman key exchange during phase 2 (Quick Mode). Specifying a DH group such as group 14 (2048-bit MODP) in the phase 2 proposal ensures that a fresh key is generated for each session, so compromise of one session key does not expose past or future session keys.

Why this answer

Perfect forward secrecy in IPsec is achieved by including a Diffie-Hellman group in the phase 2 (Quick Mode) proposal. This forces a new key exchange for each session, ensuring that compromise of one session key does not compromise other sessions. Encryption algorithms and authentication methods do not provide PFS; they serve different purposes.

Exam trap

The trap here is confusing authentication or encryption algorithms with key exchange mechanisms, assuming that strong encryption alone provides perfect forward secrecy.

637
MCQmedium

A security analyst is evaluating encryption modes for a new system that requires authenticated encryption to ensure both confidentiality and integrity of data in transit. Which AES mode should the analyst recommend?

A.ECB
B.CBC
C.CTR
D.GCM
AnswerD

GCM combines AES counter-mode encryption with GHASH authentication, producing a tag that verifies integrity alongside confidentiality in a single pass. This satisfies the authenticated encryption requirement, unlike CBC or CTR, which provide confidentiality only and need a separate MAC.

Why this answer

GCM (Galois/Counter Mode) is the correct choice because it provides authenticated encryption, combining the confidentiality of CTR mode with integrity verification via a Galois field authentication tag. This makes it ideal for securing data in transit, as it ensures both privacy and tamper detection in a single, efficient operation.

Exam trap

The trap here is that candidates often confuse confidentiality-only modes (like CBC or CTR) with authenticated encryption, overlooking that GCM is the only option listed that natively provides both encryption and integrity in a single mode.

How to eliminate wrong answers

Option A is wrong because ECB (Electronic Codebook) mode encrypts each block independently, producing identical ciphertext for identical plaintext blocks, which leaks patterns and provides no integrity protection. Option B is wrong because CBC (Cipher Block Chaining) mode ensures confidentiality through chaining but does not inherently provide authentication or integrity; it requires a separate MAC (e.g., HMAC) for authenticated encryption. Option C is wrong because CTR (Counter) mode offers confidentiality by encrypting a counter value, but like CBC, it lacks built-in integrity verification and is vulnerable to bit-flipping attacks without an additional authentication mechanism.

638
MCQmedium

A security analyst notices unusual outbound traffic from a server in the DMZ to an external IP address on port 4444. The server runs a web application. Which action should the analyst take first?

A.Disconnect the server from the network.
B.Reboot the server to clear any malware.
C.Check the server's running processes and established connections.
D.Block the outbound traffic at the firewall.
AnswerC

Port 4444 outbound traffic suggests a reverse shell; checking running processes and established connections identifies the responsible process and command-and-control channel before blocking, preserving evidence. This satisfies the scenario's need for the first investigative step on the DMZ server.

Why this answer

The first step in incident response is to gather forensic evidence and understand the scope of the compromise. Checking running processes and established connections allows the analyst to identify the malicious process, its parent, and the active command-and-control (C2) channel on port 4444, which is commonly associated with reverse shells or backdoor traffic. This data is volatile and must be captured before any disruptive action like disconnection or reboot, which would destroy evidence.

Exam trap

The trap here is that candidates often choose to immediately block or disconnect, confusing containment with the first step of incident response, which must always be evidence preservation and scoping.

How to eliminate wrong answers

Option A is wrong because immediately disconnecting the server from the network destroys volatile evidence (e.g., active network connections, memory-resident malware) and may alert the attacker, hindering forensic analysis. Option B is wrong because rebooting clears memory-resident malware and volatile forensic data, such as running processes and network connections, making root cause analysis impossible. Option D is wrong because blocking outbound traffic at the firewall without first investigating the source may disrupt the attacker's C2 channel, but it also prevents the analyst from observing the attacker's actions and collecting evidence; it should be done only after evidence is preserved.

639
MCQmedium

A security administrator is reviewing the organization's account management process. The policy states that user accounts must be reviewed at least quarterly to ensure that only authorized individuals retain access. During an audit, it is discovered that several former employees still have active accounts. Which of the following is the MOST appropriate action to address this finding?

A.Immediately disable the accounts and then review the account management process to identify why the accounts were not removed.
B.Delete the accounts and then perform a full audit of all user accounts to ensure no other former employees have access.
C.Document the finding in the audit report and schedule the account removals for the next quarterly review cycle.
D.Reset the passwords on the accounts and notify the former employees' managers to confirm whether access is still needed.
AnswerA

Disabling the accounts immediately removes the unauthorized access risk posed by former employees. Following that, reviewing the process identifies the root cause of the failure to remove accounts, such as a missing trigger from HR, and allows the administrator to implement corrective controls to prevent recurrence. This aligns with the SSCP principle of least privilege and timely access revocation.

Why this answer

The most critical step is to immediately disable the accounts to eliminate the unauthorized access. Then, the administrator should investigate why the accounts were not removed to prevent similar issues. Deleting accounts can destroy evidence and is not best practice; resetting passwords does not revoke access; and delaying action increases risk.

Thus, disabling and then reviewing the process is the correct approach.

Exam trap

The trap here is assuming that resetting passwords or deleting accounts is sufficient, when the primary goal is to revoke access quickly while preserving audit trails and addressing the root cause.

640
MCQmedium

After an incident, the team identifies that the incident was caused by a missing security patch. Which of the following is the MOST effective way to prevent recurrence?

A.Conduct phishing simulations
B.Increase network monitoring
C.Implement a patch management policy
D.Update the incident response plan
AnswerC

A patch management policy establishes repeatable scanning, testing and deployment cycles, removing the root cause rather than reacting to individual incidents. This satisfies the stem's recurrence-prevention goal, unlike one-off remediation or awareness training that would not systematically close the missing-patch gap.

Why this answer

A missing security patch indicates a failure in the vulnerability management lifecycle. Implementing a patch management policy ensures that patches are systematically identified, tested, and deployed, directly addressing the root cause. This is the most effective preventive measure because it establishes a recurring process to close known vulnerabilities before they can be exploited.

Exam trap

The trap here is that candidates often confuse reactive measures (monitoring, response plans) with proactive prevention, or they mistakenly think user training (phishing simulations) addresses a technical configuration failure.

How to eliminate wrong answers

Option A is wrong because phishing simulations address social engineering attacks, not missing patches; they test user awareness, not system configuration. Option B is wrong because increasing network monitoring improves detection of ongoing attacks but does not prevent exploitation of unpatched vulnerabilities. Option D is wrong because updating the incident response plan improves future response efficiency but does not prevent the initial cause—the missing patch—from recurring.

641
Multi-Selecteasy

A network administrator is implementing segmentation to limit the spread of malware. Which two technologies can achieve network segmentation? (Choose two.)

Select 2 answers
A.Firewalls
B.VPN
C.NAT
D.Subnetting
E.VLANs
AnswersA, E

Firewalls can segment by controlling traffic between network zones.

Why this answer

Firewalls are correct because they can enforce network segmentation by controlling traffic between network segments based on security policies. By placing firewalls at segment boundaries, administrators can filter traffic using rules that inspect source/destination IP addresses, ports, and application-layer data, thereby limiting the lateral spread of malware.

Exam trap

The trap here is that candidates often confuse subnetting with segmentation, not realizing that subnetting alone provides no traffic filtering or isolation without a firewall or router ACL, and that VPNs are for secure tunneling, not internal network partitioning.

642
MCQmedium

A security administrator is implementing an access control system that uses sensitivity labels on subjects and objects. The policy dictates that a subject can only read objects with a label equal to or lower than the subject's clearance, and can only write to objects with a label equal to or higher than the subject's clearance. Which access control model and principle is being enforced?

A.MAC with Bell-LaPadula model
B.MAC with Biba model
C.DAC with owner-based permissions
D.RBAC with role hierarchy
AnswerA

Bell-LaPadula enforces mandatory access control through the no-read-up and no-write-down rules, matching the stated label comparisons exactly. Sensitivity labels on subjects and objects, rather than owner discretion, make the model mandatory, satisfying both the read and write constraints described.

Why this answer

The Bell-LaPadula model is a mandatory access control (MAC) model focused on confidentiality. Its two core rules are the Simple Security Property (no read up: a subject can only read objects at or below its clearance) and the Star Property (no write down: a subject can only write to objects at or above its clearance). The scenario describes exactly these two rules, so MAC with Bell-LaPadula is the correct answer.

Exam trap

SSCP often tests the confusion between Bell-LaPadula (confidentiality: no read up, no write down) and Biba (integrity: no read down, no write up) — candidates who memorize only one direction of the rules pick the wrong model.

How to eliminate wrong answers

Option B is wrong because the Biba model enforces integrity, not confidentiality — its rules are 'no read down' and 'no write up,' the inverse of what the question describes. Option C is wrong because DAC relies on owner-assigned discretionary permissions rather than sensitivity labels and clearances. Option D is wrong because RBAC assigns permissions through roles based on job function, not through sensitivity labels and clearance levels.

643
Multi-Selecteasy

Which TWO protocols are considered insecure and should be replaced with secure alternatives? (Choose two.)

Select 2 answers
A.IPsec
B.Telnet
C.HTTPS
D.SNMPv3
E.FTP
AnswersB, E

Telnet transmits all data, including credentials, in cleartext, offering no encryption or integrity protection. This directly satisfies the stem's requirement for an insecure protocol needing replacement; SSH provides the secure alternative. Its lack of confidentiality makes it unsuitable for any authenticated administrative access across untrusted networks.

Why this answer

Both Telnet and FTP are considered insecure because they transmit data, including login credentials, in cleartext. Telnet (B) uses TCP port 23 and lacks encryption, making it vulnerable to packet sniffing and man-in-the-middle attacks. FTP (E) similarly transmits usernames and passwords over TCP port 21 in cleartext, and also allows anonymous access and passive data transfer issues.

Secure alternatives include SSH for remote access (replacing Telnet) and SFTP or FTPS for file transfer (replacing FTP). IPsec (A), HTTPS (C), and SNMPv3 (D) are all considered secure protocols as they incorporate encryption and authentication.

Exam trap

ISC2 often tests the distinction between secure and insecure versions of protocols, where candidates mistakenly think SNMPv3 or IPsec are insecure because they confuse them with older versions (SNMPv1/v2c) or assume all VPN protocols are vulnerable.

644
MCQeasy

A company wants to ensure that data transmitted between its two branch offices remains confidential. Which cryptographic goal is primarily being addressed?

A.Availability
B.Non-repudiation
C.Integrity
D.Confidentiality
AnswerD

Confidentiality directly satisfies the stem's requirement that transmitted data remain secret between branch offices. Encryption ensures only intended recipients can read the data, preventing eavesdroppers on the link from interpreting it. This cryptographic goal maps precisely to protecting data in transit, unlike integrity, authentication or non-repudiation, which address different security objectives.

Why this answer

Confidentiality ensures that data is accessible only to authorized parties, typically achieved through encryption. In this scenario, the company wants to prevent unauthorized interception of data between branch offices, which is the core goal of confidentiality. Technologies such as IPsec VPNs or TLS are used to encrypt the data in transit, directly addressing this requirement.

Exam trap

The trap here is that candidates often confuse confidentiality with integrity, mistakenly thinking that protecting data from modification also prevents it from being read, but encryption alone does not guarantee integrity unless combined with a MAC or authenticated encryption mode like GCM.

How to eliminate wrong answers

Option A is wrong because availability ensures that systems and data are accessible when needed, often through redundancy or fault tolerance, not by protecting data from eavesdropping. Option B is wrong because non-repudiation provides proof of origin or delivery of data, typically via digital signatures, and does not prevent unauthorized reading of the data. Option C is wrong because integrity ensures that data has not been altered during transit, often using hashing or MACs, but does not protect against unauthorized viewing of the data.

645
MCQhard

A company is preparing for a PCI DSS assessment. According to PCI DSS requirements, how frequently must internal vulnerability scans be performed?

A.Annually
B.Monthly
C.Weekly
D.Quarterly
AnswerD

PCI DSS mandates that internal vulnerability scans be run at least quarterly, satisfying the assessment's recurring scanning obligation. Scans must also be repeated after any significant network change, but the baseline cadence the question asks for is quarterly.

Why this answer

PCI DSS Requirement 11.2.1 mandates that internal vulnerability scans must be performed at least quarterly and after any significant change in the network. This frequency ensures that new vulnerabilities introduced since the last scan are identified and remediated before they can be exploited. Quarterly scans are a minimum; more frequent scanning is recommended for high-risk environments.

Exam trap

The trap here is that candidates often confuse the quarterly internal scan requirement with the weekly external scan requirement (for internet-facing systems), leading them to incorrectly select 'Weekly' as the answer.

How to eliminate wrong answers

Option A is wrong because annual scans are far too infrequent to meet PCI DSS requirements, which demand a minimum of quarterly scans to keep pace with emerging vulnerabilities. Option B is wrong because monthly scans, while more frequent than required, are not the mandated minimum; PCI DSS specifically requires quarterly scans, not monthly. Option C is wrong because weekly scans are not required by PCI DSS for internal scans; the standard explicitly states quarterly as the baseline frequency, though weekly scans may be used for external scans or as a best practice.

646
MCQmedium

A system administrator receives an alert from the SIEM indicating a possible brute-force attack on a server. The logs show 100 failed logins in 2 minutes from a single source. Which of the following is the best immediate action to verify and respond?

A.Immediately disable the user account that was targeted most
B.Check firewall logs for the source IP and block it in the firewall
C.Reset all user passwords and enable multi-factor authentication
D.Ignore the alert because it is likely a false positive
AnswerB

Checking firewall logs confirms whether the 100 failed logins actually reached the server from that source, and blocking the IP immediately stops the brute-force attempt. This verifies the SIEM alert against an independent log source while containing the attack, satisfying the stem's requirement to verify and respond.

Why this answer

The immediate priority is to stop the ongoing attack by blocking the source IP at the firewall. Checking firewall logs confirms the source IP and ensures the block is applied to the correct address, preventing further authentication attempts. This aligns with the principle of containment before remediation in incident response.

Exam trap

The trap here is that candidates confuse immediate containment (blocking the source IP) with long-term remediation (resetting passwords or disabling accounts), leading them to choose a reactive user-focused action instead of a network-level control to stop the attack in progress.

How to eliminate wrong answers

Option A is wrong because disabling the targeted user account does not stop the brute-force attack; the attacker can simply target another account or continue with different usernames, and it may disrupt legitimate user access without addressing the source. Option C is wrong because resetting all passwords and enabling MFA is a long-term remediation step, not an immediate action; it is premature without first verifying the attack and containing it, and it could cause widespread disruption. Option D is wrong because ignoring the alert assumes a false positive without verification; 100 failed logins in 2 minutes from a single source is a strong indicator of a brute-force attack and requires investigation, not dismissal.

647
MCQhard

A security analyst is reviewing network traffic and notices that an attacker is sending forged ARP replies to a host, attempting to associate the attacker's MAC address with the IP address of the default gateway. Which security feature should be implemented on the switch to prevent this attack?

A.Port security
B.DHCP snooping
C.Dynamic ARP Inspection (DAI)
D.802.1X authentication
AnswerC

Dynamic ARP Inspection (DAI) validates ARP packets on untrusted ports by comparing the IP-to-MAC binding against a trusted database, such as the DHCP snooping binding table. It drops ARP packets with invalid bindings, preventing ARP spoofing attacks. This directly addresses the scenario where an attacker is sending forged ARP replies to impersonate the default gateway.

Why this answer

Dynamic ARP Inspection (DAI) is the switch feature designed to prevent ARP spoofing by validating ARP packets against a trusted binding table. It drops ARP packets that contain invalid IP-to-MAC mappings, thereby blocking the attacker's attempt to associate their MAC with the gateway's IP. Other features like port security, DHCP snooping, or 802.1X do not provide this specific ARP validation.

Exam trap

The trap here is confusing DHCP snooping with Dynamic ARP Inspection; DHCP snooping builds the binding table but does not filter ARP packets, while DAI actively validates and drops malicious ARP replies.

648
Multi-Selecthard

Which THREE of the following are appropriate techniques for securely disposing of magnetic hard disk drives that contain sensitive data? (Choose three.)

Select 3 answers
A.Low-level format
B.Shredding
C.Quick format
D.Overwriting with random patterns
E.Degaussing
AnswersB, D, E

Shredding physically reduces magnetic platters to small fragments, making data recovery impossible even with laboratory techniques. It satisfies the stem's requirement for secure disposal of magnetic media, unlike overwriting or degaussing alone, which may leave residual data. Shredding is therefore an appropriate technique for destroying sensitive data on hard disk drives.

Why this answer

Shredding (B) is correct because physically destroying the magnetic platters into small particles makes data recovery impossible, which is the strongest disposal method for magnetic HDDs. Overwriting with random patterns (D) is correct because repeatedly writing random data across the entire disk renders the original sensitive data unrecoverable, and it is a standard sanitization technique for magnetic media. Degaussing (E) is correct because exposing the drive to a strong magnetic field destroys the magnetic alignment of the platters, erasing the data and typically also rendering the drive unusable.

Low-level format (A) is not appropriate because it only recreates the disk's physical structure and does not securely erase existing data. Quick format (C) is not appropriate because it merely removes file system references while leaving the underlying data intact and recoverable.

Exam trap

The trap here is that candidates often confuse 'low-level format' or 'quick format' with secure erasure, not realizing these methods leave recoverable data on the platters.

649
Multi-Selectmedium

Which TWO of the following are characteristics of a Mandatory Access Control (MAC) system?

Select 2 answers
A.Access decisions are based on security labels.
B.Access is determined by the owner of the object.
C.It uses roles to assign permissions.
D.Users can change permissions on their own objects.
E.It is commonly used in military environments.
AnswersA, E

MAC decisions derive from security labels assigned to subjects and objects, not owner discretion. The label comparison, typically enforcing Bell-LaPadula or Biba rules, is what makes access mandatory: users cannot alter or override classifications, satisfying the stem's requirement for label-driven control.

Why this answer

Option A is correct because a MAC system bases every access decision on security labels (sensitivity levels and categories) assigned to subjects and objects, rather than on user discretion; the system compares these labels against a policy to grant or deny access. Option E is correct because MAC is historically and commonly implemented in military and government environments, where strict confidentiality and need-to-know enforcement (e.g., via labels like Top Secret, Secret, Confidential) is required. Option B is incorrect because basing access on the object's owner describes Discretionary Access Control (DAC), where the owner decides who gets access.

Option C is incorrect because using roles to assign permissions describes Role-Based Access Control (RBAC), not MAC. Option D is incorrect because allowing users to change permissions on their own objects is a hallmark of DAC, whereas in MAC users cannot alter the labels or permissions that govern access.

Exam trap

The trap here is that candidates often confuse MAC with DAC or RBAC, mistakenly thinking that owners or roles can override label-based policies, when in fact MAC strictly enforces system-wide rules that neither users nor owners can modify.

650
MCQeasy

During which phase of the NIST SP 800-61 incident response lifecycle are incident response plan updates and lessons learned typically documented?

A.Preparation
B.Containment, Eradication, and Recovery
C.Detection and Analysis
D.Post-Incident Activity
AnswerD

Post-Incident Activity is where the NIST SP 800-61 lifecycle captures lessons learned and revises the incident response plan. This phase explicitly covers reviewing what happened and feeding improvements back into the plan, satisfying the stem's requirement.

Why this answer

The Post-Incident Activity phase of NIST SP 800-61 is specifically designed for conducting lessons learned meetings, documenting improvements, and updating the incident response plan based on findings from the incident. This phase ensures that the organization captures feedback to refine procedures, tools, and training for future incidents.

Exam trap

The trap here is that candidates confuse the Post-Incident Activity phase with the Preparation phase, mistakenly thinking that plan updates occur before incidents, but NIST SP 800-61 explicitly places lessons learned and plan updates after the incident is resolved.

How to eliminate wrong answers

Option A is wrong because the Preparation phase focuses on establishing policies, tools, and training before an incident occurs, not on documenting updates after an incident. Option B is wrong because Containment, Eradication, and Recovery phases are operational steps to stop the incident, remove threats, and restore systems, not for retrospective documentation. Option C is wrong because Detection and Analysis involves identifying and analyzing potential incidents, not capturing lessons learned or updating plans.

651
Multi-Selecthard

Which THREE of the following are critical elements of a patch management policy? (Select THREE)

Select 3 answers
A.Patch prioritization based on CVSS score and asset criticality
B.Immediate deployment of all patches without testing
C.Annual review of patch status
D.Vulnerability scanning to identify missing patches
E.Testing patches in a staging environment
AnswersA, D, E

Prioritisation using CVSS severity combined with asset criticality directs remediation effort to the most exploitable flaws on the most valuable systems, satisfying the policy's need to sequence patching within limited maintenance windows rather than treating every vulnerability identically.

Why this answer

Option A is correct because a sound patch management policy must rank patches by risk, combining the CVSS base score (e.g., 9.8 Critical) with the business criticality of the affected asset so that the most dangerous exposures on the most important systems are remediated first. Option D is correct because you cannot patch what you have not found; regular authenticated vulnerability scanning (e.g., credentialed scans with Nessus or Qualys) is the mechanism that identifies missing patches and misconfigurations and feeds the remediation workflow. Option E is correct because patches should be validated in a staging or test environment that mirrors production before broad rollout, catching application compatibility and regression issues while still meeting the policy's remediation deadlines.

Option B is not part of a policy because deploying every patch immediately with no testing risks outages and is the opposite of a controlled, risk-based process. Option C is not adequate because reviewing patch status only annually leaves systems exposed for months; effective policies require continuous or at least monthly monitoring and reporting of patch compliance.

Exam trap

In this question, the trap is that candidates might select 'Immediate deployment of all patches without testing' (Option B) or 'Annual review of patch status' (Option C) thinking they are critical elements. However, patch management requires testing, prioritization, and continuous verification, not haphazard deployment or infrequent reviews.

652
MCQmedium

A security analyst notices an unusual number of ARP replies on the network where one MAC address is claiming to be multiple IP addresses. Which type of attack is most likely occurring?

A.ARP spoofing
B.SYN flood
C.DNS poisoning
D.DHCP starvation
AnswerA

ARP spoofing involves an attacker sending forged ARP replies that bind one MAC address to multiple IP addresses, poisoning neighbours' ARP caches so traffic is redirected to the attacker. This matches the observed pattern of conflicting ARP mappings.

Why this answer

ARP spoofing (or ARP poisoning) involves an attacker sending forged ARP replies to associate their MAC address with multiple IP addresses, causing traffic intended for those IPs to be redirected to the attacker. This matches the scenario where one MAC address claims to be multiple IP addresses. The goal is often to intercept, modify, or block network traffic (man-in-the-middle).

Exam trap

SSCP often tests the confusion between ARP spoofing and other network attacks like DNS poisoning or DHCP starvation, where candidates might focus on the 'multiple IP addresses' aspect and incorrectly choose DHCP starvation, which also involves multiple IPs but through a different mechanism.

How to eliminate wrong answers

Option B is wrong because a SYN flood is a denial-of-service attack that exploits the TCP three-way handshake by sending many SYN packets without completing the handshake, not by sending ARP replies. Option C is wrong because DNS poisoning involves corrupting DNS cache records to redirect domain name resolution, not ARP traffic. Option D is wrong because DHCP starvation exhausts the DHCP server's pool of IP addresses by sending numerous DHCP requests with spoofed MAC addresses, not by sending ARP replies claiming multiple IPs.

653
MCQhard

During a user offboarding process, the security team must ensure that the former employee's access is revoked immediately. However, the user's manager requests that the account remain active for a week to review files. What is the BEST practice?

A.Change the account to a service account and keep it active
B.Disable the account immediately and transfer ownership of files to the manager
C.Keep the account active but change the password and share it with the manager
D.Leave the account as-is and monitor activity for the week
AnswerB

Disabling the account immediately satisfies the revocation constraint while preserving the data for review. Unlike deletion, which destroys the identity and its associated content, disabling blocks all authentication through Microsoft Entra ID yet allows an administrator to transfer file ownership to the manager, granting the week-long access without reactivating the former employee's credentials.

Why this answer

Best practice for offboarding is to disable the account immediately upon termination to eliminate the risk of unauthorized access, while preserving the account for audit and file-ownership purposes. File ownership and access to needed data should be transferred to the manager or another designated employee, satisfying the business need without keeping credentials live. This balances security with operational continuity.

Exam trap

The trap here is the manager's request to 'keep the account active for a week' — candidates who prioritize business convenience over security pick C or D, forgetting that immediate disablement plus file-ownership transfer satisfies both needs.

How to eliminate wrong answers

Option A is wrong because converting a terminated user's account into a service account keeps active credentials tied to a departed employee, creating an unauthorized-access and accountability gap. Option C is wrong because sharing a password with the manager violates individual accountability and non-repudiation principles — actions would be logged under the former employee's identity. Option D is wrong because leaving the account active and merely monitoring it does not prevent misuse and violates the principle of least privilege and prompt revocation.

654
MCQmedium

A company experiences a security breach where an attacker gained access to the network through a compromised vendor account. Which of the following controls would have BEST prevented this attack?

A.Install a network-based intrusion detection system.
B.Require vendors to sign an NDA.
C.Create a separate VLAN for vendor access.
D.Enable multi-factor authentication for vendor accounts.
AnswerD

Requiring a second authentication factor for vendor accounts directly blocks the compromised-credential vector: a stolen password alone cannot authenticate. This satisfies the stem's constraint of preventing network access via a compromised vendor account, since MFA defeats credential replay even when the password is valid.

Why this answer

Multi-factor authentication (MFA) for vendor accounts is the best preventive control because it adds an additional layer of security beyond just a password. Even if the attacker compromises the vendor's credentials, MFA requires a second factor (e.g., a one-time code from a token or biometric) to authenticate, effectively blocking unauthorized access. This directly addresses the attack vector of credential theft, which was the root cause of the breach.

Exam trap

The trap here is that candidates often confuse network segmentation (VLANs) with access control, mistakenly believing that isolating vendor traffic on a separate VLAN prevents credential-based attacks, when in fact VLANs do not authenticate users or validate the legitimacy of the account being used.

How to eliminate wrong answers

Option A is wrong because a network-based intrusion detection system (NIDS) is a detective control that monitors traffic for suspicious patterns after the attack has begun, not a preventive control that stops initial access via compromised credentials. Option B is wrong because a non-disclosure agreement (NDA) is a legal contract that addresses confidentiality after access is granted, not a technical control that prevents unauthorized access through a compromised account. Option C is wrong because creating a separate VLAN for vendor access segments network traffic but does not prevent an attacker from using stolen credentials to authenticate into that VLAN; VLANs provide network isolation, not authentication security.

655
MCQmedium

A company is deploying a web application in a containerized environment. The security team wants to ensure that if an attacker compromises the application, they cannot escalate privileges to the host or other containers. Which of the following container security measures should be implemented?

A.Run containers as a non-root user and drop unnecessary Linux capabilities.
B.Use a read-only root filesystem for the container.
C.Enable inter-container communication on the default bridge network.
D.Store container images in a private registry with vulnerability scanning.
AnswerA

Running as non-root and dropping capabilities follows the principle of least privilege. If the application is compromised, the attacker has limited permissions and cannot perform privileged operations like mounting filesystems or modifying kernel parameters. This significantly reduces the risk of container escape and lateral movement to the host or other containers.

Why this answer

The most effective runtime control to prevent privilege escalation and container escape is to run containers with least privilege: as a non-root user and with unnecessary Linux capabilities dropped. This limits the impact of a compromise. Other measures like read-only filesystems or private registries add defense in depth but do not directly address privilege escalation.

Exam trap

The trap here is focusing on image security or filesystem restrictions while overlooking the runtime privileges that determine what an attacker can do after compromising the container.

656
MCQmedium

You are a security analyst at a financial institution. The company uses a role-based access control (RBAC) system for its internal banking application. Recently, the compliance team discovered that a teller, who should only have access to customer account information for their branch, was able to view account details for customers in other branches. The RBAC system assigns roles based on job titles. You review the configuration and find that the 'Teller' role has a permission that allows viewing all customer accounts, regardless of branch. The company wants to enforce branch-level restrictions. Which of the following is the best approach to address this issue?

A.Implement attribute-based access control (ABAC) to incorporate branch location as an attribute.
B.Use mandatory access control (MAC) with labels for each customer account.
C.Create separate roles for each branch, such as 'Teller_Branch1', 'Teller_Branch2', etc.
D.Modify the 'Teller' role to remove the permission to view all accounts.
AnswerA

Adding an attribute for branch location and using ABAC in conjunction with RBAC allows fine-grained control. This approach is scalable and minimizes administrative overhead because permissions are evaluated dynamically based on the user's branch attribute.

Why this answer

ABAC allows access decisions based on attributes of the user, resource, and environment, such as branch location. By incorporating branch as an attribute, the system can enforce fine-grained restrictions without creating numerous roles. This directly addresses the requirement to restrict tellers to their own branch while maintaining a manageable role structure.

Exam trap

SSCP often tests the misconception that RBAC can easily handle fine-grained, context-aware access control, leading candidates to choose role proliferation or permission removal instead of recognizing the need for ABAC.

How to eliminate wrong answers

Option B is wrong because MAC uses labels and clearances, which is overly rigid and not suited for dynamic branch-level restrictions. Option C is wrong because creating separate roles per branch leads to role explosion and administrative overhead, and does not inherently enforce branch restrictions if role assignments are misconfigured. Option D is wrong because simply removing the permission to view all accounts would prevent tellers from viewing any accounts, not just those in other branches.

657
Multi-Selectmedium

A financial services firm must demonstrate to auditors that access to its core banking platform follows least privilege and is reviewed regularly. Which TWO practices BEST support this objective? (Choose two.)

Select 2 answers
A.Grant permanent elevated access to any user who requests it to reduce help desk tickets.
B.Implement role-based access control with entitlements mapped to documented job functions.
C.Assign all platform administrators a shared emergency account for routine maintenance.
D.Disable audit logging on the platform to improve performance during peak transaction periods.
E.Conduct periodic user access reviews with business owners certifying each entitlement.
AnswersB, E

Role-based access control ties permissions to defined job functions, so users receive only what their role requires. It makes excessive access easier to spot and simplifies reviews because entitlements are grouped logically. This supports least privilege at scale and gives auditors a clear model showing how access decisions are derived.

Why this answer

Least privilege is sustained through two complementary mechanisms: a design that grants only role-appropriate entitlements, and a recurring review that confirms those grants remain justified. Role-based access control structures the grants, while owner certification validates them over time. Together they produce both the control and the evidence auditors expect.

Exam trap

The trap here is accepting operational shortcuts, such as shared or permanently elevated accounts, as reasonable trade-offs when they actually dissolve the accountability and minimal-access principles being audited.

658
Drag & Dropmedium

Drag and drop the steps to configure a static route on a network device into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

To configure a static route on a network device, the correct order is: (1) enter configuration mode, (2) configure the static route by specifying the destination network, subnet mask, and next-hop address, (3) exit configuration mode, and (4) save the configuration. The order of parameters within the static route command itself does not constitute separate steps, so option D is not a distinct correct sequence.

Exam trap

Do not confuse the order of parameters inside a single command with the order of configuration steps. Entering configuration mode must precede issuing the route command, and saving must follow exiting configuration mode.

659
Multi-Selecthard

Which TWO of the following are key indicators of a potential data exfiltration attempt?

Select 2 answers
A.Large number of failed login attempts from multiple accounts
B.Unusual outbound traffic to a known malicious IP address
C.Multiple firewall rule changes in a short period
D.Successful logins from unusual geolocations for multiple users
E.Sudden increase in database read operations by a single user account
AnswersB, E

Outbound traffic to a known malicious IP address indicates command-and-control or staging infrastructure receiving stolen data, a hallmark of exfiltration rather than routine egress. This satisfies the stem's requirement for a key indicator of a potential data exfiltration attempt.

Why this answer

Option B is correct because unusual outbound traffic to a known malicious IP address is a classic exfiltration indicator — data leaving the network to an attacker-controlled command-and-control (C2) or drop server, often over DNS, HTTP/S, or other protocols, signals that stolen data may be leaving the environment. Option E is correct because a sudden spike in database read operations by a single account indicates bulk collection or staging of data, a common precursor or component of exfiltration (e.g., SELECT-heavy queries or mass table dumps). Option A is not an exfiltration indicator but rather a sign of brute-force or credential-stuffing activity, which is an initial-access attempt.

Option C is not specific to exfiltration; firewall rule changes suggest configuration tampering or persistence, not necessarily data leaving. Option D indicates compromised credentials or impossible-travel/account takeover, which is an access anomaly rather than proof of data being exfiltrated.

Exam trap

SSCP often tests the difference between indicators of compromise for intrusion (failed logins, geo-anomalies) versus indicators of exfiltration (outbound traffic, bulk data reads), so candidates who pick any 'suspicious' activity rather than data-leaving activity get it wrong.

660
Multi-Selectmedium

Which THREE activities are part of the post-incident phase?

Select 3 answers
A.Lessons learned meeting
B.Conduct root cause analysis
C.Notify affected customers
D.Reimage infected computers
E.Update incident response plan
AnswersA, B, E

A lessons learned meeting convenes responders and stakeholders after resolution to review the timeline, decisions and outcomes, capturing improvement actions. It is inherently post-incident because it requires the completed response as its subject matter, satisfying the stem's requirement for activities conducted after recovery.

Why this answer

The post-incident phase focuses on reviewing what happened and improving future response, so A (Lessons learned meeting) is correct because it formally gathers the incident response team to review the timeline, decisions, and outcomes after containment and recovery are complete. B (Conduct root cause analysis) is correct because determining the underlying cause—often via techniques like the 5 Whys or fishbone analysis—happens after the incident is resolved and feeds directly into preventive actions. E (Update incident response plan) is correct because the post-incident phase produces documented improvements, such as revised playbooks, contact lists, and detection rules, based on lessons learned and root cause findings.

C (Notify affected customers) and D (Reimage infected computers) belong to earlier phases—notification typically occurs during detection/containment or as required by breach-notification obligations, and reimaging is a containment/eradication/recovery activity—so neither is part of the post-incident phase.

Exam trap

The trap here is confusing recovery/eradication activities (like reimaging systems or notifying customers) with post-incident review activities; candidates often assume any action taken after the incident is contained counts as post-incident, but the exam expects strict adherence to the (ISC)² phase definitions.

661
Multi-Selectmedium

A security team is conducting a risk assessment for a new cloud-based collaboration platform. They need to identify potential threats and vulnerabilities. Which TWO of the following are examples of technical vulnerabilities that should be considered? (Choose two.)

Select 2 answers
A.Lack of security awareness training for employees.
B.Weak encryption algorithms used for data in transit.
C.Insufficient physical security at the data center.
D.Unpatched software on the platform's servers.
E.Lack of a formal risk management policy.
AnswersB, D

Weak encryption is a technical vulnerability because it is a flaw in the cryptographic implementation that could allow unauthorized access to data. It is a configuration or design weakness in the technology. Risk assessments must evaluate encryption strength to protect data confidentiality and integrity. This is a technical issue.

Why this answer

Technical vulnerabilities are weaknesses in hardware, software, or configurations that can be exploited. Unpatched software and weak encryption algorithms are both technical flaws that directly affect the security of the cloud platform. The other options—lack of training, insufficient physical security, and missing policy—are administrative, physical, or governance issues, not technical vulnerabilities.

A comprehensive risk assessment should consider all types, but the question specifically targets technical ones.

Exam trap

The trap here is confusing administrative or physical weaknesses with technical vulnerabilities, especially because all can contribute to risk.

662
Multi-Selectmedium

Which TWO of the following are key components of a Business Impact Analysis (BIA)?

Select 2 answers
A.Recovery time objective.
B.Vulnerability assessment.
C.Criticality analysis.
D.Likelihood estimation.
E.Threat modeling.
AnswersA, C

The recovery time objective defines the maximum tolerable downtime for a business process, directly satisfying the BIA's need to quantify impact over time. It links process criticality to recovery priorities, which is why it counts as a key BIA component rather than a purely technical recovery metric.

Why this answer

A Business Impact Analysis (BIA) identifies the critical business functions and the maximum tolerable downtime, so the Recovery Time Objective (RTO) is a core output — it defines how quickly a process or system must be restored after disruption, directly driving continuity and recovery strategies. Criticality analysis is also a key BIA component because it ranks business processes and assets by their importance to the organization, typically using impact categories such as financial, operational, legal, and reputational, which determines prioritization for recovery. Vulnerability assessment (B) is a risk-assessment activity that identifies weaknesses in systems, not a BIA component, and it focuses on exposure rather than business impact.

Likelihood estimation (D) belongs to risk analysis, where the probability of a threat event is evaluated, whereas the BIA focuses on consequences and tolerances. Threat modeling (E) is a security design technique for identifying threats and attack paths, not a BIA element, since the BIA is threat-agnostic and centers on business process impact.

Exam trap

ISC2 often tests the distinction between BIA components (RTO, criticality analysis) and risk assessment components (vulnerability assessment, likelihood, threat modeling), causing candidates to conflate impact analysis with risk analysis.

663
MCQmedium

A security analyst reviews a cryptographic implementation and notices that the same initialization vector (IV) is used repeatedly with the same key in CBC mode. What is the primary risk?

A.Loss of confidentiality
B.Loss of authentication
C.Non-repudiation is compromised
D.Loss of integrity
AnswerA

Reusing an IV with the same key in CBC mode makes identical plaintext blocks produce identical ciphertext blocks, leaking patterns and enabling chosen-plaintext attacks. Confidentiality is lost; integrity is not directly the issue here, so loss of confidentiality is the primary risk.

Why this answer

In CBC (Cipher Block Chaining) mode, the initialization vector (IV) is XORed with the first plaintext block before encryption. Reusing the same IV with the same key means that identical plaintext blocks will produce identical ciphertext blocks, revealing patterns in the data. This directly breaks confidentiality, as an attacker can detect repeated plaintext segments, infer message structure, or even recover plaintext through known-plaintext attacks.

Exam trap

The trap here is that candidates often confuse confidentiality with integrity or authentication, mistakenly thinking IV reuse primarily enables data tampering (integrity) or impersonation (authentication), when in fact the core cryptographic weakness is the exposure of plaintext patterns, directly violating confidentiality.

How to eliminate wrong answers

Option B is wrong because loss of authentication refers to the inability to verify the origin or identity of the sender, which is not directly caused by IV reuse; CBC mode does not provide authentication by itself (that requires a MAC). Option C is wrong because non-repudiation is a property that prevents a party from denying an action, typically provided by digital signatures, not by CBC mode or IV usage. Option D is wrong because loss of integrity means data has been tampered with undetected; while IV reuse can enable certain attacks (e.g., bit-flipping), the primary and most immediate risk is the exposure of plaintext patterns, i.e., loss of confidentiality.

664
MCQeasy

Which of the following is a secure hash algorithm currently recommended by NIST?

A.SHA-1
B.RC4
C.MD5
D.SHA-256
AnswerD

SHA-256 belongs to the SHA-2 family, which NIST specifies in FIPS 180-4 for cryptographic hashing. It resists the collision attacks that broke SHA-1 and MD5, satisfying the stem's requirement for a currently recommended secure hash algorithm.

Why this answer

SHA-256 is a member of the SHA-2 family of secure hash algorithms and is currently recommended by NIST for cryptographic use. It produces a 256-bit (32-byte) hash value and is widely deployed in protocols such as TLS, SSH, and IPsec, as well as in digital signatures and certificate validation.

Exam trap

ISC2 SSCP exams often test the distinction between hash algorithms and encryption ciphers, so candidates may mistakenly select RC4 because it is a well-known cryptographic algorithm, but it is not a hash function at all.

How to eliminate wrong answers

Option A is wrong because SHA-1 is no longer considered secure by NIST due to demonstrated collision attacks (e.g., the SHAttered attack in 2017) and is deprecated for most cryptographic applications. Option B is wrong because RC4 is a stream cipher, not a hash algorithm, and it is also deprecated due to severe biases in its output. Option C is wrong because MD5 is a broken hash algorithm with practical collision attacks (e.g., used in the Flame malware) and is explicitly not recommended by NIST for any security purpose.

665
Multi-Selecthard

A security engineer is designing a key management system for a large enterprise. Which two of the following practices are essential for securing cryptographic keys throughout their lifecycle?

Select 2 answers
A.Store keys in dedicated hardware security modules (HSMs).
B.Use the same key for encryption, digital signatures, and key exchange.
C.Email keys to authorized users for convenience.
D.Store keys in the same database as encrypted data.
E.Rotate keys regularly and upon compromise.
AnswersA, E

HSMs provide tamper-resistant hardware that generates and stores keys so private material never exists in plaintext on general-purpose systems, satisfying the lifecycle requirement for secure generation, storage and protection. Keys are used inside the module, preventing extraction even if the host is compromised.

Why this answer

Option A is correct because dedicated hardware security modules (HSMs) provide tamper-resistant, FIPS 140-2/140-3 validated storage and cryptographic processing, ensuring keys are generated, used, and stored in a protected boundary and never exposed in plaintext on general-purpose systems. Option E is correct because regular key rotation limits the amount of data protected by any single key (cryptoperiod) and reduces the blast radius of a compromise, while rotation upon suspected or confirmed compromise ensures the exposed key is retired and replaced immediately. Options B, C, and D are not appropriate: reusing one key across encryption, digital signatures, and key exchange violates key-separation principles and increases the impact of any single key compromise; emailing keys exposes them to interception and unauthorized access; and storing keys alongside the encrypted data means a single database breach compromises both the ciphertext and the key needed to decrypt it.

Exam trap

SSCP often tests key management fundamentals, catching candidates who choose convenience (emailing keys, single key for all purposes) over security best practices like HSM storage and rotation.

666
Multi-Selectmedium

A security administrator is implementing the 3-2-1 backup rule. Which THREE actions are required to comply with this rule? (Select THREE.)

Select 3 answers
A.Store one copy offsite
B.Maintain at least three copies of the data
C.Use two different media types (e.g., disk and tape)
D.Perform daily full backups
E.Use encryption for all backup copies
AnswersA, B, C

The 3-2-1 rule's final component requires one copy stored at a separate physical location, protecting against site-level loss such as fire, flood or theft destroying all on-premises backups simultaneously. Offsite storage satisfies that geographic-separation requirement.

Why this answer

The 3-2-1 backup rule requires three things: at least three copies of the data (option B), stored on two different media types (option C), with one copy kept offsite (option A). Option B is correct because the '3' means the original data plus two backup copies, totaling three copies. Option C is correct because the '2' means two distinct media or storage types, such as disk and tape, to avoid a single failure mode.

Option A is correct because the '1' means at least one copy must be stored offsite for disaster recovery. Option D is not required by the rule, since backup frequency is a separate scheduling decision. Option E is also not part of the 3-2-1 rule, as encryption is a security control rather than a copy-count or media requirement.

Exam trap

SSCP often tests the exact components of the 3-2-1 rule, and candidates frequently confuse it with general backup best practices like encryption or daily full backups, which are not part of the rule.

667
MCQmedium

A company implements a DMZ to host public services. Which of the following is the best practice for securing the DMZ?

A.Allow all traffic from the internet to the DMZ
B.Disable logging on DMZ firewalls
C.Use separate firewall rules for inbound and outbound traffic
D.Place the DMZ behind the internal firewall
E.Use the same subnet for DMZ and internal network
AnswerC

Separate inbound and outbound rules enforce stateful inspection and least-privilege filtering on DMZ traffic, preventing compromised public hosts from initiating unrestricted outbound connections. This satisfies the stem's best-practice requirement by containing breaches rather than relying on a single permissive rule set.

Why this answer

DMZ security relies on strict separation of inbound and outbound traffic rules. Inbound rules should permit only necessary traffic (e.g., HTTP/HTTPS to web servers) from the internet to the DMZ, while outbound rules should restrict DMZ-initiated connections to the internal network, typically allowing only established sessions or specific protocols. This prevents an attacker who compromises a DMZ host from using it as a pivot to access internal resources.

Exam trap

The trap here is that candidates often confuse the DMZ's placement (thinking it should be behind the internal firewall for extra protection) with the need for separate rule sets, but the correct placement is between two firewalls (or a single firewall with three interfaces) with distinct inbound and outbound rules to enforce isolation.

How to eliminate wrong answers

Option A is wrong because allowing all traffic from the internet to the DMZ defeats the purpose of a DMZ, which is to expose only specific services while blocking all other traffic. Option B is wrong because disabling logging on DMZ firewalls eliminates the ability to detect and investigate security incidents, violating fundamental security monitoring practices. Option D is wrong because placing the DMZ behind the internal firewall would expose the internal network to direct internet traffic if the DMZ is compromised, negating the isolation a DMZ provides.

Option E is wrong because using the same subnet for DMZ and internal network removes network segmentation, allowing broadcast traffic and potential lateral movement between zones.

668
MCQhard

A security analyst is tuning a SIEM and needs to reduce false positives from a rule that alerts on failed logins. The rule currently triggers on any single failed login. Which modification would best reduce false positives while still detecting brute-force attacks?

A.Add a threshold of 5 failed logins within 5 minutes
B.Disable the rule entirely
C.Increase the severity level of the alert
D.Ignore failed logins from known users
AnswerA

A threshold of five failures within five minutes aggregates events, so isolated typos no longer trigger alerts while sustained bursts still do. This directly satisfies the stem's constraint of cutting false positives without losing brute-force detection, unlike disabling the rule entirely.

Why this answer

Adding a threshold of 5 failed logins within 5 minutes reduces false positives from isolated accidental lockouts while still detecting the sustained pattern of failed attempts characteristic of brute-force attacks. This aligns with SIEM tuning best practices where aggregation over a time window filters out noise without losing signal.

Exam trap

The SSCP exam often tests the misconception that increasing severity or ignoring specific users reduces false positives, when in fact only time-based thresholding or contextual filtering (e.g., source IP reputation) properly addresses the root cause of noise from isolated events.

How to eliminate wrong answers

Option B is wrong because disabling the rule entirely would remove detection of brute-force attacks, creating a security gap. Option C is wrong because increasing the severity level does not reduce false positives; it only changes the alert's priority, leaving the same number of noisy alerts. Option D is wrong because ignoring failed logins from known users would miss attacks where a legitimate user's account is compromised and used for brute-force attempts, and it assumes user identity is reliably verified at the authentication layer.

669
MCQmedium

An organization has experienced a ransomware attack. After containing the incident, the response team plans to restore systems from backups. Which step is most critical before restoring production systems?

A.Verify the integrity of backup data by restoring to an isolated test environment.
B.Notify law enforcement immediately.
C.Patch the exploited vulnerability and ensure the backup is free of malware.
D.Disconnect all systems from the network.
AnswerC

Correct. Eradication and patching prevent recurrence.

Why this answer

Restoring from backups while the original vulnerability remains unpatched would allow the ransomware to reinfect the systems immediately. Additionally, if the backup itself contains malware (e.g., the ransomware encrypted the backup repository), restoring it would reintroduce the infection. Patching the exploited vulnerability and verifying the backup is clean ensures a safe restoration point, breaking the attack chain.

Exam trap

The trap here is that candidates often choose Option A (verify backup integrity) because it sounds thorough, but they miss that the most critical step is to eliminate the root cause of the infection to prevent immediate reinfection after restoration.

How to eliminate wrong answers

Option A is wrong because verifying backup integrity in an isolated test environment is a good practice but not the most critical step before restoration; the primary risk is reinfection from the same vulnerability or a compromised backup, not data corruption. Option B is wrong because notifying law enforcement is a post-incident legal and compliance step that does not directly prevent reinfection or data loss during restoration; it should occur after containment and evidence preservation, not before restoring systems. Option D is wrong because disconnecting all systems from the network is a containment step that should have been performed earlier in the incident response process; by the time the team plans to restore from backups, containment is already assumed to be complete, and re-disconnecting would hinder the restoration process.

670
Multi-Selecthard

A security administrator is designing an access control scheme for a research lab where data sensitivity varies widely and the organization wants the operating system itself to enforce access decisions based on labels, independent of user discretion. Which TWO of the following characteristics apply to mandatory access control (MAC)? (Choose two.)

Select 2 answers
A.Access is granted based on the user's role within the organization rather than on labels
B.The operating system enforces access decisions through a reference monitor
C.Users may change the classification label of files they own to share them more easily
D.Resource owners can grant access at their discretion to any user they choose
E.Access decisions are based on security labels and clearances assigned by a central authority
AnswersB, E

MAC depends on a reference monitor that mediates every access request and compares subject clearance against object label. This enforcement is inside the trusted computing base and cannot be bypassed by users or applications. It directly satisfies the lab's requirement that the OS itself enforce decisions based on labels, making this a core MAC characteristic alongside centralized label assignment.

Why this answer

MAC is defined by centralized assignment of labels and clearances and by OS-level enforcement through a reference monitor. Users cannot alter labels or grant access at their discretion, and access is not determined by role membership. These two traits together satisfy the lab's need for label-based decisions that the operating system enforces independently of user choice.

Exam trap

The trap here is conflating discretionary owner control or role-based access with MAC, when MAC specifically removes user discretion and bases every decision on central labels and clearances.

671
Multi-Selectmedium

A company is upgrading its legacy systems to use modern cryptographic standards. Which two of the following algorithms should be avoided due to known weaknesses or deprecation?

Select 2 answers
A.SHA-256 for hashing
B.MD5 for hashing
C.AES-256 for encryption
D.ECDH for key exchange
E.3DES for encryption
AnswersB, E

MD5 is cryptographically broken; collision attacks are feasible.

Why this answer

MD5 (option B) must be avoided because it is cryptographically broken: practical collision attacks (e.g., chosen-prefix collisions) make it unsuitable for hashing, digital signatures, or integrity checks, and it has been deprecated by NIST for security use. 3DES (option E) should also be avoided because its 64-bit block size enables Sweet32-style birthday attacks, and its effective key strength is reduced (e.g., 2-key 3DES offers only about 80 bits), leading to its deprecation and removal from standards such as NIST SP 800-131A. SHA-256 (option A) is a current, secure SHA-2 hash and remains approved for hashing. AES-256 (option C) is a strong, modern symmetric cipher with no practical breaks and is widely recommended.

ECDH (option D) is a sound modern elliptic-curve key-exchange method and is not deprecated.

Exam trap

SSCP often tests whether candidates can distinguish deprecated algorithms (MD5, SHA-1, 3DES, RC4) from still-strong ones (SHA-256, AES-256, ECDH) — the trap is assuming 'Triple DES' must be three times stronger than DES and therefore secure.

672
MCQhard

A healthcare organization stores patient records in a database that is encrypted at rest using AES-256-CBC. The encryption key is stored in a plaintext configuration file on the database server, with file permissions set to read-only for the database service account and administrators. During an internal audit, the security team flags this as a critical vulnerability because the key is co-located with the encrypted data. The system administrator argues that the file permissions are sufficient to prevent unauthorized access. Separately, the organization must comply with HIPAA requirements for encryption key management. Which remediation most effectively addresses the vulnerability and meets compliance requirements?

A.Change the encryption algorithm from AES-256-CBC to AES-256-GCM.
B.Implement file integrity monitoring (FIM) on the configuration file to alert on unauthorized access.
C.Move the encryption key to a hardware security module (HSM) accessible only via authenticated API calls.
D.Encrypt the configuration file containing the key with a second AES-256 key stored in the same directory.
AnswerC

An HSM stores keys in tamper-resistant hardware and performs cryptographic operations internally, so the plaintext key never resides on the database server. This removes co-location, satisfies HIPAA key-management expectations, and defeats the administrator's file-permission argument.

Why this answer

Moving the encryption key to a hardware security module (HSM) physically separates the key from the encrypted data, eliminating the co-location vulnerability. HSMs provide tamper-resistant key storage and enforce access controls via authenticated API calls, which aligns with HIPAA requirements for proper key management and protection of electronic protected health information (ePHI).

Exam trap

The trap here is that candidates often confuse encryption algorithm improvements (like GCM) or monitoring controls (like FIM) with proper key management, failing to recognize that co-location of the key with the data is the core vulnerability that must be addressed by physical or logical separation.

How to eliminate wrong answers

Option A is wrong because changing the cipher mode from CBC to GCM addresses data integrity and authentication, not the fundamental issue of key storage co-location or access control. Option B is wrong because file integrity monitoring (FIM) only detects unauthorized access or changes after the fact; it does not prevent an attacker who gains access to the server from reading the plaintext key from the configuration file. Option D is wrong because encrypting the configuration file with a second key stored in the same directory merely adds a layer of obfuscation; the second key remains co-located and accessible, so an attacker who compromises the server can retrieve both keys.

673
Multi-Selectmedium

Which TWO of the following are characteristics of the Biba integrity model? (Choose TWO.)

Select 2 answers
A.No write-up
B.No write-down
C.No read-up
D.Discretionary access
E.No read-down
AnswersA, E

Subjects cannot write to higher integrity levels.

Why this answer

Option A, 'No write-up,' is correct because the Biba integrity model's *-integrity axiom (the write-up rule) forbids a subject from writing to an object of higher integrity level, preventing low-integrity data from contaminating higher-integrity data. Option E, 'No read-down,' is correct because Biba's simple integrity axiom forbids a subject from reading an object of lower integrity level, preventing a high-integrity subject from being corrupted by low-integrity data. Option B, 'No write-down,' actually belongs to the Bell-LaPadula confidentiality model (the *-property), which restricts writing to lower or equal sensitivity levels, not to Biba.

Option C, 'No read-up,' is also a Bell-LaPadula rule (the simple security property), prohibiting reading data at a higher classification, so it is not a Biba characteristic. Option D, 'Discretionary access,' describes discretionary access control (DAC) mechanisms such as owner-controlled ACLs, which are independent of the Biba mandatory integrity model and therefore not one of its defining characteristics.

Exam trap

SSCP often tests the mirror-image confusion between Biba (integrity: no write-up, no read-down) and Bell-LaPadula (confidentiality: no read-up, no write-down), so candidates who mix up the two models select the wrong pair.

674
MCQeasy

A security administrator is configuring access controls for a shared file server. The administrator wants to grant permissions based on the sensitivity labels of the files and the clearance levels of the users, ensuring that users cannot change these permissions. Which access control model should be implemented?

A.Role-Based Access Control (RBAC)
B.Attribute-Based Access Control (ABAC)
C.Mandatory Access Control (MAC)
D.Discretionary Access Control (DAC)
AnswerC

MAC enforces access based on security labels assigned to objects (files) and clearances assigned to subjects (users). These labels and clearances are typically managed by a central authority, and users cannot alter them. This matches the requirement that access be based on sensitivity labels and clearance levels, and that users cannot change permissions.

Why this answer

Mandatory Access Control (MAC) is the only model that enforces access using sensitivity labels on objects and clearances on subjects, with permissions managed centrally so users cannot change them. This precisely matches the administrator's requirement. The other models either rely on roles, owner discretion, or flexible attributes, none of which provide the same mandatory, label-based enforcement.

Exam trap

The trap here is assuming that any label-based system is MAC, when in fact ABAC can also use labels as attributes but does not enforce mandatory, non-discretionary control.

675
MCQeasy

Which of the following is a common vulnerability source that would be documented in a risk register?

A.Password policies
B.Intrusion alerts
C.Firewall logs
D.CVE entries
AnswerD

CVE entries provide standardised identifiers for publicly disclosed software flaws, giving the risk register concrete, traceable vulnerability data. They satisfy the stem's requirement for a common vulnerability source by cataloguing specific weaknesses that feed directly into likelihood and impact assessments, unlike broader threat categories or control gaps.

Why this answer

D is correct because CVE (Common Vulnerabilities and Exposures) entries are standardized identifiers for known security vulnerabilities, making them a direct source of vulnerability information that should be documented in a risk register. A risk register captures identified risks, including specific vulnerabilities, and CVE entries provide the precise technical details needed to assess and track those risks.

Exam trap

ISC2 often tests the distinction between vulnerability sources (like CVE entries) and security controls or monitoring outputs (like password policies, intrusion alerts, or firewall logs), trapping candidates who confuse operational data with vulnerability documentation.

How to eliminate wrong answers

Option A is wrong because password policies are security controls or guidelines, not vulnerability sources; they define rules for password creation and management, whereas a risk register documents actual or potential vulnerabilities, not policy documents. Option B is wrong because intrusion alerts are outputs from an intrusion detection system (IDS) indicating potential security incidents, not vulnerability sources; they represent events that may exploit vulnerabilities, but the alerts themselves are not the vulnerabilities. Option C is wrong because firewall logs are records of network traffic and firewall rule actions, used for monitoring and forensics, not a source of vulnerability information; they can help identify attacks but do not list or describe vulnerabilities like CVE entries do.

Page 8

Page 9 of 13

Page 10