Courseiva

SSCP · domain

Security Operations and Administration

Security Operations and Administration covers the day-to-day controls that keep systems trustworthy: asset inventory, configuration and change management, patch management, security awareness, physical/environmental controls, and incident response support. Questions are scenario-based, asking you to pick the best administrative or operational action, recognize process gaps, and apply risk-based prioritization rather than recite definitions.

93 questions25 easy41 medium27 hard

Focused practice

Practice Security Operations and Administration questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security Operations and Administration

Be able to select the best operational control for a scenario and justify it using risk: severity, active exploitation, and asset criticality. The single most important thing is prioritizing remediation by real business impact, not raw CVSS score alone.

Using a hardened baseline and configuration monitoring to detect drift, as with SIEM alerts on changed server settings.

Prioritizing patching by combining CVSS severity, active exploitation (KEV), and asset criticality/business impact.

Identifying patch management audit gaps such as no inventory, no testing, no rollback, or no verification of deployment.

Applying administrative controls: least privilege, separation of duties, security awareness training, and formal change management.

Watch out for

Common Security Operations and Administration exam traps

  • ▸Treating CVSS score alone as the priority; a 9.8 on a low-criticality, non-exploited host may rank below an exploited medium-severity issue on a critical system.
  • ▸Confusing configuration management with patch management: baselines and drift detection are not the same as deploying missing software updates.
  • ▸Assuming a patch is complete once deployed; verification, testing, and rollback planning are required to close the process gap.

Question index

All Security Operations and Administration questions (93)

Click any question to see the full explanation, or start a practice session above.

1

A security administrator is configuring a new web server and wants to ensure that the server's operating system and applications are hardened according to organizational standards. Which of the following should the administrator apply to enforce the desired security settings?

Medium
2

An organization's backup policy states: 'Maintain three copies of data on two different media types, with one copy stored offsite.' This is known as:

Medium
3

Which TWO of the following are examples of physical security controls? (Select TWO)

Easy
4

A security administrator is tasked with implementing a formal process for managing user access rights. The organization requires that access be granted based on job roles and that users receive only the permissions necessary to perform their duties. Which of the following should the administrator implement?

Hard
5

A company has a backup policy that performs a full backup every Sunday and incremental backups on other days. On Wednesday, a server fails. How many backup sets are needed to restore the server to its state on Tuesday night?

Hard
6

A security administrator is reviewing the organization's awareness program after a recent phishing campaign. Several employees clicked the link, and one entered credentials on the fake page. The administrator wants to reduce the likelihood of credential theft in future campaigns. Which control should the administrator implement to best address this risk?

Medium
7

Which backup type copies all data that has changed since the last full backup, regardless of subsequent backups?

Easy
8

A security administrator must verify that a third-party service provider meets the organization's security requirements before signing a contract. The provider will process regulated customer data. Which action provides the most reliable assurance?

Hard
9

An employee is leaving the company. As part of the offboarding process, which action should be taken regarding the hardware assigned to the employee?

Medium
10

An organization wants to ensure that sensitive data on laptops is protected in case of loss or theft. Which control is MOST effective?

Medium
11

A change request to update a critical database server has been approved by the Change Advisory Board (CAB). During testing, a major compatibility issue is discovered. What is the best course of action?

Hard
12

A vulnerability scan identifies a critical vulnerability on a web server with a CVSS score of 9.8. The server hosts a public-facing application. However, the patch would require a reboot that would cause downtime during business hours. What should the security administrator do FIRST?

Hard
13

A security administrator at a financial services firm is reviewing the organization's data retention practices. The legal team has mandated that certain transaction records be kept for exactly seven years and then destroyed. The administrator must ensure records are deleted automatically after seven years. Which of the following should be implemented to enforce this requirement?

Medium
14

During a security audit, it is found that several employees have written their passwords on sticky notes attached to their monitors. Which policy is being violated?

Medium
15

A company wants to ensure that employees understand the proper use of corporate email and internet. Which policy should they implement?

Easy
16

What is the primary purpose of a baseline configuration in configuration management?

Easy
17

A company uses a backup strategy that backs up all data every Sunday and backs up only data that has changed since the last full backup on other days. This is an example of which backup type?

Medium
18

A security administrator is implementing a defense-in-depth strategy for a new data center. Which of the following BEST describes the role of security awareness training within this strategy?

Easy
19

A security administrator is selecting security metrics for the organization. Which TWO metrics are most useful for measuring the effectiveness of patching? (Select TWO)

Medium
20

Which of the following is the correct order of steps in the change management process?

Easy
21

A security administrator is reviewing the organization's backup strategy for a database server that must meet a recovery point objective (RPO) of 15 minutes. The server currently uses a full backup every Sunday and differential backups every night. The administrator finds that the current strategy cannot meet the RPO. Which backup method should the administrator implement to meet the RPO while minimizing backup storage consumption?

Medium
22

During a post-implementation review of a change, it is discovered that the change introduced a configuration deviation from the baseline. The deviation was not detected during testing. What is the BEST way to prevent this in the future?

Hard
23

A security administrator is implementing a new file integrity monitoring (FIM) solution on critical servers. The administrator needs to ensure that the solution can detect unauthorized changes to system binaries and configuration files. Which of the following should the administrator configure to establish a trusted baseline for the FIM solution?

Hard
24

A company is implementing a new access control system for its data center. Which physical security control is best for preventing tailgating?

Medium
25

A security administrator at a software company is reviewing the organization's security assessment strategy. The administrator must select an assessment method that evaluates the effectiveness of implemented controls through direct observation and testing, rather than relying on interviews or documentation review alone. Which assessment method should the administrator choose?

Hard
26

A security administrator is reviewing log files and notices that a user logged in at 3:00 AM from an IP address in a foreign country. The user's manager confirms the user is not authorized for remote access. Which type of policy has likely been violated?

Medium
27

A security metric tracking the percentage of systems with critical patches applied within 48 hours is an example of which type of metric?

Medium
28

An organization's security policy requires that all portable media containing sensitive data be encrypted. Which type of control does this requirement represent?

Medium
29

Which physical security control is designed to prevent tailgating by allowing only one person to enter at a time?

Easy
30

A security administrator at a healthcare company must ensure that audit logs from a critical patient-record system are retained for seven years and cannot be altered even by system administrators. Which solution BEST meets these requirements?

Medium
31

An organization uses a mantrap at its main entrance. An employee badges in, enters the first door, but then the second door fails to open. What should the employee do?

Hard
32

Which TWO of the following are key components of a configuration management database (CMDB)? (Select TWO)

Medium
33

A security administrator is implementing a policy that requires all employees to use a password manager and enable multi-factor authentication. This policy is BEST described as a:

Easy
34

A security administrator is designing physical security for a high-security area. Which TWO controls are most effective for preventing unauthorized entry? (Select TWO)

Easy
35

A company is implementing a change management process. Which THREE elements are essential for every change request? (Select THREE)

Medium
36

A security administrator is implementing a new access control system. The organization wants to ensure that users are granted only the permissions necessary to perform their job functions and nothing more. Which principle is being applied?

Easy
37

A security awareness training program is being developed. Which topic is most important to include to reduce the risk of credential theft?

Easy
38

An organization is implementing a software inventory management process. Which TWO of the following should be tracked for each software asset?

Medium
39

A security administrator is implementing physical security for a data center. Which THREE of the following controls should be included to provide layered security?

Hard
40

A healthcare organization's security team is reviewing a third-party cloud provider that will store electronic protected health information. The provider's SOC 2 Type II report is two years old, and the provider has since migrated to a new data center. Which action should the security administrator take FIRST to determine whether the provider still meets the organization's security requirements?

Medium
41

An organization wants to ensure that servers are configured securely before deployment. They plan to use a hardened operating system image and regularly scan for deviations using SCAP. Which concept does this represent?

Hard
42

Which THREE of the following are examples of security awareness training topics?

Easy
43

An organization wants to ensure that all new servers are deployed with a hardened baseline configuration. Which of the following is the most effective control to enforce this?

Hard
44

A company is implementing a new patch management process. After scanning for missing patches, the team must prioritize which patches to apply first. Which combination of factors is most critical for prioritization?

Hard
45

A security administrator needs to ensure that all servers are configured with a hardened baseline. Which tool is best suited to detect deviations from the baseline configuration?

Medium
46

A security administrator is reviewing the organization's incident response plan. The plan must include procedures for handling security incidents. Which of the following are appropriate steps to include in the incident response process? (Choose two.)

Medium
47

Which of the following backup methods copies all data that has changed since the last full backup, regardless of any intermediate backups?

Easy
48

A security administrator is drafting a data handling standard for a retail company that processes payment cards. The standard must state how long transaction records may be retained and how they must be destroyed. Which source should PRIMARILY drive these retention and destruction requirements?

Hard
49

A company's backup strategy uses a full backup on Sundays and differential backups on other days. On Thursday, the storage system fails. How many backups are required to restore the data?

Hard
50

A security administrator is implementing a data loss prevention strategy for a company that handles credit card data. The administrator must ensure the organization meets PCI DSS requirements for protecting stored cardholder data. Which TWO practices should the administrator implement? (Choose two.)

Medium
51

A security administrator is reviewing the organization's account management procedures. The administrator discovers that user accounts for terminated employees remain active for up to 30 days after departure. Which account management control should the administrator implement to address this risk?

Easy
52

A financial services firm is implementing role-based access control for its trading platform. An auditor finds that several traders can approve their own trades in addition to executing them. Which principle is being violated, and which control should the security administrator implement to remediate the finding?

Hard
53

A critical vulnerability with a CVSS score of 9.8 is discovered in a web server that cannot be patched due to vendor dependency. What is the best compensating control?

Hard
54

Which of the following is a key principle of the 3-2-1 backup rule?

Easy
55

A security administrator is reviewing an incident response plan and finds that the team has no agreed way to classify how severe a detected event is before deciding whether to escalate. Which artifact should be created to standardize this decision?

Medium
56

After a patch is deployed to a critical server, the system becomes unstable. The change management plan includes a rollback procedure. What should be done FIRST?

Hard
57

Which of the following physical security controls is designed to prevent tailgating by requiring two doors to be interlocked?

Easy
58

A security administrator is implementing a new system that will process credit card payments. The organization must comply with PCI DSS. Which of the following controls is specifically required by PCI DSS to protect stored cardholder data?

Hard
59

An organization is enhancing its backup strategy. According to the 3-2-1 rule, which THREE characteristics must the backup strategy include? (Select THREE)

Hard
60

A security administrator needs to ensure that a terminated employee loses access to all systems immediately upon departure. Which action best accomplishes this?

Easy
61

A security administrator is reviewing the organization's account management process. The policy states that user accounts must be reviewed at least quarterly to ensure that only authorized individuals retain access. During an audit, it is discovered that several former employees still have active accounts. Which of the following is the MOST appropriate action to address this finding?

Medium
62

Which THREE of the following are critical elements of a patch management policy? (Select THREE)

Hard
63

A financial services firm must demonstrate to auditors that access to its core banking platform follows least privilege and is reviewed regularly. Which TWO practices BEST support this objective? (Choose two.)

Medium
64

A security administrator is implementing the 3-2-1 backup rule. Which THREE actions are required to comply with this rule? (Select THREE.)

Medium
65

A security administrator receives an alert from the SIEM indicating a configuration change on a critical server. The change was not part of any approved change request. What should be the first step?

Medium
66

A security metric shows that patch compliance is at 85%. The goal is 95%. Which action should be taken first?

Medium
67

A security administrator is implementing a security awareness training program. The administrator wants to measure the effectiveness of the training in reducing phishing susceptibility. Which of the following metrics would be MOST indicative of the training's success?

Medium
68

A security administrator is tasked with implementing a defense-in-depth strategy for the organization's data center. The administrator wants to ensure that physical access to servers is restricted to authorized personnel only. Which of the following controls should be implemented to achieve this?

Easy
69

Which of the following is the BEST definition of Recovery Point Objective (RPO)?

Easy
70

A patch management process is being audited. Which finding indicates a critical gap in the process?

Hard
71

Which THREE of the following are valid steps in the change management process? (Select THREE)

Hard
72

A security administrator is reviewing audit logs and discovers that a user account with administrative privileges was used to access a file server outside of normal business hours. The administrator needs to determine whether this access was authorized. Which of the following should the administrator do FIRST?

Medium
73

A security administrator is reviewing the organization's data retention policy. The policy states that customer financial records must be kept for seven years, but the IT team currently archives them indefinitely. Which action should the administrator take to align data handling with the policy while preserving records for legal discovery?

Medium
74

A security administrator needs to ensure that only authorized devices can connect to the corporate wireless network. Which of the following should be implemented to meet this requirement?

Easy
75

A security awareness training program aims to reduce successful phishing attacks. Which metric is most appropriate for measuring the effectiveness of this training?

Medium
76

A company wants to track all hardware assets including serial numbers and locations. What is the primary repository for this information?

Medium
77

A security administrator is reviewing the account lifecycle process for a large retail company. An employee in the accounting department has been promoted to a role in the same department that requires access to the payroll system, while the employee's previous duties no longer require access to the accounts payable system. Which action should the administrator take to ensure least privilege is maintained?

Easy
78

Which of the following is the PRIMARY purpose of implementing a clean desk policy?

Easy
79

A security administrator is reviewing the organization's security awareness training program. The administrator wants to measure whether employees can recognize and report phishing emails. Which metric BEST measures the effectiveness of the training?

Medium
80

Which backup type copies all data that has changed since the last full backup, regardless of any incremental backups?

Easy
81

A security administrator is implementing a mandatory vacation policy for employees in sensitive roles. The administrator needs to ensure that the policy supports the detection of fraudulent activities. Which control should be implemented alongside mandatory vacations to maximize its effectiveness?

Hard
82

A security administrator is conducting a risk assessment for a new cloud-based application. The administrator needs to identify TWO factors that are most important when determining the appropriate security controls for the application. (Choose two.)

Hard
83

During a change management process, the Change Advisory Board (CAB) has approved a change to update a critical database server. After implementation, a rollback is necessary due to unforeseen performance issues. What should the change manager do next?

Medium
84

An organization uses a SIEM to alert when a server's configuration changes from its hardened baseline. This is an example of:

Medium
85

A security administrator is implementing a solution to detect unauthorized changes to critical system files on a server. Which of the following technologies is BEST suited for this purpose?

Medium
86

A security administrator is implementing a formal data retention and destruction program for a financial services firm. The firm stores customer records, transaction logs, and email archives on a variety of media, including solid-state drives, magnetic tapes, and cloud object storage. Which TWO practices should the administrator include to ensure data is destroyed in a manner that is both effective and auditable? (Choose two.)

Hard
87

A security administrator is prioritizing patches for a vulnerability with a CVSS score of 9.8 that is being actively exploited in the wild. The affected server has a low criticality classification. What should the administrator do?

Hard
88

Which TWO of the following are valid reasons to deny a change request during the CAB approval process?

Medium
89

Which of the following is the primary purpose of a configuration management database (CMDB)?

Easy
90

A security administrator needs to dispose of hard drives that contain sensitive data. Which method provides the highest assurance that data cannot be recovered?

Medium
91

An organization needs to recover data from a backup after a ransomware attack. The backup was taken 12 hours ago, and the RPO is 4 hours. What is the impact?

Medium
92

Which TWO controls are examples of physical security controls that can help prevent unauthorized access to a data center? (Select TWO.)

Medium
93

A payroll administrator at a healthcare company resigns. On her last day, the security team must ensure she can no longer access the HR payroll application, but her mailbox must remain active for 30 days so her manager can review pending correspondence. Which access management action BEST meets these requirements?

Easy

Frequently asked questions

What does the Security Operations and Administration domain cover on the SSCP exam?
Be able to select the best operational control for a scenario and justify it using risk: severity, active exploitation, and asset criticality. The single most important thing is prioritizing remediation by real business impact, not raw CVSS score alone.
How many questions are in this domain?
This page lists all 93 Security Operations and Administration questions in the SSCP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security Operations and Administration questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-sscp ISC2-SSCP sscp security ops Practice Questions