SSCP Security Operations and Administration Practice Question
An organization uses a SIEM to alert when a server's configuration changes from its hardened baseline. This is an example of:
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deviation detection
SIEM alerts on configuration changes from baseline are a form of deviation detection, which is part of configuration management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deviation detection
Why this is correct
Deviation detection compares current system state against a defined baseline and raises alerts on any divergence, which is precisely what the SIEM performs when a server's configuration drifts from its hardened state. It satisfies the stem's constraint of detecting configuration changes rather than preventing them or scanning for known malware signatures.
- ✗
Patch management
Why it's wrong here
Patch management remediates known software flaws by deploying vendor updates; it does not compare running configuration against a hardened baseline, so no drift alert would be produced. It is tempting because patching also maintains server hardening over time, and it would be the correct answer if the question concerned applying security updates to close vulnerabilities.
- ✗
Vulnerability scanning
Why it's wrong here
Vulnerability scanning probes systems for known weaknesses and missing patches; it does not detect deviation of configuration settings from an approved baseline, so the SIEM would receive no drift event. It is tempting because scanning supports hardening programmes, and it would be correct if the question asked how weaknesses are identified rather than how configuration change is detected.
- ✗
Asset management
Why it's wrong here
Asset management inventories hardware, software and ownership records; it does not monitor configuration settings for deviation from a hardened baseline, so it cannot generate the SIEM alert described. It is tempting because accurate asset data underpins security monitoring, and it would be correct if the question concerned discovering or tracking the servers themselves.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.