Courseiva
hardMultiple Choice

SSCP Practice Question: Experiences malware that injects code into…

An organization experiences malware that injects code into legitimate processes. Which security feature should be enabled to prevent code execution in memory pages?

⚠ Common exam trap

Many candidates confuse ASLR with DEP, thinking randomization alone prevents code execution, but ASLR only makes addresses unpredictable while DEP actively blocks execution from non-executable pages.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data Execution Prevention (DEP)

Data Execution Prevention (DEP) is a hardware and software security feature that marks memory pages as non-executable unless they explicitly contain executable code. By preventing code execution in data-only memory regions (such as the heap and stack), DEP stops malware that attempts to inject and run shellcode within legitimate processes, even if the process is compromised.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encrypted File System (EFS)

    Why it's wrong here

    EFS encrypts files at rest on disk; it does not mark memory pages non-executable, so injected code still runs. It is tempting because it protects data confidentiality, and would be correct when files on a volume need encryption, not when blocking code execution in memory.

  • ✗

    Address Space Layout Randomization (ASLR)

    Why it's wrong here

    ASLR randomises memory layout to hinder exploitation, but it does not mark pages non-executable, so injected code still runs. It is tempting because ASLR is a genuine anti-exploitation mitigation, and it would be correct when the goal is making memory addresses unpredictable to defeat return-oriented programming.

  • ✗

    Mandatory Access Control (MAC)

    Why it's wrong here

    MAC governs which subjects may access which objects via labels, not memory page permissions, so injected code still executes. It is tempting because MAC hardens systems against unauthorised access, and it would be the right choice when the requirement is enforcing confidentiality and integrity labels across users and processes.

  • ✓

    Data Execution Prevention (DEP)

    Why this is correct

    DEP marks memory pages as non-executable, so injected code placed in data regions cannot run. This blocks the mechanism described, where malware injects code into legitimate processes and attempts execution from those pages, satisfying the requirement to prevent code execution in memory.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.