SSCP · domain
Security Operations and Administration
Practise Systems Security Certified Practitioner SSCP Security Operations and Administration practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Security Operations and Administration questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Security Operations and Administration
Security Operations and Administration questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Security Operations and Administration exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Security Operations and Administration questions (64)
Click any question to see the full explanation, or start a practice session above.
An organization's backup policy states: 'Maintain three copies of data on two different media types, with one copy stored offsite.' This is known as:
Medium2Which TWO of the following are examples of physical security controls? (Select TWO)
Easy3A company has a backup policy that performs a full backup every Sunday and incremental backups on other days. On Wednesday, a server fails. How many backup sets are needed to restore the server to its state on Tuesday night?
Hard4Which backup type copies all data that has changed since the last full backup, regardless of subsequent backups?
Easy5A security analyst notices multiple failed login attempts on a critical server followed by a successful login from an unusual IP address. Which metric would BEST capture this event?
Medium6A security administrator is evaluating backup strategies for a critical database with a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 1 hour. Which backup approach best meets these requirements?
Medium7An employee is leaving the company. As part of the offboarding process, which action should be taken regarding the hardware assigned to the employee?
Medium8An organization wants to ensure that sensitive data on laptops is protected in case of loss or theft. Which control is MOST effective?
Medium9During a physical security audit, it is discovered that employees often prop open the mantrap door to allow easier access. What is the BEST control to address this?
Hard10A change request to update a critical database server has been approved by the Change Advisory Board (CAB). During testing, a major compatibility issue is discovered. What is the best course of action?
Hard11An organization's security policy prohibits employees from sharing passwords. What type of policy is this?
Easy12A vulnerability scan identifies a critical vulnerability on a web server with a CVSS score of 9.8. The server hosts a public-facing application. However, the patch would require a reboot that would cause downtime during business hours. What should the security administrator do FIRST?
Hard13During a security audit, it is found that several employees have written their passwords on sticky notes attached to their monitors. Which policy is being violated?
Medium14A change request to update a firewall rule has been submitted. After impact assessment, the change is approved by the Change Advisory Board (CAB). What is the NEXT step in the change management process?
Medium15A company wants to ensure that employees understand the proper use of corporate email and internet. Which policy should they implement?
Easy16What is the primary purpose of a baseline configuration in configuration management?
Easy17A company uses a backup strategy that backs up all data every Sunday and backs up only data that has changed since the last full backup on other days. This is an example of which backup type?
Medium18A security administrator is selecting security metrics for the organization. Which TWO metrics are most useful for measuring the effectiveness of patching? (Select TWO)
Medium19Which of the following is the correct order of steps in the change management process?
Easy20During a post-implementation review of a change, it is discovered that the change introduced a configuration deviation from the baseline. The deviation was not detected during testing. What is the BEST way to prevent this in the future?
Hard21A company is implementing a new access control system for its data center. Which physical security control is best for preventing tailgating?
Medium22A security metric tracking the percentage of systems with critical patches applied within 48 hours is an example of which type of metric?
Medium23An organization's security policy requires that all portable media containing sensitive data be encrypted. Which type of control does this requirement represent?
Medium24Which physical security control is designed to prevent tailgating by allowing only one person to enter at a time?
Easy25An organization uses a mantrap at its main entrance. An employee badges in, enters the first door, but then the second door fails to open. What should the employee do?
Hard26Which TWO of the following are key components of a configuration management database (CMDB)? (Select TWO)
Medium27A security administrator is designing physical security for a high-security area. Which TWO controls are most effective for preventing unauthorized entry? (Select TWO)
Easy28A company is implementing a change management process. Which THREE elements are essential for every change request? (Select THREE)
Medium29A security awareness training program is being developed. Which topic is most important to include to reduce the risk of credential theft?
Easy30An organization is implementing a software inventory management process. Which TWO of the following should be tracked for each software asset?
Medium31A security administrator is drafting an acceptable use policy (AUP). Which of the following should be included to address the use of personal devices for work purposes?
Easy32An organization wants to ensure that servers are configured securely before deployment. They plan to use a hardened operating system image and regularly scan for deviations using SCAP. Which concept does this represent?
Hard33Which THREE of the following are examples of security awareness training topics?
Easy34An organization wants to ensure that all new servers are deployed with a hardened baseline configuration. Which of the following is the most effective control to enforce this?
Hard35A company is implementing a new patch management process. After scanning for missing patches, the team must prioritize which patches to apply first. Which combination of factors is most critical for prioritization?
Hard36During a change management process, the Change Advisory Board (CAB) approves a high-risk change. What is the NEXT step according to standard change management?
Hard37A security administrator needs to ensure that all servers are configured with a hardened baseline. Which tool is best suited to detect deviations from the baseline configuration?
Medium38Which of the following backup methods copies all data that has changed since the last full backup, regardless of any intermediate backups?
Easy39A company's backup strategy uses a full backup on Sundays and differential backups on other days. On Thursday, the storage system fails. How many backups are required to restore the data?
Hard40A critical vulnerability with a CVSS score of 9.8 is discovered in a web server that cannot be patched due to vendor dependency. What is the best compensating control?
Hard41During a security awareness training session, an employee asks how to identify a phishing email. Which of the following is the most reliable indicator of a phishing attempt?
Medium42Which of the following is a key principle of the 3-2-1 backup rule?
Easy43An organization is enhancing its backup strategy. According to the 3-2-1 rule, which THREE characteristics must the backup strategy include? (Select THREE)
Hard44An organization is implementing configuration management and wants to detect unauthorized changes to server configurations. Which of the following tools would be most effective for this purpose?
Hard45During a post-implementation review of a recent change, it is found that the change introduced a security vulnerability. What TWO actions should be taken? (Select TWO)
Hard46Which THREE of the following are critical elements of a patch management policy? (Select THREE)
Hard47A security administrator is implementing the 3-2-1 backup rule. Which THREE actions are required to comply with this rule? (Select THREE.)
Medium48A security administrator receives an alert from the SIEM indicating a configuration change on a critical server. The change was not part of any approved change request. What should be the first step?
Medium49A security metric shows that patch compliance is at 85%. The goal is 95%. Which action should be taken first?
Medium50A company has a Recovery Time Objective (RTO) of 4 hours for its critical database. Which backup strategy best supports this RTO?
Medium51A patch management process is being audited. Which finding indicates a critical gap in the process?
Hard52Which THREE of the following are valid steps in the change management process? (Select THREE)
Hard53Which TWO of the following are key components of the 3-2-1 backup rule?
Medium54A security awareness training program aims to reduce successful phishing attacks. Which metric is most appropriate for measuring the effectiveness of this training?
Medium55A company wants to track all hardware assets including serial numbers and locations. What is the primary repository for this information?
Medium56Which of the following is the PRIMARY purpose of implementing a clean desk policy?
Easy57Which backup type copies all data that has changed since the last full backup, regardless of any incremental backups?
Easy58During a change management process, the Change Advisory Board (CAB) has approved a change to update a critical database server. After implementation, a rollback is necessary due to unforeseen performance issues. What should the change manager do next?
Medium59Which TWO of the following are key components of the 3-2-1 backup rule? (Select TWO)
Medium60An organization uses a SIEM to alert when a server's configuration changes from its hardened baseline. This is an example of:
Medium61A security administrator is prioritizing patches for a vulnerability with a CVSS score of 9.8 that is being actively exploited in the wild. The affected server has a low criticality classification. What should the administrator do?
Hard62During a security awareness training session, an employee reports receiving an email that appears to be from the CEO requesting an urgent wire transfer. The email has a suspicious domain and poor grammar. Which type of attack is this an example of?
Medium63A security administrator needs to dispose of hard drives that contain sensitive data. Which method provides the highest assurance that data cannot be recovered?
Medium64An organization needs to recover data from a backup after a ransomware attack. The backup was taken 12 hours ago, and the RPO is 4 hours. What is the impact?
MediumOther domains
All SSCP exam domains
Frequently asked questions
- What does the Security Operations and Administration domain cover on the SSCP exam?
- Security Operations and Administration questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 64 Security Operations and Administration questions in the SSCP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security Operations and Administration questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.