Courseiva

SSCP Security Operations and Administration Practice Question

An organization is implementing a software inventory management process. Which TWO of the following should be tracked for each software asset?

⚠ Common exam trap

(ISC)² often tests the distinction between physical asset tracking (e.g., hardware serial numbers) and logical software inventory attributes, leading candidates to mistakenly select the serial number of installation media as a tracked item.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

License type and number of licenses

Option A (License type and number of licenses) is correct because software inventory management must track licensing entitlements—such as perpetual, subscription, or concurrent-user licenses and the quantity purchased—to ensure license compliance, avoid over-deployment penalties, and support audits. Option C (Version and patch level) is correct because knowing the exact version and patch level of each installed application is essential for vulnerability management, patch remediation, and confirming supportability. Option B is not a standard inventory attribute for software assets; physical location is typically tracked for hardware assets, not installed software. Option D is unnecessary because installation media serial numbers are not meaningful inventory data for deployed software. Option E is not required for inventory purposes; the installing user does not determine licensing, versioning, or compliance status.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    License type and number of licenses

    Why this is correct

    Tracking licence type and count directly satisfies the inventory's licensing-compliance constraint, since each asset's entitlement must be reconcilable against deployed instances. Licence type distinguishes perpetual, subscription, and concurrent models, while the count exposes over-deployment or shortfalls during audits. This pairing is therefore essential for software asset management.

  • ✗

    Physical location of the installed software

    Why it's wrong here

    Physical location is an asset-management attribute for hardware, not a software inventory field; software is tracked by title, version, licence and installation count instead. It is tempting because location matters for tangible assets, and would be correct when recording where servers or laptops are housed for audits.

  • ✓

    Version and patch level

    Why this is correct

    Recording version and patch level exposes outdated or unpatched installations, enabling the organisation to correlate inventory entries with vulnerability data and remediate known exploits, which is the core security objective of maintaining a software inventory.

  • ✗

    Serial number of the installation media

    Why it's wrong here

    Serial numbers apply to physical installation media, not to software installed from downloads or repositories, so this field is not tracked per software asset. It is tempting because media control matters in classified environments, and would be correct when managing removable media under a physical security policy.

  • ✗

    Name of the user who installed it

    Why it's wrong here

    Recording the installing user's name is not a standard software inventory attribute; licence entitlement, version and installation count are tracked instead. It is tempting because accountability for installations seems useful, and would be correct when auditing user activity through logging rather than inventory records.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.