Courseiva

CCNA Risk Identification, Monitoring, and Analysis Questions

75 of 91 questions · Page 1/2 · Risk Identification, Monitoring, and Analysis · Answers revealed

1
Multi-Selecthard

A company is implementing a new SIEM. Which THREE factors are most important to ensure log integrity and usefulness for forensic investigations? (Choose THREE.)

Select 3 answers
A.Write-once storage to prevent modification
B.Digital signing of logs to verify authenticity
C.Minimizing log retention to reduce storage costs
D.Ensuring logs are retained for a period consistent with legal and regulatory requirements
E.Aggregating logs from all sources into one centralized repository
AnswersA, B, D

Write-once storage prevents logs from being altered or deleted after capture, preserving evidential integrity. This directly satisfies the forensic requirement that records remain tamper-evident and unmodified, ensuring investigators can trust that what they review reflects the original event data.

Why this answer

Option A (write-once storage to prevent modification) is correct because WORM (Write Once Read Many) media or immutable storage ensures that once log data is written it cannot be altered or deleted, preserving evidentiary integrity for forensics. Option B (digital signing of logs to verify authenticity) is correct because cryptographic signatures or hashes let investigators prove logs were not tampered with and confirm their origin, supporting non-repudiation and chain-of-custody requirements. Option D (ensuring logs are retained for a period consistent with legal and regulatory requirements) is correct because forensic usefulness depends on having the relevant logs still available when an investigation occurs, and retention periods are often mandated by laws such as HIPAA, PCI DSS, or GDPR.

Option C is not correct because minimizing retention to cut storage costs directly undermines forensic and compliance needs by destroying potentially critical evidence prematurely. Option E is not correct because centralizing logs improves correlation and management but does not by itself guarantee integrity or forensic usefulness, and it can even concentrate risk if the repository is not protected.

Exam trap

A common trap on the SSCP exam is to select 'centralized aggregation' (Option E) as a key factor for log integrity, but aggregation alone does not protect against modification. The correct factors focus on preserving log authenticity and immutability, such as write-once storage and digital signatures.

2
Multi-Selectmedium

A security analyst is reviewing SIEM alerts and wants to identify potential data exfiltration. Which TWO of the following indicators are most relevant?

Select 2 answers
A.Successful logins during business hours
B.Large outbound data transfers to an external IP
C.A user connecting to a known command-and-control server
D.Multiple failed login attempts
E.Elevated CPU usage on a database server
AnswersB, C

Exfiltration requires data leaving the network, so unusually large outbound transfers to an external IP directly indicate possible data theft. Volume and destination are the measurable network-flow characteristics that distinguish exfiltration from normal egress traffic.

Why this answer

Option B is correct because large outbound data transfers to an external IP are a classic exfiltration indicator: data leaving the network in abnormal volume or to an unfamiliar destination suggests staging and transfer of stolen data, and SIEM correlation on bytes sent, destination reputation, and baseline deviation is the standard detection method. Option C is correct because a user or host connecting to a known command-and-control (C2) server indicates active adversary communication, which typically precedes or accompanies exfiltration and is detected via threat-intelligence feeds, DNS/HTTP beaconing patterns, and IOC matching. Option A does not belong because successful logins during business hours are normal expected activity and lack exfiltration context.

Option D does not belong because multiple failed login attempts indicate brute-force or credential-stuffing attempts (an access/integrity threat), not outbound data theft. Option E does not belong because elevated CPU usage on a database server is a performance or resource symptom that may have many benign causes and is not a direct exfiltration indicator.

Exam trap

The trap here is that candidates confuse indicators of compromise (like failed logins or CPU spikes) with exfiltration-specific signs, failing to focus on outbound data movement as the core criterion.

3
MCQeasy

Which type of IDS uses a database of known attack patterns to identify malicious activity?

A.Behavior-based IDS
B.Network-based IDS
C.Anomaly-based IDS
D.Signature-based IDS
AnswerD

Signature-based IDS matches network traffic against a database of known attack signatures, satisfying the stem's requirement to identify malicious activity using known attack patterns. It detects previously catalogued threats with high accuracy but cannot recognise novel or polymorphic attacks lacking an existing signature.

Why this answer

Signature-based IDS (D) is correct because it relies on a pre-defined database of known attack patterns, or signatures, to match against network traffic or system activity. When a packet or event matches a signature, the IDS generates an alert. This is the traditional method used by systems like Snort, which compares traffic against rule sets containing specific byte sequences or protocol anomalies.

Exam trap

The trap here is confusing the detection method (signature-based) with the deployment type (network-based), leading candidates to pick 'Network-based IDS' because they associate it with monitoring network traffic, even though the question specifically asks about the detection methodology using known attack patterns.

How to eliminate wrong answers

Option A is wrong because behavior-based IDS (also known as anomaly-based) establishes a baseline of normal activity and flags deviations, not known attack patterns. Option B is wrong because network-based IDS describes the deployment location (monitoring network traffic) rather than the detection methodology; a network-based IDS can be either signature-based or anomaly-based. Option C is wrong because anomaly-based IDS uses statistical models or machine learning to detect deviations from a baseline of normal behavior, not a database of known attack signatures.

4
Multi-Selectmedium

Which TWO of the following are examples of technical threat sources that should be considered during risk identification?

Select 2 answers
A.Earthquake
B.Hardware failure
C.Unauthorized access by employee
D.Software bug
E.Social engineering
AnswersB, D

Hardware failure counts as a technical threat source because it arises from the failure of technology components themselves, such as disk crashes or component degradation, rather than from environmental forces or human actors. Risk identification must catalogue it alongside software and network weaknesses.

Why this answer

Hardware failure (B) is a technical threat source because it arises from the failure of IT infrastructure components such as servers, disks, or network devices, which is a classic technology-originated risk considered in risk identification. Software bug (D) is also a technical threat source, as flaws in application or system code can introduce vulnerabilities and cause failures or exploitable conditions. These two are correct because they stem from technology itself rather than from natural events or deliberate human behavior.

In contrast, earthquake (A) is an environmental/natural threat source, unauthorized access by employee (C) is a human/internal threat source, and social engineering (E) is a human-driven threat that exploits people rather than a technical fault.

Exam trap

The trap here is that candidates confuse threat categories, mistakenly classifying human-based threats like social engineering or insider actions as technical threat sources, when the SSCP exam strictly separates technical threats (hardware/software failures) from human and environmental threats.

5
MCQmedium

An organization's web application experienced a data breach due to a SQL injection vulnerability. During the risk analysis phase, the security team calculated the SLE as $25,000 and the ARO as 0.5. What is the ALE?

A.$50,000
B.$25,000
C.$6,250
D.$12,500
AnswerD

ALE is derived by multiplying single loss expectancy by annualised rate of occurrence: $25,000 × 0.5 = $12,500. This satisfies the stem's requirement to quantify expected yearly loss from the SQL injection breach, giving the security team a monetary figure for risk prioritisation.

Why this answer

The Annualized Loss Expectancy (ALE) is calculated by multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO). Given an SLE of $25,000 and an ARO of 0.5, the ALE is $25,000 × 0.5 = $12,500. This quantifies the expected annual financial loss from the SQL injection vulnerability.

Exam trap

The trap here is that candidates often confuse multiplication with division or forget to apply the ARO, selecting the SLE value directly instead of computing the product.

How to eliminate wrong answers

Option A is wrong because $50,000 results from incorrectly dividing SLE by ARO (i.e., $25,000 / 0.5) rather than multiplying. Option B is wrong because $25,000 equals the SLE itself, ignoring the ARO factor entirely. Option C is wrong because $6,250 comes from dividing SLE by 4 or multiplying by 0.25, which does not correspond to any standard risk calculation formula.

6
MCQmedium

A security analyst notices repeated failed login attempts from a single IP address targeting a domain controller. The SIEM alerts after 10 failed attempts within 5 minutes. Which detection type is most likely used?

A.Anomaly-based detection
B.Signature-based detection
C.Rule-based detection
D.Behavior-based detection
AnswerC

A fixed threshold — ten failed attempts within five minutes from one source — is a deterministic signature. Rule-based detection matches events against predefined conditions, unlike anomaly or behavioural baselining, which flags deviations from learned norms.

Why this answer

The alert is triggered by a static threshold (10 failed attempts in 5 minutes) with no baseline learning. This is characteristic of rule-based detection, which uses predefined conditions (e.g., 'if count > 10 then alert'). Anomaly-based detection would require establishing a baseline of normal behavior and detecting deviations from that baseline.

Therefore, rule-based detection is the most likely type used.

Exam trap

Candidates may assume any threshold-based alert is anomaly-based, but a fixed, static threshold is a hallmark of rule-based detection. Anomaly-based detection derives thresholds from historical baselines.

How to eliminate wrong answers

Option A is wrong because anomaly-based detection relies on statistical baselines and deviations from normal behavior, not a fixed threshold like 10 attempts in 5 minutes. Option B is wrong because signature-based detection matches known attack patterns (e.g., specific payloads or exploit signatures), not volumetric thresholds. Option D is wrong because behavior-based detection analyzes patterns of user or entity behavior over time (e.g., UEBA), not a simple count of failed logins from a single IP.

7
MCQhard

After a security incident, the incident response team needs to analyze logs from multiple sources to reconstruct the timeline. The SIEM retains logs for 90 days, but the incident occurred 120 days ago. Which action should the organization have taken to ensure log availability?

A.Use a different SIEM vendor
B.Increase log verbosity
C.Implement real-time alerting
D.Extend log retention period to at least 1 year
AnswerD

The SIEM's 90-day retention expired before the 120-day-old incident could be investigated, so logs were gone. Extending retention to at least one year ensures evidence remains available beyond the investigation window, directly addressing the stem's availability constraint.

Why this answer

The organization's log retention policy was insufficient to cover the incident timeline. The SIEM retained logs for only 90 days, but the incident occurred 120 days ago, meaning the logs were overwritten or purged before the incident was discovered. Extending the retention period to at least one year ensures logs are available for post-incident forensic analysis, aligning with industry best practices (e.g., NIST SP 800-61) and regulatory requirements that often mandate 6–12 months of log retention.

Exam trap

The trap here is that candidates confuse log verbosity (option B) with log retention, thinking that capturing more data inherently preserves it longer, when in fact retention is a separate storage policy parameter.

How to eliminate wrong answers

Option A is wrong because switching SIEM vendors does not change the underlying retention policy; the new vendor would still need to be configured to retain logs for an adequate duration. Option B is wrong because increasing log verbosity (e.g., logging more events or details) does not extend the retention window; it actually consumes more storage and could shorten retention if capacity is fixed. Option C is wrong because real-time alerting helps detect incidents sooner but does not preserve historical logs beyond the configured retention period; logs older than 90 days would still be unavailable for timeline reconstruction.

8
MCQhard

An organization is calculating the Annualized Loss Expectancy (ALE) for a server. The Asset Value (AV) is $50,000, the Exposure Factor (EF) is 40%, and the Annualized Rate of Occurrence (ARO) is 0.5. What is the Single Loss Expectancy (SLE) and ALE?

A.SLE = $20,000, ALE = $10,000
B.SLE = $50,000, ALE = $25,000
C.SLE = $10,000, ALE = $5,000
D.SLE = $20,000, ALE = $40,000
AnswerA

SLE equals AV multiplied by EF: $50,000 × 0.40 = $20,000. ALE equals SLE multiplied by ARO: $20,000 × 0.5 = $10,000. These figures satisfy the stem's quantitative risk calculation, correctly applying the standard formulas to the given asset value, exposure factor and annualised rate of occurrence.

Why this answer

The Single Loss Expectancy (SLE) is calculated as Asset Value (AV) × Exposure Factor (EF) = $50,000 × 0.40 = $20,000. The Annualized Loss Expectancy (ALE) is then SLE × Annualized Rate of Occurrence (ARO) = $20,000 × 0.5 = $10,000. This matches option A exactly.

Exam trap

The trap here is that candidates may forget to apply the EF to the AV when calculating SLE, or they may invert the ARO (e.g., using 2 instead of 0.5) when computing ALE.

How to eliminate wrong answers

Option B is wrong because it incorrectly uses the full AV as the SLE ($50,000) instead of applying the EF, and then multiplies by ARO to get $25,000, which is not the correct ALE. Option C is wrong because it mistakenly halves the AV to get SLE = $10,000 (perhaps confusing EF with ARO) and then multiplies by ARO to get ALE = $5,000, misapplying both formulas. Option D is wrong because it correctly calculates SLE = $20,000 but then multiplies by the reciprocal of ARO (2) instead of ARO (0.5), yielding ALE = $40,000 instead of $10,000.

9
Multi-Selectmedium

A vulnerability management team is scanning a network. Which THREE factors should be considered to minimize false positives?

Select 3 answers
A.Scanning only during peak hours
B.Using default scan profiles
C.Tuning the scanner based on the environment
D.Performing authenticated scans
E.Manually verifying results
AnswersC, D, E

Scanner signatures and severity thresholds are generic by default, so tuning them to the actual operating systems, applications and network topology removes checks that do not apply. This eliminates environment-specific false positives before they reach analysts.

Why this answer

Option C is correct because tuning the scanner to the specific environment—adjusting plugin sets, port ranges, timing templates, and severity thresholds—reduces noise from irrelevant checks and mismatched assumptions, which directly lowers false positives. Option D is correct because authenticated (credentialed) scans let the scanner read actual patch levels, registry keys, and installed software instead of inferring vulnerabilities from banners or version strings, eliminating many false positives caused by backported patches or obscured services. Option E is correct because manually verifying findings (for example, confirming a suspected open port with netstat or a service banner with a targeted probe) validates scanner output before it is reported, catching false positives that automated logic cannot resolve.

Option A is not correct because scanning only during peak hours does not reduce false positives and can actually increase them through timeouts and dropped packets under load. Option B is not correct because default scan profiles are generic and often produce more false positives, since they are not tailored to the target environment's operating systems, applications, or network topology.

Exam trap

A common misconception is that scanning during peak hours yields more accurate results, when in fact it degrades scan reliability and increases false positives due to network load and timeouts.

10
MCQmedium

A security administrator is configuring log collection for a new web application tier. The organization must retain logs for one year and needs to ensure that log data cannot be altered after collection. Which control best meets the integrity requirement?

A.Store logs on the same web servers that generate them, protected by the application's own file permissions
B.Compress logs into archives on each server and email weekly copies to the security team
C.Forward logs to a centralized server configured with write-once storage and cryptographic hashing of log records
D.Enable verbose logging on all servers and rely on the operating system's default log rotation
AnswerC

Centralized collection with write-once, read-many storage prevents modification or deletion of records, and cryptographic hashing lets auditors verify that entries have not been tampered with. Moving logs off the source hosts also removes them from the blast radius of a compromised application server. Together these controls directly satisfy the requirement that log data remain unaltered for the retention period.

Why this answer

Protecting log integrity requires moving records out of the control of the systems being monitored and storing them where they cannot be modified. Write-once storage plus cryptographic hashing delivers both immutability and verifiability, satisfying the one-year retention and tamper-evidence requirements. Local storage and email archives leave logs exposed to the same threats as the applications themselves.

Exam trap

The trap here is treating log retention as a storage-capacity problem when the requirement is really about tamper-evident integrity.

11
Multi-Selectmedium

An analyst is reviewing alerts from a network-based intrusion detection system (NIDS) deployed on a span port at the internet edge. Several alerts reference exploit attempts against services that are not exposed to the internet. Which TWO actions should the analyst take to improve the fidelity of the monitoring data? (Choose two.)

Select 2 answers
A.Verify the span port configuration and confirm which VLANs and interfaces are actually mirrored
B.Increase the alert severity of all exploit signatures to critical to ensure they are reviewed
C.Enable blocking mode so the NIDS drops packets matching the noisy signatures
D.Disable all exploit-class signatures and rely solely on anomaly-based detection
E.Tune the NIDS signature set to match the services actually exposed on the monitored segment
AnswersA, E

A span port that mirrors the wrong VLANs or an incorrect interface set can feed the NIDS traffic from internal segments, making internal-only services appear internet-facing in alerts. Confirming exactly what is mirrored establishes ground truth about what the sensor can see, which is essential before drawing conclusions from any alert and prevents misinterpretation of where attacks actually occurred.

Why this answer

Alerts against services that are not actually reachable indicate a mismatch between what the sensor is configured to detect or see and the environment it protects. Restricting signatures to the real exposed services removes irrelevant detections, and validating the span port mirroring confirms the sensor is observing the intended segment, so alerts can be trusted to reflect genuine attack surface.

Exam trap

The trap here is assuming noisy alerts require blocking or severity escalation, when the real issue is signature scope and what traffic the sensor actually receives.

12
MCQmedium

A security analyst is reviewing the organization's SIEM and notices that the daily log volume dropped by 60 percent overnight, but no maintenance window was scheduled. The analyst must determine whether this is a genuine reduction in activity or a monitoring failure. Which action should the analyst take FIRST to validate the health of the monitoring capability?

A.Perform a log-source inventory reconciliation against the SIEM's expected asset list and verify each critical source is actively sending events.
B.Increase the severity threshold for correlation rules so that only high-priority alerts are generated while the volume anomaly is investigated.
C.Run a full vulnerability scan against the entire environment to confirm whether any systems have stopped responding.
D.Review the SIEM's storage utilization and archive older logs to free capacity for incoming events.
AnswerA

A sudden drop in log volume usually indicates one or more sources stopped forwarding. Reconciling the expected source inventory against what the SIEM currently receives identifies silent sources, such as a failed collector or broken agent, before assuming the environment is quiet. This directly validates monitoring coverage and restores visibility.

Why this answer

A sharp, unexplained decrease in collected logs points to a monitoring failure rather than a quiet network. The fastest way to confirm this is to compare the SIEM's expected log sources with those actually reporting. Identifying silent sources restores visibility and prevents the organization from operating blind while believing it is fully monitored.

Exam trap

The trap here is assuming a drop in log volume means the environment became quieter, rather than suspecting that a log source stopped reporting.

13
Multi-Selecthard

A risk analyst is building a risk register for a cloud-hosted customer portal and must classify threats by their source. Which TWO of the following are examples of environmental threat sources that should be documented? (Choose two.)

Select 2 answers
A.A flood that inundates the facility housing the primary database cluster
B.A misconfigured firewall rule that exposes the portal's management interface
C.A disgruntled employee with administrative access to the portal's backend
D.A software vulnerability in the portal's third-party authentication library
E.A regional power grid failure that takes the primary data center offline
AnswersA, E

Natural disasters such as floods are environmental threats. They arise from geographic and climatic conditions rather than from people or technology failures. Including this in the risk register supports decisions about site selection, flood barriers, and geographic redundancy. It clearly belongs in the environmental category and is distinct from human or technical threat sources.

Why this answer

Environmental threat sources stem from natural events and supporting infrastructure, such as power failures and floods, that can disrupt operations regardless of human intent. Human threats like insiders and technical threats like misconfigured firewalls or vulnerable libraries are categorized separately. Correctly separating these categories sharpens the risk register and points to the right controls, from backup power to geographic redundancy.

Exam trap

The trap here is lumping all disruptive events together and missing that environmental threats specifically exclude human and technical origins.

14
MCQmedium

During a qualitative risk analysis, an organization assesses a threat of a data breach due to weak encryption. The likelihood is rated as 'Medium' and the impact as 'High'. According to a standard 3x3 risk matrix, what is the overall risk rating?

A.Medium
B.High
C.Low
D.Critical
AnswerB

A standard 3x3 matrix maps Medium likelihood against High impact to High risk, because impact drives severity upward when likelihood is not Low. The combination does not average to Medium; the matrix's defined intersection for these two ratings is High.

Why this answer

In a standard 3x3 qualitative risk matrix, likelihood and impact are each rated Low, Medium, or High, and the intersection of Medium likelihood with High impact yields a High overall risk rating. This is the conventional mapping used in most risk frameworks. The combination is serious enough to warrant prioritized treatment but does not reach the highest tier.

Exam trap

SSCP often tests the mechanical application of a risk matrix, and candidates err by assuming Medium likelihood always yields Medium risk regardless of impact, or by inventing a 'Critical' rating that does not exist in a 3x3 matrix.

How to eliminate wrong answers

Option A is wrong because Medium overall risk would result from combinations such as Medium likelihood with Medium impact or High likelihood with Low impact, not Medium likelihood with High impact. Option C is wrong because Low overall risk requires both likelihood and impact to be Low or near-Low, which is not the case here. Option D is wrong because Critical is not a standard rating in a 3x3 matrix (which uses Low, Medium, High); even in expanded matrices, Critical typically requires High likelihood with High impact, not Medium likelihood with High impact.

15
MCQmedium

An organization is required to maintain audit logs for at least one year for compliance purposes. Which log management practice best ensures the integrity of these logs?

A.Encrypting logs during transmission only
B.Compressing logs to save space
C.Storing logs on a standard file server with restricted permissions
D.Using write-once storage and digitally signing each log entry
AnswerD

Write-once storage prevents alteration or deletion of log records for the full retention period, while digital signatures let auditors verify each entry's authenticity and detect tampering. Together they satisfy the one-year integrity requirement, unlike practices that merely centralise, encrypt, or back up logs without guaranteeing immutability.

Why this answer

Write-once storage (e.g., WORM media or append-only filesystems) prevents any modification or deletion of log entries after they are written. Digitally signing each log entry ensures that any tampering can be detected by verifying the signature against the log data. Together, these provide non-repudiation and integrity, meeting compliance requirements for immutable audit logs.

Exam trap

The trap here is that candidates often choose restricted permissions (Option C) thinking access control is sufficient, but the SSCP exam emphasizes that integrity requires cryptographic proof and immutability, not just authorization.

How to eliminate wrong answers

Option A is wrong because encrypting logs only during transmission protects confidentiality in transit but does nothing to prevent alteration or deletion once the logs are stored. Option B is wrong because compressing logs reduces storage space but provides no integrity protection; compressed logs can still be modified or deleted. Option C is wrong because storing logs on a standard file server with restricted permissions relies on access controls, which can be bypassed by compromised accounts or insider threats, and does not guarantee immutability or detect tampering.

16
MCQeasy

A security administrator is reviewing the organization's risk register and notices that a risk related to outdated antivirus signatures has been assigned a low risk score because the likelihood is considered low. However, the impact if realized would be severe. Which risk analysis approach is being used, and what is a potential limitation of this approach?

A.Quantitative analysis; it expresses risk in monetary terms but may be limited by data availability.
B.FAIR analysis; it quantifies risk in financial terms and would not assign a low score based solely on likelihood.
C.Semi-quantitative analysis; it uses numeric scales but still requires subjective interpretation.
D.Qualitative analysis; it relies on subjective judgment and may overlook high-impact low-likelihood risks.
AnswerD

Qualitative analysis uses descriptive scales such as low, medium, high for likelihood and impact. In this case, the low likelihood led to a low overall risk score despite severe impact, which is a common limitation. Subjectivity can cause important risks to be underprioritized, especially when likelihood is underestimated.

Why this answer

The use of descriptive terms like 'low' and 'severe' indicates a qualitative risk analysis, which relies on expert judgment and subjective scales. A common limitation is that high-impact, low-likelihood risks may be underprioritized because the low likelihood dominates the overall score. This can lead to inadequate controls for catastrophic but rare events.

Other options describe quantitative or semi-quantitative methods that use numerical values, which are not present in the scenario.

Exam trap

The trap here is assuming that a low likelihood automatically justifies a low risk score without considering the severity of impact, which is a classic pitfall of qualitative analysis.

17
MCQmedium

A security manager is assessing the risk of insider threat for a healthcare organization. Which of the following is the most appropriate way to categorize a malicious insider who intentionally exfiltrates patient data?

A.Natural threat
B.Technical threat
C.Human threat
D.Environmental threat
AnswerC

A malicious insider is a human threat source because the action is deliberate and carried out by a person. Human threats can be internal or external, and they include both intentional and unintentional acts. In this scenario, the insider intentionally exfiltrates data, which clearly falls under the human threat category, making this the correct classification.

Why this answer

Threat sources are commonly categorized as natural, human, and environmental. A malicious insider who intentionally exfiltrates data is a human threat because the act is deliberate and performed by a person. This classification directs risk managers to apply controls such as background checks, least privilege, separation of duties, and continuous monitoring, which are effective against human threats.

Exam trap

The trap here is focusing on the technical method of exfiltration and misclassifying the threat source as technical, when the actor is human.

18
MCQhard

An organization experiences a ransomware attack that encrypts file servers. The annualized loss expectancy (ALE) for this risk is calculated as $150,000. The single loss expectancy (SLE) is $30,000. What is the annualized rate of occurrence (ARO)?

A.0.2
B.4.5
C.0.5
D.5
AnswerD

ARO is derived by dividing the annualised loss expectancy by the single loss expectancy: $150,000 ÷ $30,000 = 5. This means the ransomware event is expected to occur five times per year, satisfying the stem's given ALE and SLE values.

Why this answer

The annualized rate of occurrence (ARO) is calculated by dividing the annualized loss expectancy (ALE) by the single loss expectancy (SLE): ARO = ALE / SLE = $150,000 / $30,000 = 5. This means the ransomware attack is expected to occur five times per year, which is a key metric in quantitative risk analysis for prioritizing security controls.

Exam trap

The trap here is that candidates often confuse the formula and divide SLE by ALE instead of ALE by SLE, leading to the incorrect fractional answer (0.2) rather than the correct integer (5).

How to eliminate wrong answers

Option A (0.2) is wrong because it incorrectly inverts the formula, dividing SLE by ALE (30,000 / 150,000 = 0.2), which would imply the event occurs once every five years, not five times per year. Option B (4.5) is wrong because it likely results from a miscalculation, such as subtracting or misplacing a decimal, and does not correspond to any correct risk formula. Option C (0.5) is wrong because it represents half an occurrence per year, which would require an ALE of $15,000 (SLE × 0.5), not the given $150,000.

19
MCQmedium

A security analyst is reviewing logs and notices multiple failed login attempts for a user account, followed by a successful login from an unfamiliar IP address at 3:00 AM. Which type of risk is most directly indicated by this scenario?

A.Environmental risk
B.Human intentional risk
C.Human accidental risk
D.Technical risk
AnswerB

Repeated failed logins followed by a successful login from an unfamiliar IP at 3:00 AM indicates deliberate credential attack or account compromise. A person intentionally attempted unauthorised access, which is human intentional risk rather than accidental or environmental risk.

Why this answer

The scenario describes a successful login after multiple failed attempts from an unfamiliar IP address at an unusual time (3:00 AM). This pattern strongly indicates a deliberate brute-force or credential-stuffing attack, where an attacker intentionally attempts to gain unauthorized access. Therefore, the risk is human intentional, as it involves a malicious actor's purposeful actions.

Exam trap

ISC2 often tests the distinction between 'human intentional' and 'human accidental' by presenting a pattern of failed logins that could be mistaken for a user forgetting their password, but the successful login from an unfamiliar IP at an odd hour confirms malicious intent, not a mistake.

How to eliminate wrong answers

Option A is wrong because environmental risk refers to threats like natural disasters, power outages, or hardware failures, not to authentication anomalies. Option C is wrong because human accidental risk involves unintentional errors (e.g., mistyping a password or misconfiguring a firewall), not a pattern of repeated failed logins followed by a successful breach. Option D is wrong because technical risk relates to system vulnerabilities, software bugs, or protocol weaknesses (e.g., unpatched SSH flaws), not to the deliberate exploitation of credentials.

20
MCQmedium

A financial services firm runs a Security Information and Event Management (SIEM) platform that ingests Windows Security event logs, firewall syslog, and NetFlow records. The CISO asks the analyst to detect brute-force attacks against Active Directory domain accounts. Which approach should the analyst implement to achieve this goal?

A.Enable NetFlow export on the core router and alert when a single source IP generates more than 500 flows per minute to any internal subnet.
B.Configure a SIEM correlation rule that counts Windows Security Event ID 4625 per source IP within a rolling window and triggers when the threshold is exceeded.
C.Deploy an inline intrusion prevention system in front of the domain controllers and enable signatures for the SMB and LDAP protocols.
D.Create a SIEM rule that alerts whenever Windows Security Event ID 4624 is written to the domain controller's security log more than ten times per minute.
AnswerB

Event ID 4625 is generated on failed logon attempts and includes the source workstation and account name. Counting these events per source IP in a rolling window directly reveals repeated failed authentications characteristic of brute-force activity against Active Directory, which is exactly what the CISO requested in this scenario.

Why this answer

Failed logon events are the authoritative indicator of brute-force authentication activity, and Windows Security Event ID 4625 records each failed attempt with source and account details. Correlating these events per source IP over a rolling time window produces a high-fidelity alert while keeping false positives manageable. Flow data and successful logon events do not capture authentication failures, so they cannot satisfy the detection requirement.

Exam trap

The trap here is assuming that any high-volume network or authentication event indicates brute-force activity, when only repeated failed logon events (Event ID 4625) reveal it.

21
MCQeasy

A security analyst is reviewing logs and notices that an application log shows an error message indicating 'unhandled exception' followed by a stack trace. This log is most likely categorized as which type?

A.System log
B.Security log
C.Audit log
D.Application log
AnswerD

An unhandled exception with a stack trace is generated by the application's own runtime error handling, so it belongs in the application log. Operating system, security and network logs record different event sources and would not capture this application-level failure.

Why this answer

Application logs are generated by software applications and record application-specific events, including errors like 'unhandled exception' and stack traces. Since the log entry originates from an application and contains a stack trace (a developer-oriented diagnostic), it is categorized as an application log, not a system, security, or audit log.

Exam trap

The trap here is that candidates confuse 'unhandled exception' with a security event (like a crash due to an exploit) and incorrectly select Security log, but the question explicitly states the log contains a stack trace, which is a hallmark of application-level debugging output, not a security or system event.

How to eliminate wrong answers

Option A is wrong because system logs (e.g., /var/log/syslog or Windows System event log) record OS-level events such as driver failures, kernel panics, or service start/stop, not application-specific unhandled exceptions with stack traces. Option B is wrong because security logs (e.g., Windows Security log or /var/log/auth.log) track authentication attempts, privilege use, and policy violations, not application runtime errors. Option C is wrong because audit logs (e.g., Windows Audit log or Linux auditd logs) record compliance-relevant events like file access or user actions per predefined audit policies, not unhandled exceptions from application code.

22
MCQmedium

An organization decides to outsource its data center operations to a cloud provider. The cloud provider is responsible for physical security and hardware maintenance. This is an example of which risk response strategy?

A.Risk acceptance
B.Risk transfer
C.Risk avoidance
D.Risk mitigation
AnswerB

Transferring data centre operations shifts physical security and hardware maintenance obligations to the cloud provider, moving that risk off the organisation's books via contract. This satisfies the stem's description precisely: the provider assumes responsibility, though residual accountability for data and compliance remains with the outsourcing organisation.

Why this answer

Risk transfer involves shifting the financial impact of a risk to a third party, typically through insurance or outsourcing. By outsourcing data center operations to a cloud provider, the organization transfers the risks associated with physical security and hardware maintenance to the provider, making this a classic example of risk transfer.

Exam trap

SSCP often tests the confusion between risk transfer and risk mitigation, so candidates must recognize that outsourcing to a cloud provider is a transfer of operational risk, not an internal mitigation.

How to eliminate wrong answers

Option A is wrong because risk acceptance means acknowledging the risk and taking no action to mitigate it, which is not the case here. Option C is wrong because risk avoidance means eliminating the activity that introduces the risk entirely, whereas here the organization still operates in the cloud. Option D is wrong because risk mitigation means reducing the likelihood or impact of a risk through controls, but the organization is shifting the risk to a third party rather than reducing it internally.

23
MCQmedium

During a vulnerability scan, a security analyst discovers that several workstations are missing critical security patches. The organization decides to implement a compensating control by restricting network access to these workstations until patches are applied. Which risk response strategy is being used?

A.Avoidance
B.Mitigation
C.Transfer
D.Acceptance
AnswerB

Mitigation reduces risk likelihood or impact through controls, and restricting network access to unpatched workstations does exactly that by shrinking their exposure while patching is pending. It satisfies the stem's compensating-control constraint, since the underlying vulnerability remains until patches are applied, but the residual risk is lowered.

Why this answer

Restricting network access to vulnerable workstations reduces the likelihood of exploitation by limiting their exposure to potential threats. This is a classic mitigation strategy because it does not eliminate the vulnerability (missing patches) but instead implements a compensating control to reduce the risk to an acceptable level until the patches can be applied. Mitigation focuses on reducing the impact or probability of a risk event, which is exactly what network access restrictions achieve.

Exam trap

The trap here is that candidates often confuse 'mitigation' with 'avoidance' because both involve taking action, but mitigation reduces risk without eliminating the root cause, while avoidance removes the risk entirely by eliminating the activity or asset.

How to eliminate wrong answers

Option A is wrong because avoidance would require eliminating the vulnerability entirely (e.g., removing the workstations from the network permanently or replacing them), not just restricting access temporarily. Option C is wrong because transfer would involve shifting the risk to a third party (e.g., purchasing cyber insurance or outsourcing patch management), which is not happening here. Option D is wrong because acceptance would mean acknowledging the risk and taking no action, whereas the organization is actively implementing a compensating control to reduce risk.

24
MCQhard

A security operations center (SOC) analyst is investigating a series of alerts from the intrusion detection system (IDS) indicating possible command-and-control (C2) traffic. The analyst examines network flow logs and notices periodic outbound connections from an internal server to an external IP address every 30 minutes, with each connection transferring exactly 512 bytes. The external IP address has a low reputation score. Which of the following is the MOST likely explanation for this traffic pattern?

A.The server is infected with malware that is beaconing to a C2 server.
B.The server is exfiltrating data in small chunks to avoid detection.
C.The server is performing legitimate software updates from a vendor's server.
D.The server is sending heartbeat signals to a load balancer for high availability.
AnswerA

Periodic outbound connections at regular intervals with fixed small payloads are characteristic of malware beaconing. The low reputation of the external IP further supports this. Beaconing allows attackers to maintain command and control while blending into normal traffic. The consistent 30-minute interval and 512-byte size suggest automated communication, which is typical for malware checking in with its C2 infrastructure.

Why this answer

The correct answer is the one identifying malware beaconing. The combination of periodic connections, fixed small payload size, and low-reputation external IP is a classic indicator of command-and-control beaconing. Malware often uses regular intervals to check in with its C2 server, and the small, consistent payload size helps evade detection by not transferring large amounts of data.

This pattern is distinct from legitimate traffic like updates or heartbeats, which typically have different characteristics.

Exam trap

The trap here is assuming that any periodic outbound traffic is benign, such as software updates, without considering the fixed small payload and low-reputation destination that indicate malicious beaconing.

25
MCQmedium

A company wants to implement a security baseline for its Windows servers. Which of the following frameworks is most commonly used for this purpose?

A.CIS Benchmarks
B.ISO 27001
C.ITIL
D.COBIT
AnswerA

CIS Benchmarks publish consensus-derived, platform-specific secure configuration settings for Windows Server, covering registry, account and service hardening. They map directly to the stem's requirement for a commonly used Windows server baseline, unlike broader governance frameworks that prescribe no technical settings.

Why this answer

CIS Benchmarks are widely adopted security configuration guidelines for various systems, including Windows servers. They provide Level 1 (basic) and Level 2 (defense-in-depth) recommendations.

26
Multi-Selectmedium

A security analyst is configuring a SIEM to detect potential insider threats. Which TWO of the following data sources would be most relevant for detecting an employee exfiltrating sensitive data via email?

Select 2 answers
A.Physical access logs
B.Email gateway logs
C.Firewall logs
D.Data Loss Prevention (DLP) logs
E.DNS logs
AnswersB, D

Email gateway logs record sender, recipient, attachment, and message metadata, revealing anomalous outbound mail volumes or destinations. This makes them directly relevant to detecting an employee exfiltrating sensitive data through email, satisfying the insider-threat detection scenario.

Why this answer

Email gateway logs (B) are directly relevant because they record SMTP metadata such as sender, recipient, subject, attachment names, and message size, allowing the SIEM to spot an employee sending sensitive files to external or personal addresses. DLP logs (D) are equally relevant because DLP engines inspect email content and attachments against policies and generate alerts when classified data (e.g., PII, credit card numbers, source code) is transmitted outside the organization. Together these two sources give both the transport-level view and the content-level detection needed for insider exfiltration via email.

Physical access logs (A) only show building entry/exit events and cannot reveal email data movement, while firewall logs (C) capture IP/port connections but not email content or recipients, and DNS logs (E) only show domain name resolutions, none of which directly evidence data exfiltration through email.

Exam trap

The exam often tests the distinction between logs that show network-level activity (firewall, DNS) versus logs that inspect content or policy violations (email gateway, DLP), leading candidates to mistakenly choose firewall logs because they see 'outbound traffic' without considering content inspection.

27
MCQeasy

An organization wants to quantify the potential financial loss from a specific risk scenario. The risk team estimates that a data breach would cost $500,000 in direct expenses and that such an event is expected to occur once every five years. Which metric are they calculating?

A.Single loss expectancy (SLE)
B.Annualized loss expectancy (ALE)
C.Annualized rate of occurrence (ARO)
D.Exposure factor (EF)
AnswerB

ALE is calculated by multiplying the single loss expectancy (SLE) by the annualized rate of occurrence (ARO). Here, SLE is $500,000 and ARO is 1/5 = 0.2, so ALE = $500,000 × 0.2 = $100,000. This metric expresses the expected yearly financial loss from the risk.

Why this answer

The team is calculating annualized loss expectancy by multiplying the single loss expectancy by the annualized rate of occurrence. With an SLE of $500,000 and an ARO of 0.2 (once every five years), the ALE is $100,000. This quantifies the expected yearly financial impact and helps prioritize risk mitigation investments.

Exam trap

The trap here is selecting single loss expectancy because it matches the dollar figure in the scenario, but the question asks for the metric that incorporates the frequency of occurrence.

28
MCQhard

A security operations center uses a SIEM to monitor authentication activity. The team wants to detect a password spraying campaign in which a single source attempts a small number of common passwords against many different user accounts, staying below the per-account lockout threshold. Which correlation approach would BEST detect this activity?

A.Alert when a user authenticates successfully from a country where the organization has no offices
B.Alert when one source IP generates failed logons against many distinct accounts within a short window
C.Alert when any single account exceeds five failed logons within ten minutes
D.Alert when total failed logons across the environment exceed a fixed daily count
AnswerB

Password spraying is characterized by a single source touching numerous distinct accounts with few attempts each. Correlating failed authentication events by source address and counting unique targeted accounts over a short interval detects the horizontal pattern that per-account thresholds cannot see, which is why this approach best identifies the campaign described.

Why this answer

Password spraying avoids per-account lockout by trying common passwords against many accounts with only a few attempts each. The distinguishing signal is one source address generating failures across a large number of distinct accounts in a short period. Correlating failed authentications by source and counting unique usernames over a time window surfaces that horizontal pattern, whereas per-account or global thresholds do not.

Exam trap

The trap here is applying a per-account lockout-style threshold, which spraying is explicitly designed to stay beneath, instead of correlating across many accounts from one source.

29
MCQmedium

Which of the following is a key advantage of using a behavior-based detection approach in a User and Entity Behavior Analytics (UEBA) system?

A.Ability to detect previously unknown threats based on anomalous behavior
B.Requires less data processing than signature-based detection
C.Easier to configure and maintain
D.Lower false positive rates compared to signature-based detection
AnswerA

Behaviour-based detection builds baselines of normal user and entity activity, so deviations trigger alerts without relying on known signatures. This satisfies the stem's requirement for identifying previously unknown threats, catching novel attack patterns or compromised accounts whose activity has never been catalogued.

Why this answer

Behavior-based detection in UEBA establishes a baseline of normal user and entity activity using machine learning and statistical models. It then identifies deviations from this baseline, enabling the detection of novel or previously unknown threats, such as zero-day exploits or insider threats, without relying on pre-defined signatures.

Exam trap

The trap here is that candidates often assume behavior-based detection is easier or produces fewer false positives, but the exam emphasizes that its key advantage is detecting unknown threats, not operational simplicity or accuracy.

How to eliminate wrong answers

Option B is wrong because behavior-based detection typically requires more data processing and computational resources than signature-based detection, which simply matches patterns against a static database. Option C is wrong because behavior-based systems are more complex to configure and maintain, requiring tuning of baselines and thresholds, whereas signature-based systems are simpler to update with new signatures. Option D is wrong because behavior-based detection often produces higher false positive rates due to legitimate but unusual activities being flagged as anomalous, while signature-based detection has lower false positives for known threats but misses unknown ones.

30
Multi-Selectmedium

A risk analyst is conducting a quantitative risk analysis for a data center. The analyst needs to calculate the annualized loss expectancy (ALE). Which TWO of the following values are required to compute ALE? (Choose two.)

Select 2 answers
A.Return on security investment (ROSI)
B.Single loss expectancy (SLE)
C.Annualized rate of occurrence (ARO)
D.Asset value (AV)
E.Exposure factor (EF)
AnswersB, C

ALE is calculated as SLE multiplied by the annualized rate of occurrence (ARO). Therefore, SLE is a required input. SLE represents the monetary loss from a single incident, including costs such as downtime, data recovery, and reputational damage. Without SLE, the analyst cannot determine the expected yearly loss from a given risk, making this a necessary component.

Why this answer

The annualized loss expectancy is computed by multiplying the single loss expectancy by the annualized rate of occurrence. SLE represents the expected loss from one incident, while ARO estimates how many times that incident will occur in a year. Together they yield the expected yearly financial impact of a risk.

Exposure factor and asset value feed into SLE, but are not direct inputs to ALE. ROSI is a separate metric for evaluating controls.

Exam trap

The trap here is including exposure factor or asset value as direct inputs to ALE, when they are actually components of SLE, which in turn feeds ALE.

31
MCQeasy

A healthcare organization has completed a risk assessment and documented a set of identified risks in its risk register. Management decides not to purchase cyber insurance and not to implement any additional safeguards for a specific risk involving legacy medical devices. Which risk response strategy has management chosen?

A.Risk transfer
B.Risk acceptance
C.Risk avoidance
D.Risk mitigation
AnswerB

Acceptance means management acknowledges the risk, documents the decision, and proceeds without additional controls or insurance. Because the organization chose to add no safeguards and no coverage for the legacy device risk, it has formally accepted the residual exposure. Acceptance is a legitimate strategy when the cost of treatment exceeds the potential loss.

Why this answer

When management reviews a documented risk and consciously decides to add no controls and buy no insurance, the organization is accepting the risk. Acceptance is recorded in the risk register with a rationale and often a review date, so the decision is deliberate and auditable. Mitigation, transfer, and avoidance all require concrete actions that were explicitly declined for the legacy devices.

Exam trap

The trap here is reading the absence of action as a failure to respond, when formally documented inaction is itself the acceptance strategy.

32
MCQhard

An analyst is tuning an intrusion detection system that generates far too many alerts. The analyst wants to reduce noise while preserving detection of genuinely suspicious behavior. Which approach BEST supports this goal?

A.Lower the severity rating of all signature-based alerts so analysts can triage them last.
B.Baseline normal network and host activity, then write thresholds and correlation rules relative to that baseline.
C.Disable signature categories that have produced any false positives in the past month.
D.Increase the alert threshold on the console so events are only displayed after they repeat several times.
AnswerB

Baselining establishes what normal looks like for the environment, which lets the analyst set thresholds and correlations that flag meaningful deviations instead of expected traffic. This directly reduces false positives while retaining sensitivity to anomalies such as unusual outbound volume or new service behavior. It is the most effective noise-reduction technique because it adapts detection to the actual environment rather than to generic signatures.

Why this answer

Alert noise is best reduced by understanding the environment. Baselining normal traffic and behavior gives the analyst a reference point, so thresholds and correlation rules can distinguish expected activity from anomalies. This preserves detection of real threats while eliminating the benign events that flood the console, which is far more effective than suppressing categories or hiding alerts.

Exam trap

The trap here is treating alert volume as a display problem to be hidden with thresholds or severity changes rather than a detection-quality problem to be fixed with baselining.

33
MCQhard

An organization calculates the SLE for a server as $5,000 and the ARO as 0.2. What is the ALE?

A.$5,000
B.$10,000
C.$25,000
D.$1,000
AnswerD

Multiplying the single loss expectancy of $5,000 by the annualised rate of occurrence of 0.2 yields an annualised loss expectancy of $1,000. This satisfies the stem's requirement to derive the expected yearly financial loss from the two supplied quantitative risk values.

Why this answer

The Annualized Loss Expectancy (ALE) is calculated by multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO). Given SLE = $5,000 and ARO = 0.2, the ALE is $5,000 × 0.2 = $1,000. This is the expected annual financial loss from the server risk.

Exam trap

The trap here is that candidates often multiply SLE by the reciprocal of ARO (e.g., 5 instead of 0.2) or confuse ARO with a percentage, leading to an inflated ALE like $25,000.

How to eliminate wrong answers

Option A is wrong because $5,000 is the SLE, not the ALE; it ignores the ARO multiplier. Option B is wrong because $10,000 would result from multiplying SLE by 2, which is not the correct ARO of 0.2. Option C is wrong because $25,000 would result from dividing SLE by 0.2 (or multiplying by 5), which is a common arithmetic reversal error.

34
MCQhard

A security operations center (SOC) manager is evaluating a new intrusion detection system (IDS). The vendor claims the system can detect previously unknown attacks by building a baseline of normal network behavior and flagging deviations. Which detection methodology is the vendor describing?

A.Anomaly-based detection
B.Stateful protocol analysis
C.Signature-based detection
D.Heuristic-based detection
AnswerA

Anomaly-based detection establishes a baseline of normal activity and alerts on deviations from that baseline. This allows it to potentially identify zero-day or previously unknown attacks that do not match existing signatures. The vendor's description of building a baseline and flagging deviations aligns exactly with anomaly-based detection, making it the correct answer for this scenario.

Why this answer

Anomaly-based detection is designed to identify unknown attacks by modeling normal behavior and detecting statistically significant deviations. This approach can catch zero-day exploits and insider threats that signature-based systems miss. However, it often generates false positives when legitimate but unusual activity occurs, requiring tuning.

The vendor's claim of detecting previously unknown attacks through baseline deviation is a textbook description of anomaly-based detection.

Exam trap

The trap here is confusing anomaly-based detection with heuristic or stateful protocol analysis, which do not rely on a learned baseline of normal network behavior.

35
MCQmedium

A security engineer is reviewing system logs and notices that the log file size has not changed for several days, despite high system activity. Which log management concern does this indicate?

A.Incorrect time synchronization
B.Normal log rotation
C.Insufficient storage capacity
D.Log tampering or disabled logging
AnswerD

Static log size despite high activity indicates logging has been halted or the file altered, satisfying the stem's concern about missing audit records. Tampering or disabled logging removes the evidence trail entirely, unlike rotation or retention issues, which still produce new entries.

Why this answer

The log file size remaining static despite high system activity strongly indicates that logging has been disabled or the log files have been tampered with (e.g., truncated or replaced with empty files). Under normal operation, a busy system generates continuous log entries, causing the log file size to increase. A complete lack of size change over several days is a classic red flag for log integrity compromise, not a benign administrative action.

Exam trap

ISC2 SSCP often tests the misconception that a static log file size is due to log rotation, but rotation actually creates a new active log file with new entries, not a file that remains unchanged for days.

How to eliminate wrong answers

Option A is wrong because incorrect time synchronization would cause timestamps to be wrong, but it would not prevent log entries from being written; the log file size would still increase. Option B is wrong because normal log rotation typically renames or compresses the current log file and starts a new one, which would result in a new file with a non-zero size, not a static file size for days. Option C is wrong because insufficient storage capacity would cause the system to stop writing logs, but the log file would still show a final size from when writes ceased; the question states the size has not changed for several days, implying no writes occurred, which is more consistent with disabled logging or tampering than a full disk (which would still show the last written size).

36
MCQmedium

After implementing security controls, a risk assessment shows that a residual risk of data exfiltration remains. Which document should formally record this residual risk and the decision to accept it?

A.Incident response plan
B.Risk register
C.Business continuity plan
D.Security baseline
AnswerB

The risk register formally documents identified risks, their assessed residual level and the management decision to accept them, providing an auditable record. It satisfies the stem's requirement to record residual risk and the acceptance decision.

Why this answer

The risk register is the formal document used to track identified risks, their assessed likelihood and impact, and the chosen risk response. When a residual risk remains after controls are implemented, the risk register records that residual risk level and formally documents management's decision to accept it, including the rationale and approval. This ensures auditability and accountability for the accepted risk.

Exam trap

The trap here is that candidates confuse the risk register with the incident response plan, thinking that any risk-related documentation belongs in the incident response plan, but the risk register is specifically designed for tracking and formally accepting residual risks before any incident occurs.

How to eliminate wrong answers

Option A is wrong because the incident response plan documents procedures for detecting, responding to, and recovering from security incidents, not for recording residual risks or acceptance decisions. Option C is wrong because the business continuity plan focuses on maintaining critical business functions during and after a disruption, not on tracking residual risks from data exfiltration. Option D is wrong because a security baseline defines the minimum security configuration standards for systems, not a repository for risk acceptance decisions.

37
MCQhard

A security analyst is reviewing netflow data and notices a workstation periodically sending large amounts of data to an external IP address during non-business hours. The destination IP is not associated with any known business partner. The analyst suspects data exfiltration but needs to confirm before escalating. Which of the following actions would BEST validate the suspicion while preserving evidence?

A.Run a vulnerability scan against the workstation to check for missing patches.
B.Capture full packet data for the workstation and analyze the payload for sensitive information.
C.Immediately block the destination IP at the firewall to stop the transfer.
D.Disable the workstation's network account and force a password reset.
AnswerB

Capturing full packets allows deep inspection of the actual data being transferred, which can confirm whether sensitive information is leaving the network. This preserves evidence for incident response and avoids alerting the attacker. It is the most direct way to validate exfiltration without disrupting operations or tipping off the adversary.

Why this answer

Capturing full packet data allows the analyst to inspect the actual content being transmitted, which can definitively confirm whether sensitive data is being exfiltrated. This method preserves evidence and does not alert the attacker. Other actions like blocking, scanning, or disabling the account are either disruptive, do not confirm the suspicion, or could destroy evidence.

Validation should precede escalation and containment.

Exam trap

The trap here is choosing an active containment measure like blocking or disabling the account, which might stop the attack but destroys evidence and does not validate the suspicion.

38
Multi-Selectmedium

An organization is developing a risk register. Which TWO elements are essential for each risk entry?

Select 2 answers
A.Risk owner
B.Risk description
C.Residual risk level
D.Likelihood and impact rating
E.Mitigation cost
AnswersB, D

Correct: A clear description of the risk is fundamental.

Why this answer

Option B (Risk description) is essential because every risk register entry must clearly document the nature of the risk — what could happen, the threat/vulnerability involved, and the potential consequence — so it can be understood, communicated, and managed consistently. Option D (Likelihood and impact rating) is essential because risk registers require each risk to be assessed and prioritized by combining the probability of occurrence (likelihood) with the severity of the outcome (impact), which drives risk ranking and treatment decisions. Option A (Risk owner) is a valuable governance field but is not one of the two essential elements tested here, as ownership can be assigned after the risk is identified and described.

Option C (Residual risk level) is not essential at the point of entry because residual risk is determined only after mitigation or treatment has been applied. Option E (Mitigation cost) is not essential because cost is a treatment consideration, not a defining attribute required for every risk entry.

Exam trap

The SSCP exam often tests the distinction between essential initial elements (description and rating) versus downstream elements (owner, residual risk, cost) to see if candidates confuse the risk register's foundational data with later risk treatment outputs.

39
MCQeasy

Which of the following is a vulnerability source explicitly based on publicly known flaws?

A.Configuration weaknesses
B.Hardware failure
C.CVEs
D.Design flaws
AnswerC

CVEs are identifiers assigned to publicly disclosed flaws in specific products, so they directly satisfy the stem's requirement for a vulnerability source based on publicly known issues. Unlike proprietary or internal findings, each CVE entry is catalogued and openly accessible, letting analysts correlate exposures against vendor advisories.

Why this answer

C is correct because Common Vulnerabilities and Exposures (CVEs) are a standardized, publicly maintained list of known security flaws. Each CVE entry explicitly documents a specific vulnerability that has been discovered, verified, and published, making it a direct source of publicly known flaws used for vulnerability identification and remediation.

Exam trap

The trap here is that candidates may confuse 'vulnerability source' with 'vulnerability cause'—configuration weaknesses and design flaws are causes of vulnerabilities, but only CVEs represent a formal, publicly known source of flaw documentation.

How to eliminate wrong answers

Option A is wrong because configuration weaknesses are typically the result of improper system setup or misapplied security controls, not a source of publicly known flaws; they are often organization-specific and not cataloged in a public database. Option B is wrong because hardware failure is a physical reliability issue, not a security vulnerability, and is not tracked as a publicly known flaw in vulnerability databases like CVE. Option D is wrong because design flaws are inherent architectural weaknesses that may not be publicly documented or assigned a CVE identifier; they are often discovered during security reviews or penetration testing rather than being listed as known flaws.

40
MCQeasy

Which of the following is a primary purpose of implementing a security baseline such as the CIS Benchmarks?

A.To automate incident response procedures
B.To establish a minimum level of security for system configurations
C.To detect real-time threats
D.To comply with regulatory requirements for log retention
AnswerB

CIS Benchmarks define hardened configuration settings that every system must meet, so the baseline establishes a minimum security floor rather than a maximum or an optional target. This directly satisfies the stem's requirement for a primary purpose: consistent, documented minimum configuration across systems.

Why this answer

The primary purpose of implementing a security baseline such as the CIS Benchmarks is to establish a minimum level of security for system configurations. These benchmarks provide prescriptive, consensus-based configuration guidelines (e.g., disabling unnecessary services, setting file permissions, enforcing password policies) that reduce the attack surface and ensure a consistent, hardened starting point across all systems in an organization.

Exam trap

The exam often tests the distinction between a preventive control (security baseline) and detective/reactive controls (IDS, SIEM, SOAR), so candidates mistakenly choose options that describe monitoring or response functions instead of the foundational hardening purpose of a baseline.

How to eliminate wrong answers

Option A is wrong because automating incident response procedures is the function of a Security Orchestration, Automation, and Response (SOAR) platform or playbook, not a static configuration baseline like CIS Benchmarks. Option C is wrong because detecting real-time threats is performed by intrusion detection systems (IDS), security information and event management (SIEM) correlation rules, or endpoint detection and response (EDR) tools, not by a configuration baseline. Option D is wrong because complying with regulatory requirements for log retention is addressed by specific log retention policies and technical controls (e.g., setting log rotation, archival, and secure storage), whereas CIS Benchmarks focus on secure configuration states, not log retention durations.

41
MCQhard

A security analyst is reviewing alerts from a Network Intrusion Detection System (NIDS) that monitors a demilitarized zone segment. Over one week, the same alert fires hundreds of times for traffic that the business has confirmed is a legitimate partner integration. The analyst has verified the signature is correctly written and the traffic is truly benign. What is the most appropriate action?

A.Disable the NIDS sensor on the DMZ segment to stop the noise until the partner integration is retired.
B.Increase the alert severity of the signature so that analysts investigate every occurrence manually.
C.Create a tuned exception or suppression rule scoped to the specific signature, source, and destination of the partner traffic.
D.Delete the signature from the NIDS rule set and rely on firewall logs for DMZ monitoring.
AnswerC

Since the signature is accurate and the traffic is verified benign, the correct response is targeted tuning that suppresses only that pattern while preserving the signature for all other traffic. Scoping the exception to the exact source, destination, and signature keeps detection coverage intact for genuinely malicious activity on the DMZ segment.

Why this answer

When a signature is accurate but a verified benign source repeatedly triggers it, targeted suppression is the proportionate response. Scoping the exception to the exact signature, source, and destination eliminates the noise without weakening detection elsewhere. Deleting the signature or disabling the sensor would create blind spots, and raising severity would simply escalate benign alerts for manual review.

Exam trap

The trap here is treating verified benign traffic as a reason to remove or disable the detection, rather than tuning it narrowly to preserve coverage.

42
MCQmedium

A company's security policy requires that all logs be stored in a write-once, read-many (WORM) format. What is the primary security objective of this requirement?

A.To maintain log integrity
B.To ensure log availability
C.To improve log review speed
D.To reduce storage costs
AnswerA

WORM storage prevents modification or deletion of existing records, so attackers or rogue insiders cannot alter or erase evidence after intrusion. This preserves the log's evidential value and supports non-repudiation, directly satisfying the policy's objective of maintaining log integrity.

Why this answer

WORM (write-once, read-many) storage prevents any modification or deletion of log data after it is written, directly preserving the integrity of the logs. This ensures that log entries remain an accurate and unaltered record of events, which is critical for forensic investigations, compliance audits, and legal admissibility. The primary security objective is therefore to maintain log integrity, not availability, speed, or cost.

Exam trap

The trap here is confusing integrity with availability or cost, as candidates might think WORM ensures logs are always accessible or saves money, but the core security objective is preventing unauthorized modification.

How to eliminate wrong answers

Option B is wrong because availability focuses on ensuring logs are accessible when needed, whereas WORM specifically prevents alteration, not downtime or access issues. Option C is wrong because WORM storage does not inherently improve review speed; in fact, it can sometimes slow down analysis due to immutability constraints. Option D is wrong because WORM storage typically increases costs by using specialized media or cloud tiers, and cost reduction is not a security objective.

43
MCQmedium

An organization uses a network-based intrusion detection system (NIDS). An analyst receives an alert for a known exploit signature. Which type of detection is the NIDS using?

A.Anomaly-based detection
B.Behavior-based detection
C.Signature-based detection
D.Heuristic detection
AnswerC

The alert fired because traffic matched a stored pattern of a known exploit, which is precisely how signature-based detection works: it compares activity against a database of predefined attack signatures rather than profiling normal behaviour or anomalies.

Why this answer

The NIDS generated an alert based on a known exploit signature, which means it compared network traffic against a database of predefined patterns or fingerprints of known attacks. This is the defining characteristic of signature-based detection, where the system relies on exact or pattern matches to known malicious activity.

Exam trap

The trap here is that candidates confuse 'signature-based' with 'heuristic' detection, because both involve pattern matching, but heuristic detection uses fuzzy logic or statistical models rather than exact known signatures.

How to eliminate wrong answers

Option A is wrong because anomaly-based detection establishes a baseline of normal network behavior and flags deviations from that baseline, not known exploit signatures. Option B is wrong because behavior-based detection analyzes patterns of activity over time to identify suspicious behavior, such as unusual data exfiltration rates, rather than matching static signatures. Option D is wrong because heuristic detection uses algorithms or rules to infer malicious intent based on generalized characteristics or statistical analysis, not a direct match to a known exploit signature.

44
MCQmedium

A security analyst is reviewing logs from a SIEM and notices multiple failed login attempts for a privileged account from an IP address in a foreign country, followed by a successful login after hours. Which type of security monitoring tool would be most effective at detecting this pattern as anomalous behavior based on user baseline?

A.Signature-based IDS
B.Network-based IPS
C.Host-based IDS
D.User Behavior Analytics (UBA)
AnswerD

User Behaviour Analytics builds baselines of normal activity per account and flags deviations, so the foreign-IP, after-hours privileged login pattern stands out as anomalous. Signature or rule-based tools would miss this because no known attack signature matches.

Why this answer

User Behavior Analytics (UBA) is designed to establish a baseline of normal user activity and detect anomalies such as a privileged account logging in from an unusual geographic location after hours. Unlike signature or rule-based tools, UBA uses statistical modeling and machine learning to identify deviations from the user's historical patterns, making it ideal for detecting this type of credential misuse.

Exam trap

The trap here is that candidates often confuse anomaly detection with signature-based detection, assuming that a failed login followed by a success is a known brute-force pattern that a signature-based IDS would catch, but the question specifically asks for detection based on a user baseline, which is the core function of UBA, not signature matching.

How to eliminate wrong answers

Option A is wrong because a signature-based IDS relies on predefined patterns (e.g., known attack signatures) and cannot detect novel or anomalous behavior like a login from an unusual IP unless a specific signature exists for that scenario. Option B is wrong because a network-based IPS focuses on blocking malicious traffic at the network layer (e.g., exploiting vulnerabilities) and does not analyze user login patterns or establish behavioral baselines. Option C is wrong because a host-based IDS monitors system-level events (e.g., file changes, process execution) on a single host but lacks the cross-session, user-centric analytics needed to compare a login event against historical user behavior.

45
MCQmedium

A security analyst is reviewing firewall logs and notices repeated inbound TCP SYN packets to multiple destination ports on an internal web server, but no corresponding ACK packets are returned. The source IP address is spoofed. Which type of activity does this pattern most likely indicate?

A.TCP SYN flood
B.Smurf attack
C.UDP amplification attack
D.DNS cache poisoning
AnswerA

A TCP SYN flood sends numerous SYN packets with spoofed source addresses to exhaust the server's connection backlog. Because the source is spoofed, the server's SYN-ACK replies never reach a real host, so no final ACK completes the handshake, exactly matching the observed half-open connections.

Why this answer

The pattern of many TCP SYN packets with spoofed source addresses and no completing ACKs is the signature of a TCP SYN flood, a denial-of-service technique that exhausts the target's half-open connection table. The lack of ACK packets confirms that the handshake is never completed, which is characteristic of this attack.

Exam trap

The trap here is confusing a TCP SYN flood with other volumetric attacks such as UDP amplification or Smurf, even though the observed protocol and handshake behavior uniquely identify the SYN flood.

46
MCQmedium

A security operations center uses Nessus to scan its internal network nightly. A newly deployed web server is reporting a critical TLS vulnerability, but the vulnerability analyst confirms the server is configured to negotiate only TLS 1.3 with approved cipher suites. The scanner plugin was last updated eight weeks ago. Which action should the analyst take FIRST to resolve the discrepancy?

A.Escalate the finding to the change advisory board as a confirmed critical risk requiring emergency patching.
B.Accept the risk for the web server and document the exception because TLS 1.3 is enabled.
C.Disable the TLS-related plugin family on the scanner so the server stops generating noisy findings.
D.Update the Nessus plugins and credentials, then rescan the host to validate the finding before acting.
AnswerD

An eight-week-old plugin set can produce false positives because detection logic for TLS versions and cipher negotiation changes frequently. Refreshing plugins and ensuring credentialed scanning lets the scanner inspect the true negotiated protocol and cipher list rather than inferring from a banner or stale signature. Validating before remediation prevents wasted patching effort and preserves trust in the vulnerability management process.

Why this answer

Stale scanner content is a common source of false positives, especially for protocol and cipher detection where vendor logic evolves quickly. Before treating the TLS finding as real, the analyst should refresh plugins, confirm credentials work, and rescan so the scanner evaluates the actual negotiated protocol and cipher suites. Only validated findings should be escalated, suppressed, or formally accepted as risk.

Exam trap

The trap here is assuming a scanner finding is authoritative and jumping straight to remediation or risk acceptance instead of validating the scan data first.

47
MCQmedium

During a risk assessment, a company identifies that a legacy system cannot be patched due to vendor end-of-life. The system is critical to operations. Which risk response strategy is most appropriate initially?

A.Avoid the risk by decommissioning the system immediately
B.Transfer the risk by purchasing cyber insurance
C.Accept the risk without any further action
D.Mitigate the risk by implementing compensating controls
AnswerD

Compensating controls such as network segmentation or strict access restrictions reduce the likelihood or impact of exploitation on the unpatched legacy system, which is mitigation. Avoidance would mean decommissioning a system the stem states is critical to operations.

Why this answer

When a legacy system cannot be patched due to vendor end-of-life, the most appropriate initial risk response is to implement compensating controls. Compensating controls, such as network segmentation, strict access controls, or an intrusion detection system, reduce the likelihood or impact of exploitation without requiring a patch. This approach balances operational necessity with security, as immediate decommissioning (avoidance) may be infeasible for a critical system.

Exam trap

The trap here is that candidates often confuse risk acceptance with passive inaction, but the SSCP exam expects that acceptance must be a deliberate decision with documented justification and often paired with compensating controls, not simply ignoring the risk.

How to eliminate wrong answers

Option A is wrong because decommissioning a critical system immediately would disrupt operations, and risk avoidance is not appropriate when the system is essential to business functions; the goal is to manage risk, not eliminate it at the cost of operations. Option B is wrong because transferring risk via cyber insurance does not reduce the technical vulnerability; it only provides financial compensation after a breach, which does not address the immediate security gap. Option C is wrong because accepting the risk without any further action is negligent; while acceptance is a valid strategy, it requires documented understanding and often compensating controls, not passive inaction.

48
Multi-Selecthard

A risk analyst is building a threat model for a new customer-facing web application. The analyst must identify threat sources and classify them appropriately. Which TWO of the following are examples of environmental or natural threat sources that should be documented in the risk assessment? (Choose two.)

Select 2 answers
A.A disgruntled former employee who retains knowledge of internal application architecture.
B.A prolonged power outage affecting the cloud region where the application is deployed.
C.An organized criminal group targeting the application for financial fraud.
D.A regional flood that could inundate the primary data center hosting the application.
E.An unstructured software error in a third-party payment library that causes data corruption.
AnswersB, D

Power loss is an environmental threat source, whether caused by grid failure or weather. It threatens availability of the application and its supporting infrastructure, so it must be documented alongside human threats. Mitigations include uninterruptible power supplies, generator testing, and multi-region failover.

Why this answer

Natural and environmental threat sources originate in the physical world and affect assets regardless of human intent. Flooding and extended power loss both threaten the web application's availability and supporting infrastructure, so they must be documented in the risk assessment to justify continuity, redundancy, and recovery investments.

Exam trap

The trap here is mixing human and technical threat sources into the environmental category, when only naturally occurring physical events qualify.

49
MCQhard

A financial services firm classifies its customer database as its most critical asset. The risk register shows a single entry for "unauthorized database access" with an annualized loss expectancy of $2,000,000. Management approves a database activity monitoring (DAM) solution plus tokenization of account numbers, which reduces the annualized loss expectancy to $300,000. Which of the following BEST describes the $300,000 figure in risk terms?

A.The risk appetite threshold approved by the board for this asset
B.The total cost of ownership of the implemented controls
C.The inherent risk of the database before any controls existed
D.The residual risk remaining after the controls are applied
AnswerD

Residual risk is the expected loss that persists after mitigation. The original annualized loss expectancy was $2,000,000, and the approved controls reduced it to $300,000; that remaining exposure is precisely the residual risk. Recording it lets management compare it against the organization's risk appetite and decide whether further treatment, transfer, or acceptance is warranted.

Why this answer

Annualized loss expectancy quantifies expected yearly loss for a given risk. Applying controls that cut the figure from $2,000,000 to $300,000 leaves $300,000 of expected annual loss still present, which is the residual risk. Documenting that value allows comparison with the organization's risk tolerance and supports decisions about accepting or further treating the remaining exposure.

Exam trap

The trap here is treating any post-control dollar figure as control cost or as inherent risk, when a reduced expected loss is by definition residual risk.

50
Multi-Selecthard

A security team is implementing a vulnerability management program. According to industry best practices, which THREE of the following are essential components of a mature vulnerability management process?

Select 3 answers
A.Manual patch management
B.Quarterly vulnerability scans
C.False positive management process
D.Remediation SLAs based on severity
E.Continuous scanning capability
AnswersC, D, E

A false positive management process is essential because it triages scanner findings that incorrectly flag benign activity, preventing analyst fatigue and wasted remediation effort. Without it, genuine vulnerabilities get buried, so the programme cannot mature or prioritise accurately.

Why this answer

Option C (False positive management process) is essential because scanners inevitably generate findings that are not genuine vulnerabilities, and a mature program must triage, validate, and document these to prevent wasted remediation effort and alert fatigue. Option D (Remediation SLAs based on severity) is correct because best practices such as those in NIST SP 800-40 and CIS Controls require risk-based timeframes (for example, critical vulnerabilities remediated in days versus low-severity in weeks) to prioritize limited resources. Option E (Continuous scanning capability) is correct because mature programs move beyond point-in-time assessments to ongoing discovery and monitoring, enabling timely detection of new vulnerabilities and asset changes.

Option A (Manual patch management) does not belong because mature programs automate patching and configuration management rather than relying on manual processes, which are error-prone and unscalable. Option B (Quarterly vulnerability scans) does not belong because quarterly scanning alone is insufficient and outdated; mature programs scan continuously or at least much more frequently, and quarterly scans are typically only a compliance minimum, not a best-practice component.

Exam trap

A common misconception in vulnerability management is that meeting compliance requirements (e.g., quarterly scans) is sufficient for maturity. However, a mature program requires continuous scanning, remediation SLAs based on severity, and a false positive management process to ensure efficiency and effectiveness.

51
MCQmedium

A security analyst reviews the health dashboard of the organization's Security Information and Event Management (SIEM) platform and notices that event ingestion from the primary domain controllers stopped at 02:00, while all other log sources continue to report normally. Which of the following should the analyst investigate FIRST to determine why domain controller logs are missing?

A.The network firewall rules governing outbound syslog traffic from all monitored hosts
B.The SIEM correlation rules that map domain controller event IDs to alert severity levels
C.The Windows Event Forwarding subscription and the collector service status on the domain controllers
D.The retention and rollover settings on the SIEM storage volumes
AnswerC

Missing events from a single source class while all other sources report normally points to the collection path specific to those hosts. Windows Event Forwarding subscriptions, the Windows Event Collector service, and the source-side forwarding service are the components that deliver domain controller events to the SIEM, so verifying their status and subscription health is the correct first diagnostic step.

Why this answer

When one log source class stops feeding a SIEM while others continue, the fault lies in the collection pipeline unique to that source, not in shared infrastructure. Windows Event Forwarding subscriptions and the Windows Event Collector service are the exact mechanisms that transport domain controller events, so checking subscription health and collector service state isolates the failure quickly before broader troubleshooting.

Exam trap

The trap here is assuming that a monitoring gap means the SIEM platform itself is broken, when a single silent source usually indicates a source-side collection or forwarding failure.

52
MCQhard

During a risk assessment, a company identifies that a legacy system has a known CVE with a CVSS score of 9.8. The system is critical but cannot be patched immediately. The management decides to implement strict network segmentation and monitor the system continuously. This risk response is best described as:

A.Risk acceptance
B.Risk avoidance
C.Risk transfer
D.Risk mitigation
AnswerD

Risk mitigation reduces the likelihood or impact of a threat. Since patching is impossible, segmentation limits the attack surface and continuous monitoring shortens detection time, directly lowering the CVE's exploitability while the system remains critical and unpatched.

Why this answer

Risk mitigation, because the company is implementing strict network segmentation and continuous monitoring to reduce the likelihood and impact of the vulnerability being exploited. This reduces the risk without eliminating it entirely, which is the essence of mitigation. The CVSS score of 9.8 indicates critical severity, and the controls (e.g., ACLs, VLANs, IDS/IPS) directly address the attack surface.

Exam trap

The trap here is that candidates confuse 'risk mitigation' with 'risk acceptance' because the system remains vulnerable, but the key distinction is that active controls are applied to reduce risk, not merely acknowledged.

How to eliminate wrong answers

Option A is wrong because risk acceptance would involve acknowledging the risk without taking any active controls, but here the company actively deploys segmentation and monitoring. Option B is wrong because risk avoidance would require removing the system or ceasing its operation entirely, which is not done since the system remains in use. Option C is wrong because risk transfer would involve shifting the financial burden or liability to a third party (e.g., insurance or outsourcing), not implementing technical controls.

53
MCQhard

A security operations center (SOC) receives an alert from its intrusion detection system (IDS) about a possible SQL injection attack against a web server. The SOC analyst reviews the IDS signature and sees that it triggered on a request containing the string 'OR 1=1'. However, the web application logs show that the request was blocked by a web application firewall (WAF) and returned a 403 error. Which of the following BEST describes the nature of this alert?

A.True positive; the IDS correctly detected an attack, and the WAF successfully blocked it.
B.True positive; the IDS correctly detected an attack, and the WAF failed to block it.
C.False negative; the IDS failed to detect the attack, but the WAF blocked it.
D.False positive; the request was legitimate and the IDS misclassified it.
AnswerA

The IDS correctly identified a SQL injection attempt (true positive). The WAF then blocked the request, as evidenced by the 403 error. This means the attack was detected and prevented. The alert is a true positive because the IDS accurately flagged malicious activity, even though the attack was stopped. The SOC should still investigate the source and consider tuning.

Why this answer

The IDS correctly identified a SQL injection attempt, making it a true positive. The WAF then blocked the request, as shown by the 403 error, so the attack was prevented. This is a true positive detection with successful mitigation.

It is not a false positive because the traffic was malicious, and not a false negative because the IDS did alert. The SOC should investigate the source and consider whether the IDS signature needs tuning to reduce noise.

Exam trap

The trap here is equating a true positive alert with a successful attack, but a true positive can occur even when the attack is blocked by another control.

54
MCQmedium

During a qualitative risk analysis, an organization assigns a risk rating of 'High' for a specific threat. Which combination of factors most directly leads to this rating?

A.High probability and high impact
B.Low probability and low impact
C.High probability and low impact
D.Low probability and high impact
AnswerA

Qualitative risk matrices derive ratings from likelihood and consequence, so high probability combined with high impact maps directly to a High rating. This satisfies the stem's request for the factor combination producing that specific rating.

Why this answer

In qualitative risk analysis, risk rating is determined by the product of probability and impact. A 'High' rating directly results from both high probability and high impact, as this combination represents the greatest potential for loss. This aligns with the risk matrix approach where the highest risk scores occupy the top-right quadrant.

Exam trap

ISC2 often tests the misconception that high impact alone is sufficient for a 'High' risk rating, ignoring that probability must also be high to reach the top risk level.

How to eliminate wrong answers

Option B is wrong because low probability and low impact produce a 'Low' risk rating, not 'High'. Option C is wrong because high probability combined with low impact typically yields a 'Medium' or 'Moderate' rating, as the low impact reduces overall risk severity. Option D is wrong because low probability with high impact often results in a 'Medium' risk rating, as the low likelihood mitigates the overall risk despite the high potential damage.

55
MCQeasy

Which of the following is a primary purpose of a security baseline, such as the CIS Benchmarks?

A.To provide a secure configuration standard for systems
B.To calculate annualized loss expectancy
C.To replace the need for vulnerability scanning
D.To detect intrusions in real-time
AnswerA

CIS Benchmarks codify hardened, vendor-neutral configuration settings for operating systems, applications and cloud platforms. A security baseline supplies that documented secure configuration standard, giving administrators a measurable reference to assess and remediate deviations, which is precisely the purpose the question asks for.

Why this answer

A security baseline like the CIS Benchmarks establishes a hardened, consistent configuration standard for operating systems, applications, and network devices. This reduces the attack surface by disabling unnecessary services, enforcing least privilege, and applying specific registry or file permission settings. It is a foundational step in secure system deployment and ongoing compliance.

Exam trap

ISC2 SSCP emphasizes the distinction between proactive configuration standards (baselines) and ongoing operational controls like vulnerability scanning and intrusion detection. Candidates often mistakenly think a baseline replaces scanning or detection, when in fact it is a preventative measure.

How to eliminate wrong answers

Option B is wrong because annualized loss expectancy (ALE) is a quantitative risk analysis formula (SLE × ARO) used in risk management, not a function of a security baseline. Option C is wrong because a security baseline does not replace vulnerability scanning; baselines define secure configurations, while scanning actively identifies missing patches or misconfigurations. Option D is wrong because intrusion detection in real-time is performed by IDS/IPS systems (e.g., Snort, Suricata) that analyze network traffic or host logs, not by a static configuration baseline.

56
MCQeasy

Which type of IDS uses a baseline of normal behavior to detect anomalies?

A.Host-based IDS (HIDS)
B.Anomaly-based IDS
C.Network-based IDS (NIDS)
D.Signature-based IDS
AnswerB

Anomaly-based IDS builds a statistical or behavioural baseline of normal activity, then flags deviations from it as potential intrusions. This directly satisfies the stem's requirement for a baseline of normal behaviour, unlike signature-based detection, which matches known attack patterns rather than profiling legitimate traffic.

Why this answer

Anomaly-based IDS (B) is correct because it establishes a baseline of normal network or system behavior through statistical modeling or machine learning, then flags deviations from that baseline as potential intrusions. This contrasts with signature-based systems that rely on predefined patterns of known attacks. The core mechanism involves profiling metrics such as CPU usage, network traffic volume, or protocol deviations over time to identify anomalies.

Exam trap

ISC2 SSCP often tests the distinction between detection methodology (anomaly vs. signature) and deployment type (host-based vs. network-based), leading candidates to mistakenly choose HIDS or NIDS because they associate them with behavioral monitoring, when the question specifically asks about the detection method that uses a baseline.

How to eliminate wrong answers

Option A is wrong because Host-based IDS (HIDS) monitors activity on a single host (e.g., system logs, file integrity) but does not inherently use a baseline of normal behavior; it can be signature-based or anomaly-based depending on implementation. Option C is wrong because Network-based IDS (NIDS) analyzes network traffic at the packet level but, like HIDS, is a deployment type, not a detection methodology; it can use signatures or anomalies. Option D is wrong because Signature-based IDS relies on a database of known attack signatures (e.g., Snort rules) and cannot detect novel or zero-day attacks without an existing pattern, whereas anomaly-based detection uses behavioral baselines.

57
MCQmedium

A company's vulnerability scanner reports a critical vulnerability in a third-party library. The remediation SLA for critical vulnerabilities is 48 hours. However, the patch is not yet available from the vendor. Which of the following is the most appropriate immediate action?

A.Remove the vulnerable software immediately
B.Extend the SLA to 30 days
C.Accept the risk because the vendor has not released a patch
D.Implement compensating controls to mitigate the vulnerability
AnswerD

With no vendor patch available, compensating controls such as virtual patching, network segmentation or tightened access restrictions reduce exposure while the SLA clock runs. This satisfies the stem's immediate-action requirement without breaching the 48-hour critical remediation SLA.

Why this answer

When a patch is unavailable, implementing compensating controls (e.g., network segmentation, WAF rules, disabling unused features) is the immediate action to reduce risk exposure while awaiting an official fix. This aligns with the NIST SP 800-40 risk mitigation framework, which prioritizes compensating controls when patching is not feasible. Simply removing the software (A) may break business operations, extending the SLA (B) violates policy, and accepting risk (C) ignores the need for active mitigation.

Exam trap

The trap here is that candidates assume 'no patch available' means 'no action required' (Option C), but the SSCP exam expects proactive risk mitigation through compensating controls even when patching is delayed.

How to eliminate wrong answers

Option A is wrong because removing the vulnerable software immediately could cause significant operational disruption and is not required if compensating controls can reduce risk to an acceptable level. Option B is wrong because extending the SLA to 30 days violates the established 48-hour remediation policy and does not address the immediate threat; SLAs are not arbitrarily extended without formal risk acceptance. Option C is wrong because accepting risk without implementing any controls is negligent; the absence of a vendor patch does not justify inaction—compensating controls must be applied to reduce the likelihood of exploitation.

58
MCQeasy

Which term describes the risk that remains after implementing risk mitigation controls?

A.Accepted risk
B.Residual risk
C.Inherent risk
D.Control risk
AnswerB

Residual risk is the exposure that persists once mitigation controls are applied, since no control eliminates threat entirely. It directly satisfies the stem's requirement for risk remaining after implementation, distinguishing it from inherent risk (before controls) and total risk. Risk acceptance, transfer or avoidance address that remainder rather than describing it.

Why this answer

Residual risk is the risk that remains after all risk mitigation controls have been applied. It represents the portion of the original risk that cannot be eliminated or reduced further, and it must be accepted by management if it falls within the organization's risk appetite.

Exam trap

The trap here is that candidates confuse 'residual risk' with 'accepted risk,' but accepted risk is the subset of residual risk that management formally approves to tolerate, not the risk that remains after controls.

How to eliminate wrong answers

Option A is wrong because accepted risk is a decision to formally acknowledge and tolerate a specific risk, often after evaluating residual risk, not the risk that remains after controls. Option C is wrong because inherent risk is the level of risk before any controls are implemented, not after. Option D is wrong because control risk is the risk that a control may fail or be ineffective, not the leftover risk after controls are applied.

59
MCQhard

A company is preparing for a PCI DSS assessment. According to PCI DSS requirements, how frequently must internal vulnerability scans be performed?

A.Annually
B.Monthly
C.Weekly
D.Quarterly
AnswerD

PCI DSS mandates that internal vulnerability scans be run at least quarterly, satisfying the assessment's recurring scanning obligation. Scans must also be repeated after any significant network change, but the baseline cadence the question asks for is quarterly.

Why this answer

PCI DSS Requirement 11.2.1 mandates that internal vulnerability scans must be performed at least quarterly and after any significant change in the network. This frequency ensures that new vulnerabilities introduced since the last scan are identified and remediated before they can be exploited. Quarterly scans are a minimum; more frequent scanning is recommended for high-risk environments.

Exam trap

The trap here is that candidates often confuse the quarterly internal scan requirement with the weekly external scan requirement (for internet-facing systems), leading them to incorrectly select 'Weekly' as the answer.

How to eliminate wrong answers

Option A is wrong because annual scans are far too infrequent to meet PCI DSS requirements, which demand a minimum of quarterly scans to keep pace with emerging vulnerabilities. Option B is wrong because monthly scans, while more frequent than required, are not the mandated minimum; PCI DSS specifically requires quarterly scans, not monthly. Option C is wrong because weekly scans are not required by PCI DSS for internal scans; the standard explicitly states quarterly as the baseline frequency, though weekly scans may be used for external scans or as a best practice.

60
Multi-Selectmedium

A security team is conducting a risk assessment for a new cloud-based collaboration platform. They need to identify potential threats and vulnerabilities. Which TWO of the following are examples of technical vulnerabilities that should be considered? (Choose two.)

Select 2 answers
A.Lack of security awareness training for employees.
B.Weak encryption algorithms used for data in transit.
C.Insufficient physical security at the data center.
D.Unpatched software on the platform's servers.
E.Lack of a formal risk management policy.
AnswersB, D

Weak encryption is a technical vulnerability because it is a flaw in the cryptographic implementation that could allow unauthorized access to data. It is a configuration or design weakness in the technology. Risk assessments must evaluate encryption strength to protect data confidentiality and integrity. This is a technical issue.

Why this answer

Technical vulnerabilities are weaknesses in hardware, software, or configurations that can be exploited. Unpatched software and weak encryption algorithms are both technical flaws that directly affect the security of the cloud platform. The other options—lack of training, insufficient physical security, and missing policy—are administrative, physical, or governance issues, not technical vulnerabilities.

A comprehensive risk assessment should consider all types, but the question specifically targets technical ones.

Exam trap

The trap here is confusing administrative or physical weaknesses with technical vulnerabilities, especially because all can contribute to risk.

61
MCQhard

A security analyst is tuning a SIEM and needs to reduce false positives from a rule that alerts on failed logins. The rule currently triggers on any single failed login. Which modification would best reduce false positives while still detecting brute-force attacks?

A.Add a threshold of 5 failed logins within 5 minutes
B.Disable the rule entirely
C.Increase the severity level of the alert
D.Ignore failed logins from known users
AnswerA

A threshold of five failures within five minutes aggregates events, so isolated typos no longer trigger alerts while sustained bursts still do. This directly satisfies the stem's constraint of cutting false positives without losing brute-force detection, unlike disabling the rule entirely.

Why this answer

Adding a threshold of 5 failed logins within 5 minutes reduces false positives from isolated accidental lockouts while still detecting the sustained pattern of failed attempts characteristic of brute-force attacks. This aligns with SIEM tuning best practices where aggregation over a time window filters out noise without losing signal.

Exam trap

The SSCP exam often tests the misconception that increasing severity or ignoring specific users reduces false positives, when in fact only time-based thresholding or contextual filtering (e.g., source IP reputation) properly addresses the root cause of noise from isolated events.

How to eliminate wrong answers

Option B is wrong because disabling the rule entirely would remove detection of brute-force attacks, creating a security gap. Option C is wrong because increasing the severity level does not reduce false positives; it only changes the alert's priority, leaving the same number of noisy alerts. Option D is wrong because ignoring failed logins from known users would miss attacks where a legitimate user's account is compromised and used for brute-force attempts, and it assumes user identity is reliably verified at the authentication layer.

62
MCQeasy

Which of the following is a common vulnerability source that would be documented in a risk register?

A.Password policies
B.Intrusion alerts
C.Firewall logs
D.CVE entries
AnswerD

CVE entries provide standardised identifiers for publicly disclosed software flaws, giving the risk register concrete, traceable vulnerability data. They satisfy the stem's requirement for a common vulnerability source by cataloguing specific weaknesses that feed directly into likelihood and impact assessments, unlike broader threat categories or control gaps.

Why this answer

D is correct because CVE (Common Vulnerabilities and Exposures) entries are standardized identifiers for known security vulnerabilities, making them a direct source of vulnerability information that should be documented in a risk register. A risk register captures identified risks, including specific vulnerabilities, and CVE entries provide the precise technical details needed to assess and track those risks.

Exam trap

ISC2 often tests the distinction between vulnerability sources (like CVE entries) and security controls or monitoring outputs (like password policies, intrusion alerts, or firewall logs), trapping candidates who confuse operational data with vulnerability documentation.

How to eliminate wrong answers

Option A is wrong because password policies are security controls or guidelines, not vulnerability sources; they define rules for password creation and management, whereas a risk register documents actual or potential vulnerabilities, not policy documents. Option B is wrong because intrusion alerts are outputs from an intrusion detection system (IDS) indicating potential security incidents, not vulnerability sources; they represent events that may exploit vulnerabilities, but the alerts themselves are not the vulnerabilities. Option C is wrong because firewall logs are records of network traffic and firewall rule actions, used for monitoring and forensics, not a source of vulnerability information; they can help identify attacks but do not list or describe vulnerabilities like CVE entries do.

63
MCQmedium

A security analyst is tuning a SIEM to reduce false positives. Which of the following actions is most likely to reduce false positives while maintaining detection of real threats?

A.Increase the severity of all alerts to high
B.Modify correlation rules to require multiple events before alerting
C.Disable all anomaly-based detection rules
D.Create a whitelist for known benign IP addresses
AnswerB

Requiring several correlated events before an alert fires suppresses single-event noise, which is the main source of false positives, while genuine multi-stage attacks still trigger. This threshold tuning preserves detection fidelity better than disabling rules outright.

Why this answer

Modifying correlation rules to require multiple events before alerting reduces false positives by ensuring that a single benign event does not trigger an alert. This technique, often called 'thresholding' or 'event correlation,' filters out noise while still detecting multi-step attack patterns, such as a brute-force login attempt that requires multiple failed logins within a time window.

Exam trap

The trap here is that candidates often confuse 'reducing false positives' with 'eliminating all alerts,' leading them to choose disabling detection rules (Option C) or whitelisting (Option D), rather than understanding that correlation tuning preserves detection capability while filtering noise.

How to eliminate wrong answers

Option A is wrong because increasing the severity of all alerts to high does not reduce false positives; it merely reclassifies them, potentially causing alert fatigue and desensitizing analysts to critical incidents. Option C is wrong because disabling all anomaly-based detection rules would eliminate the ability to detect unknown or zero-day threats, which rely on behavioral baselines rather than static signatures. Option D is wrong because creating a whitelist for known benign IP addresses reduces false positives only for those specific IPs, but does not address false positives from other sources or from legitimate traffic that does not match the whitelist; it also risks missing real threats if an attacker spoofs a whitelisted IP.

64
MCQeasy

A security administrator is reviewing a vulnerability scan report and notices a finding labeled as a false positive. What is the most appropriate immediate action?

A.Apply the recommended patch immediately to resolve the finding.
B.Document the false positive and tune the scanner to reduce recurrence.
C.Ignore the finding because it is not a real vulnerability.
D.Escalate the finding to the incident response team as a potential breach.
AnswerB

When a vulnerability scan yields a false positive, the correct immediate step is to verify it, document the finding, and adjust scanner settings or exclusions to prevent similar false alerts. This maintains the integrity of the vulnerability management process and reduces wasted effort. Patching or ignoring without documentation would be inappropriate, making documentation and tuning the best course of action.

Why this answer

False positives in vulnerability scans should be verified, documented, and used to tune the scanner to reduce future occurrences. This ensures that the vulnerability management process remains efficient and credible. Applying patches unnecessarily, ignoring without documentation, or escalating to incident response are all incorrect because they either waste resources or fail to address the root cause of the false alert.

Exam trap

The trap here is treating a false positive as either a real vulnerability requiring patching or as something to ignore, rather than as a scanner accuracy issue to be documented and tuned.

65
MCQmedium

A company stores log files on a dedicated log server. To ensure log integrity, they implement a solution where logs are written to a WORM (Write Once, Read Many) device. Which property does this primarily protect?

A.Integrity
B.Non-repudiation
C.Availability
D.Confidentiality
AnswerA

WORM media prevent modification or deletion of records once written, so any tampering becomes evident. This directly upholds integrity, the property concerned with unauthorised alteration, rather than confidentiality or availability, satisfying the stem's requirement that stored log files remain trustworthy for forensic and compliance purposes.

Why this answer

WORM (Write Once, Read Many) technology ensures that once data is written, it cannot be altered, deleted, or overwritten. This directly protects the integrity of the log files by preventing any unauthorized or accidental modification, which is critical for maintaining a reliable audit trail.

Exam trap

Candidates often confuse integrity with non-repudiation, thinking that preventing modification also proves who wrote the data, but WORM alone does not provide proof of origin without additional authentication mechanisms.

How to eliminate wrong answers

Option B is wrong because non-repudiation is primarily about proving the origin of data (e.g., through digital signatures or PKI), not about preventing modification after writing. Option C is wrong because availability concerns ensuring data is accessible when needed, which WORM does not directly address (it may even hinder availability if the device fails). Option D is wrong because confidentiality involves preventing unauthorized access or disclosure, whereas WORM focuses on write protection, not read access controls.

66
MCQeasy

A risk analyst is documenting threats for a new cloud-hosted application. The analyst must classify threat sources. Which of the following is an example of an environmental threat source rather than a human threat source?

A.A flood that damages the regional data center hosting the application.
B.A software bug in a third-party library used by the application.
C.A disgruntled administrator with privileged access to the application database.
D.An organized criminal group targeting the application for ransomware.
AnswerA

Floods, fires, earthquakes, and similar natural events are environmental threat sources because they originate from physical surroundings rather than from people or technology. Classifying them correctly matters because environmental risks are typically addressed with geographic redundancy, backup sites, and facility controls, not with access management or patching. This distinction drives which controls a risk treatment plan selects.

Why this answer

Threat sources are grouped into human, technical, and environmental categories. A flood is a classic environmental source because it stems from natural conditions rather than from a person or a code defect. Correct classification guides the risk response: environmental threats call for geographic redundancy, resilient facilities, and continuity planning, while human and technical sources call for access controls, monitoring, and remediation of flaws.

Exam trap

The trap here is confusing a technical flaw such as a vulnerable library with an environmental threat source, when each category drives a different set of controls.

67
MCQhard

An organization uses User Behavior Analytics (UBA) to detect insider threats. Which of the following activities would most likely trigger an alert for a compromised account?

A.User receives a large number of emails
B.User logs in from a recognized corporate device
C.User attempts to access a database at 2:00 AM, which is outside their normal pattern
D.User accesses the same files as usual during business hours
AnswerC

UBA baselines each user's normal behaviour, so a 2:00 AM database access falling outside that learned pattern deviates from the established profile. This temporal anomaly is exactly the behavioural signal UBA is designed to flag for a potentially compromised account.

Why this answer

User Behavior Analytics (UBA) establishes a baseline of normal user activity, including typical login times, locations, and access patterns. An attempt to access a database at 2:00 AM, which falls outside the user's established temporal baseline, represents a significant deviation that UBA algorithms flag as anomalous. This behavior is a classic indicator of a compromised account, as attackers often operate during off-hours to avoid detection.

Exam trap

The trap here is that candidates may confuse 'anomalous behavior' with 'malicious behavior,' but UBA specifically flags deviations from a baseline, and off-hours access is a textbook anomaly for a compromised account, whereas the other options represent normal or expected activities.

How to eliminate wrong answers

Option A is wrong because receiving a large number of emails is a common occurrence and does not inherently indicate compromise; UBA focuses on deviations in access and authentication patterns, not email volume. Option B is wrong because logging in from a recognized corporate device is expected behavior and aligns with the user's baseline, thus it would not trigger an alert for a compromised account. Option D is wrong because accessing the same files as usual during business hours is consistent with the user's normal pattern and would be considered low-risk, not indicative of compromise.

68
MCQhard

A financial services firm operates a Security Operations Center that ingests NetFlow records, firewall logs, and endpoint telemetry into a SIEM. An analyst wants to reduce alert fatigue while still surfacing high-fidelity detections. Which approach best supports this goal?

A.Tune correlation rules with asset context and threat intelligence, and implement risk-based alert scoring to prioritize detections
B.Increase the severity rating of every rule so that analysts prioritize all alerts equally
C.Route all alerts to a shared mailbox and require analysts to review them only during weekly meetings
D.Disable all correlation rules that generate more than ten alerts per day and rely solely on raw log review
AnswerA

Combining asset criticality, threat intelligence, and risk-based scoring lets the SIEM rank alerts by actual business risk rather than raw event volume. Rules can be tuned to suppress known-good activity, while enrichment highlights activity tied to critical systems or active threat campaigns. This preserves detection coverage and directs analyst attention to the alerts most likely to represent real incidents, directly reducing fatigue without weakening monitoring.

Why this answer

Alert fatigue is reduced by improving the quality and context of detections, not by removing or delaying them. Enriching correlation rules with asset criticality and threat intelligence, then scoring alerts by risk, lets analysts focus on events that matter to the business. This maintains coverage while cutting noise, which is the core objective of a mature monitoring program.

Exam trap

The trap here is assuming that fewer alerts always means better monitoring, when the real goal is higher-fidelity alerts prioritized by risk.

69
MCQmedium

A financial services firm wants to reduce the risk of unauthorized access to its customer database. The security manager proposes implementing role-based access controls, encrypting data at rest, and enabling database activity monitoring. After these controls are in place, the residual risk is still considered high by the CISO. Which risk response strategy is the firm currently applying, and what should be done next?

A.Risk avoidance; the firm should discontinue the customer database entirely.
B.Risk transference; the firm should purchase cyber insurance to cover all potential losses.
C.Risk acceptance; the firm should document the residual risk and take no further action.
D.Risk mitigation; the firm should consider additional controls or risk transfer for the remaining risk.
AnswerD

The firm is applying mitigation by adding access controls, encryption, and monitoring. However, residual risk remains high, so they should evaluate further mitigation or transfer options such as cyber insurance. Mitigation reduces likelihood or impact, but does not eliminate risk entirely; therefore, continued treatment is appropriate.

Why this answer

The firm is actively reducing risk through technical controls, which is risk mitigation. Since residual risk remains high, they should consider additional mitigation or risk transfer. Mitigation lowers likelihood or impact but does not eliminate risk, so ongoing evaluation is necessary.

Avoidance would mean stopping the activity, acceptance would mean no further action, and transference would involve insurance or outsourcing—none of which match the described controls.

Exam trap

The trap here is confusing risk mitigation with risk acceptance because controls are already in place, but residual risk being high means mitigation is ongoing, not accepted.

70
MCQhard

During a vulnerability scan, a tool reports a critical vulnerability on a web server. The system owner claims it is a false positive because the server is not accessible from the internet. However, the server is accessible from the internal network. What is the best course of action?

A.Accept the risk and close the finding
B.Ignore the finding as the vulnerability scanner is known for false positives
C.Remove the server from the network to eliminate the risk
D.Verify the vulnerability manually and if confirmed, remediate according to internal risk
AnswerD

Internal reachability still constitutes real exposure, so the finding cannot be dismissed as a false positive. Manually confirming the vulnerability and then remediating it according to internal risk tolerances satisfies the stem's constraint that the server, while not internet-facing, remains accessible to internal actors and lateral movement.

Why this answer

A vulnerability that is exploitable from the internal network still poses a significant risk, as internal threats (e.g., compromised endpoints, malicious insiders) can leverage it. The system owner’s claim that the server is not internet-facing does not negate the need for verification and remediation; internal attack surfaces must be managed according to the organization’s risk appetite. Manual verification ensures the scanner’s report is accurate, and if confirmed, remediation should follow internal risk-based prioritization.

Exam trap

The trap here is that candidates assume a server not accessible from the internet is automatically low-risk, ignoring the reality that internal network threats are a primary attack vector in many breaches, and that risk must be evaluated based on the asset’s exposure and criticality within the internal environment.

How to eliminate wrong answers

Option A is wrong because accepting the risk without verification ignores the fact that internal network access can lead to exploitation, and risk acceptance requires formal approval and justification, not a simple dismissal. Option B is wrong because dismissing a finding solely because the scanner is known for false positives is negligent; each finding must be manually verified, as scanners can produce both false positives and false negatives, and internal threats are real. Option C is wrong because removing the server from the network is an extreme, unnecessary measure that disrupts business operations; the correct approach is to verify and remediate the vulnerability, not isolate the asset without analysis.

71
MCQmedium

A security analyst is reviewing logs and notices multiple failed login attempts from a single IP address against an administrative account. The SIEM has not generated an alert. Which configuration change would best detect this scenario?

A.Enable signature-based detection on the IDS
B.Implement a host-based IDS on the server
C.Create a SIEM correlation rule to alert on multiple failed logins from the same source
D.Increase log retention to 1 year
AnswerC

A correlation rule aggregates multiple failed authentication events sharing the same source IP within a defined window, generating an alert that the SIEM's default logging alone does not produce. This directly addresses the brute-force pattern against the administrative account that currently goes undetected.

Why this answer

A SIEM correlation rule can specifically detect multiple failed login attempts from the same source IP address by aggregating and analyzing log events in real time. Unlike signature-based or host-based IDS solutions, a SIEM correlation rule can be tuned to match this exact behavioral pattern, triggering an alert when the configured threshold (e.g., 5 failures within 10 minutes) is exceeded. This directly addresses the gap where the SIEM failed to generate an alert due to the absence of such a rule.

Exam trap

The trap here is that candidates often confuse the roles of IDS/IPS and SIEM, mistakenly thinking signature-based or host-based IDS can natively correlate login failures from a single source, when in fact SIEM correlation rules are specifically designed for this multi-event behavioral detection.

How to eliminate wrong answers

Option A is wrong because signature-based detection on an IDS relies on known attack patterns (e.g., SQL injection signatures) and cannot detect behavioral anomalies like multiple failed logins from a single IP unless a specific signature is written for that pattern, which is inefficient and not the standard approach. Option B is wrong because a host-based IDS (HIDS) monitors local system calls and file integrity on the server, but it does not natively correlate login attempts across multiple log sources or aggregate events from a single source IP; it would only see individual login failures without context. Option D is wrong because increasing log retention to 1 year does not enable detection of ongoing attacks; it only preserves historical data for forensic analysis after an incident has occurred, failing to provide real-time alerting.

72
Multi-Selectmedium

A security analyst is configuring a SIEM to detect potential data exfiltration. Which TWO log sources are most critical for detecting large outbound data transfers?

Select 2 answers
A.Network flow logs (e.g., NetFlow)
B.DNS logs
C.Proxy logs
D.System event logs
E.Application error logs
AnswersA, C

Network flow logs record byte and packet counts per connection, exposing volumetric anomalies such as unusually large outbound transfers that endpoint or application logs would miss. This directly satisfies the SIEM's requirement to detect data exfiltration by revealing the volume and destination of traffic leaving the network, independent of payload content.

Why this answer

Network flow logs (Option A) are critical because NetFlow/IPFIX records capture byte and packet counts per flow, letting the SIEM baseline normal egress volumes and alert on anomalously large outbound transfers to external IPs. Proxy logs (Option C) are equally critical because they record HTTP/HTTPS requests with URLs, destination hosts, and often response/request sizes, exposing web-based exfiltration such as large uploads to cloud storage or file-sharing sites. Together these two sources give both volumetric (flow) and content-context (proxy) visibility into outbound data movement.

DNS logs (B) mainly reveal tunneling or beaconing via query patterns and payload sizes, not bulk data transfer volumes. System event logs (D) and application error logs (E) are host-local and generally lack the outbound network volume and destination detail needed to detect large data exfiltration.

Exam trap

A common pitfall is to think that DNS logs are sufficient for detecting exfiltration via DNS tunneling, but the question specifically asks for detecting 'large outbound data transfers,' which require volume-based analysis from network flow logs or proxy logs, not just query patterns.

73
MCQeasy

An organization's security team is reviewing the results of a recent risk assessment. Management decides to accept a particular risk because the cost of the control exceeds the potential loss, and the risk falls within the stated risk appetite. Which term best describes this decision?

A.Risk mitigation
B.Risk acceptance
C.Risk transference
D.Risk avoidance
AnswerB

Risk acceptance is the deliberate decision to retain a risk because the cost of mitigation outweighs the benefit and the exposure is within the organization's risk tolerance. Documenting the rationale, the approving authority, and a review date keeps the decision auditable and ensures it is revisited if conditions change.

Why this answer

When management knowingly retains an exposure because controls cost more than the expected loss and the risk fits within tolerance, the decision is risk acceptance. It must be formally documented with the approving authority and a scheduled review so that changes in threat, cost, or business context trigger reconsideration.

Exam trap

The trap here is confusing acceptance with mitigation, even though no control was implemented and the organization consciously chose to retain the exposure.

74
MCQeasy

Which type of IDS monitors network traffic at a specific network segment and analyzes packets for malicious patterns?

A.NIDS
B.HIDS
C.UBA
D.SIEM
AnswerA

A Network IDS (NIDS) passively inspects packets traversing a network segment, matching them against signatures to identify malicious patterns. This placement and packet-analysis capability is exactly what the stem describes, distinguishing it from host-based monitoring.

Why this answer

A Network Intrusion Detection System (NIDS) is specifically designed to monitor traffic on a network segment, capturing packets in real time and analyzing them for known attack signatures or anomalous patterns. Unlike host-based systems, NIDS operates at the network layer, inspecting headers and payloads to detect malicious activity such as port scans, DoS attacks, or exploit attempts.

Exam trap

In the SSCP exam, the distinction between network-based and host-based monitoring is important, and the trap here is that candidates confuse HIDS with NIDS because both involve 'intrusion detection,' but HIDS operates on the host while NIDS operates on the network segment.

How to eliminate wrong answers

Option B (HIDS) is wrong because a Host-based Intrusion Detection System monitors activities on a single host (e.g., system logs, file integrity, process behavior), not network traffic at a segment level. Option C (UBA) is wrong because User Behavior Analytics focuses on identifying deviations in user activity patterns, often using machine learning, rather than analyzing raw network packets for malicious patterns. Option D (SIEM) is wrong because a Security Information and Event Management system aggregates and correlates logs from multiple sources, but does not directly capture or analyze network packets at a segment level.

75
MCQmedium

An organization wants to detect insider threats by identifying abnormal user behavior. Which technology is best suited for this purpose?

A.User Behavior Analytics (UBA)
B.Network-based IDS
C.Vulnerability scanner
D.Signature-based antivirus
AnswerA

UBA baselines each user's normal activity, then flags statistically significant deviations such as unusual access times, volumes or data transfers. This satisfies the requirement to identify abnormal user behaviour indicative of insider threat, which signature-based tools cannot detect.

Why this answer

User Behavior Analytics (UBA) is specifically designed to detect insider threats by establishing a baseline of normal user activity and then identifying anomalous deviations, such as unusual login times, abnormal data access patterns, or atypical file transfers. Unlike other security tools that rely on known signatures or network traffic patterns, UBA applies machine learning and statistical modeling to user-centric data (e.g., authentication logs, file system events, and endpoint activity) to uncover subtle, non-signature-based indicators of malicious insider behavior.

Exam trap

A common mistake is to choose Network-based IDS, but insider threats often involve legitimate credentials and non-malicious traffic, so a solution focused on user behavior (UBA) is required.

How to eliminate wrong answers

Option B is wrong because a Network-based IDS (Intrusion Detection System) monitors network traffic for known attack signatures or protocol anomalies, but it lacks the user-context and behavioral baseline needed to detect insider threats that do not generate malicious network packets (e.g., a user exfiltrating data via legitimate cloud storage). Option C is wrong because a vulnerability scanner identifies known software weaknesses (e.g., missing patches, misconfigurations) by comparing system states against a database of CVEs; it does not analyze user behavior or detect ongoing anomalous actions. Option D is wrong because signature-based antivirus relies on static file signatures and heuristics to detect known malware; it cannot identify abnormal user behavior such as a legitimate user accessing files outside their normal pattern or performing unauthorized privilege escalation.

Page 1 of 2 · 91 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Risk Identification, Monitoring, and Analysis questions.