Courseiva

SSCP · domain

Systems and Application Security

This domain covers securing hosts, applications, and virtual/cloud infrastructure. Questions present operational scenarios about hardening servers, managing virtualization risk, applying application controls, and splitting security duties in cloud service models. You must identify the correct tool, file, or responsibility owner rather than recite theory.

101 questions21 easy50 medium30 hard

Focused practice

Practice Systems and Application Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Systems and Application Security

Be able to match a scenario to the right control: sudoers for Linux privilege checks, AppLocker for Windows whitelisting, customer responsibility for IaaS workloads, and lifecycle governance for VM sprawl. The most important thing is correctly assigning responsibility and choosing the precise tool or file.

Windows AppLocker and Software Restriction Policies for application whitelisting on hardened servers

Linux sudoers file and sudo configuration for privilege escalation review

Cloud shared responsibility: customer duties under IaaS versus provider duties

Virtual machine sprawl controls such as lifecycle management, inventory, and decommissioning

Watch out for

Common Systems and Application Security exam traps

  • ▸Assuming the cloud provider secures guest OS patching, application data, and identity under IaaS when those remain customer duties
  • ▸Confusing AppLocker with antivirus or firewall features instead of application whitelisting enforcement
  • ▸Reviewing /etc/passwd or /etc/shadow for sudo rights instead of the sudoers configuration file

Question index

All Systems and Application Security questions (101)

Click any question to see the full explanation, or start a practice session above.

1

A cloud security team wants to continuously monitor for misconfigured cloud resources that could expose data. Which tool category is specifically designed for this purpose?

Medium
2

A company is implementing application whitelisting on all endpoints. Which of the following is a primary consideration for maintaining operational efficiency?

Easy
3

An organization uses Infrastructure as a Service (IaaS) in the public cloud. Which of the following security responsibilities is the customer responsible for?

Easy
4

A security analyst is reviewing an application that accepts a user-supplied file path and uses it to read a configuration file from disk. The analyst observes that a user can enter ../../etc/passwd and the application returns the contents of that system file. Which of the following best describes this vulnerability?

Medium
5

A security operations team suspects that an attacker has compromised a Linux web server and is maintaining persistence. The team wants to identify unauthorized scheduled tasks that survive reboots. Which set of locations should the team review FIRST?

Hard
6

A security analyst is reviewing a web application that stores user session identifiers in cookies. The analyst wants to recommend cookie attributes that reduce the risk of session hijacking through cross-site scripting (XSS) and cross-site request forgery (CSRF). Which TWO of the following cookie attributes should the analyst recommend? (Choose two.)

Medium
7

A system administrator is applying CIS Benchmarks to a Windows server. Which TWO hardening measures are typically recommended by CIS? (Select TWO.)

Easy
8

An organization using PaaS (Platform as a Service) for application hosting wants to ensure the application code is secure. Which of the following is the customer's responsibility under the shared responsibility model?

Hard
9

An organization is migrating a legacy application to a PaaS cloud environment. According to the shared responsibility model, which security control is the organization still responsible for?

Hard
10

A financial services firm is migrating a customer-facing web application to a containerized platform. The security team wants to reduce the risk of a compromised container accessing the host kernel or other containers. Which of the following is the MOST effective control to limit the impact of a container breakout?

Hard
11

A cloud security team is using Cloud Security Posture Management (CSPM) to identify misconfigurations. Which of the following scenarios is MOST likely to be detected by CSPM?

Hard
12

A security administrator is configuring a mobile device management (MDM) policy for company-owned smartphones. The organization wants to ensure that if a device is lost or stolen, corporate data can be removed without affecting the user's personal data. Which of the following MDM capabilities should be enabled?

Medium
13

A healthcare organization is developing a mobile application that stores patient data locally on the device. The security team must ensure that if a device is lost or stolen, the data cannot be accessed without the user's authentication. Which of the following controls should be implemented to meet this requirement?

Easy
14

A healthcare SaaS provider runs its application stack on Docker containers orchestrated by Kubernetes in a public cloud. A security administrator must reduce the risk of a compromised container accessing the underlying node's kernel. Which control BEST addresses this requirement?

Medium
15

Which Windows feature provides mandatory integrity controls and helps prevent unauthorized changes to system settings by requiring administrator approval?

Easy
16

A company uses virtualization extensively. The security team discovers that developers have created many unmanaged virtual machines that are not tracked in the configuration management database (CMDB). Which risk is MOST directly associated with this situation?

Medium
17

A healthcare organization stores protected health information on a database server. Auditors require that the data remain unreadable if the physical disk is stolen, and that encryption keys never reside on the same disk as the ciphertext. Which approach BEST satisfies these requirements?

Easy
18

A system administrator is configuring a Linux server to ensure that only authorized users can execute commands with superuser privileges. Which file should be edited to control sudo access?

Medium
19

A system administrator is hardening a Linux server. After installing the OS, which of the following steps should be taken to ensure that only authorized users can execute commands with elevated privileges?

Medium
20

A Linux server is being hardened. The security team wants to enforce mandatory access control policies that confine processes to limited access to files and resources. Which technology should be implemented?

Medium
21

A company deploys a web application and wants to protect against SQL injection and XSS attacks. Which security control is specifically designed to inspect HTTP traffic and block such attacks?

Medium
22

A security administrator at a hospital is configuring a server that processes electronic health records. The server runs a Linux-based operating system, and the administrator needs to select a mandatory access control (MAC) framework that can enforce granular, policy-based restrictions on how processes interact with files, network ports, and other system resources. Which of the following should the administrator choose?

Medium
23

A security administrator is building a Security Information and Event Management (SIEM) correlation rule to detect a specific attack pattern on a Linux web server. The rule must identify attempts where an attacker sends a single malicious HTTP request that causes the server to execute an arbitrary operating system command. Which of the following event sources would provide the most reliable and immediate evidence for this rule?

Medium
24

A Linux administrator needs to configure access controls so that a specific user can run certain commands with root privileges without entering a password. Which configuration file should be modified?

Medium
25

An organization is experiencing VM sprawl, with many unmanaged virtual machines running in the environment. Which of the following is the most significant security risk associated with VM sprawl?

Medium
26

A small accounting firm wants to ensure that if a laptop is lost, the data on its full-disk-encrypted drive cannot be recovered by an attacker who removes the drive and mounts it elsewhere. Which additional control is MOST important to meet this goal?

Easy
27

A security architect is reviewing cloud security for a SaaS application used by the company. According to the shared responsibility model, which security controls are PRIMARILY the customer's responsibility?

Hard
28

A financial services company runs a customer-facing mobile banking API on Linux containers. A penetration test reveals that when the API receives an oversized JSON payload, the application returns a stack trace containing internal file paths and database connection strings. The developer wants to prevent this information disclosure without changing the API's core business logic. Which control should the security practitioner recommend FIRST?

Medium
29

A company is migrating to the cloud and wants to understand the shared responsibility model. For an IaaS deployment, which THREE are customer responsibilities? (Select THREE.)

Medium
30

An organization using cloud IAM wants to grant a compute instance permissions to access a cloud storage bucket without storing long-term credentials on the instance. Which IAM feature should be used?

Hard
31

To prevent VM escape attacks in a virtualized environment, which of the following is the most critical security measure?

Medium
32

A security engineer is hardening a Windows server. Which TWO actions should be taken to reduce the attack surface? (Select TWO.)

Medium
33

During a security assessment, it is discovered that a Linux server has unnecessary services running, including Telnet and FTP. The server is also missing critical security patches. Which of the following is the MOST effective approach to harden this server according to industry best practices?

Medium
34

In Linux, which command is used to change file permissions to restrict access so that only the owner can read and write, and the group and others have no access?

Easy
35

Which of the following OWASP Top 10 vulnerabilities involves an attacker sending malicious data to an interpreter as part of a command or query?

Easy
36

During a vulnerability scan, a security team discovers that several virtual machine snapshots contain outdated software with known vulnerabilities. Which risk is most directly associated with this scenario?

Hard
37

An organization is hardening a Linux server. Which TWO of the following are effective steps to reduce the attack surface?

Medium
38

A cloud security team is implementing a Cloud Security Posture Management (CSPM) tool. What is the primary purpose of a CSPM solution?

Medium
39

A company is migrating to a PaaS cloud environment. According to the shared responsibility model, which THREE security responsibilities remain with the customer? (Select THREE.)

Hard
40

A DevOps team deploys containerized microservices and wants to reduce the impact of a compromised container. They need a control that limits which system calls each container process can make, without changing the application image. Which Linux kernel feature should they enable?

Hard
41

A Linux administrator is hardening a server. Which TWO commands are used to manage file permissions? (Select TWO.)

Easy
42

A security analyst investigates a suspicious process on a Linux web server that is making outbound connections to an unknown IP address. The analyst wants to confirm which executable file is running and whether it has been modified since installation. Which combination of actions best accomplishes this?

Hard
43

A security analyst is reviewing Linux server logs after a suspected breach. Which auditing tool should be used to examine detailed records of system calls and file access events?

Medium
44

A security operations center (SOC) is investigating a suspected supply chain attack where a trusted software update was modified to include a backdoor. The update was delivered via the vendor's official update server over HTTPS. Which of the following controls, if implemented by the organization, would have BEST prevented the installation of the backdoored update?

Hard
45

A company uses Infrastructure as a Service (IaaS) for its production workloads. According to the shared responsibility model, which of the following security tasks is the customer responsible for?

Hard
46

An organization uses VMware ESXi in a production environment. Which of the following is the most effective mitigation against VM escape attacks?

Hard
47

A mobile device management (MDM) administrator at a healthcare company needs to ensure that a physician's personally owned smartphone can access patient records through the corporate email application, but the administrator must be able to remotely erase only the corporate email data and its encryption keys if the device is lost, without deleting the physician's personal photos and apps. Which MDM capability should the administrator configure?

Medium
48

A security engineer is hardening a Linux server. Which TWO actions are recommended to reduce the attack surface? (Select TWO.)

Medium
49

An organization is hardening a new Windows server for production use. Which of the following is the most effective method to ensure that only approved applications can run?

Easy
50

A financial services firm must prove that an e-commerce application's source code has not been tampered with between the build pipeline and production deployment. The pipeline already stores build artifacts in an internal repository. Which control BEST provides this assurance?

Hard
51

A financial services firm runs a Java-based customer portal on Apache Tomcat. During a code review, the security team discovers that the application deserializes session objects received from an untrusted partner API without validating their contents. An attacker could craft a malicious serialized object that executes arbitrary code on the server when deserialized. Which of the following controls BEST mitigates this risk?

Medium
52

A security analyst is hardening a new Windows server. Which configuration would MOST effectively reduce the attack surface by limiting the software that can execute?

Easy
53

An organization is hardening its Windows servers. Which built-in Windows feature can be used to enforce application whitelisting, ensuring only approved executables run?

Easy
54

A company is deploying a new web application that will be accessible to the public. The security team wants to ensure that session identifiers cannot be predicted or reused by an attacker who captures one over an unencrypted network segment. Which control should be implemented to BEST address this risk?

Medium
55

Which Windows feature allows an administrator to define security policies such as password complexity and account lockout across multiple systems in a domain?

Easy
56

A security auditor discovers that a Linux server has a user who can execute any command as root via sudo without a password. Which file should be reviewed to verify this configuration?

Medium
57

During a security assessment, you discover that a Windows server has the Telnet service running. Which of the following is the BEST action to harden the server against this finding?

Easy
58

A forensic analyst needs to review security events from multiple Windows servers. To ensure that logs are centrally collected and resistant to tampering, which of the following should be implemented?

Hard
59

During a virtualized environment security assessment, which THREE of the following are considered risks associated with virtual machine snapshots? (Select three.)

Medium
60

A security analyst is hardening a web application that stores user-uploaded images. The application currently writes uploads to a directory served directly by the web server. Which TWO controls BEST reduce the risk of a malicious upload leading to remote code execution? (Choose two.)

Medium
61

According to the shared responsibility model in cloud computing, which security responsibility belongs to the customer in a SaaS deployment?

Easy
62

A security analyst is reviewing a mobile application that stores authentication tokens in a location accessible to other applications on the same device. The development team wants to remediate this finding for both Android and iOS. Which change BEST addresses the vulnerability?

Hard
63

A security analyst is reviewing Linux audit logs with auditd. Which TWO events would be of greatest concern for a server that should not have interactive logins? (Select TWO.)

Hard
64

A security engineer is hardening a Windows workstation. Which TWO configurations reduce the attack surface by limiting execution of unauthorized code? (Select TWO.)

Medium
65

An organization is implementing system hardening. Which of the following actions are recommended by CIS Benchmarks? (Select all that apply.)

Medium
66

A cloud operations team is hardening the management plane of its Infrastructure as a Service (IaaS) environment. The team wants to reduce the risk of unauthorized administrative access to the cloud console and APIs. Which TWO of the following controls best address this objective? (Choose two.)

Hard
67

A cloud security team is deploying a new web application on an IaaS platform. According to the shared responsibility model, which of the following security tasks is the customer responsible for?

Hard
68

A company is deploying a web application in a containerized environment. The security team wants to ensure that if an attacker compromises the application, they cannot escalate privileges to the host or other containers. Which of the following container security measures should be implemented?

Medium
69

A software vendor ships a Java-based payment service to a customer's data center. The customer's security team requires that the application run with only the minimum privileges necessary and cannot be trusted to restrict itself. Which mechanism should the security team use to enforce these restrictions on the JVM?

Medium
70

A company uses multiple virtual machines on a single hypervisor. To prevent a VM from escaping its virtualized environment and compromising the hypervisor, which of the following should be implemented?

Medium
71

A healthcare provider must ensure that stored patient records remain unreadable if an attacker steals the physical disk from a database server. The server runs a mainstream Linux distribution and the requirement applies to the entire volume, not just individual files. Which control best meets this requirement?

Easy
72

A Linux system administrator needs to restrict network traffic to a server, allowing only HTTP and HTTPS from the internet. Which tool should be used to configure packet filtering rules?

Medium
73

A web application is vulnerable to SQL injection. Which security control would be MOST effective at detecting and blocking such attacks at the network perimeter?

Easy
74

A healthcare organization is deploying a containerized patient records application on Kubernetes. The security team wants to prevent a compromised container from accessing the underlying node's filesystem and from escalating privileges. Which Kubernetes control should be configured to restrict the container's capabilities and prevent privilege escalation?

Hard
75

A security administrator is deploying a new web application on a Linux server. The application must be isolated from the host and other applications, and it must only be able to read its own configuration files. The administrator decides to use a container. Which of the following should the administrator implement to meet these requirements?

Medium
76

A security administrator is configuring a Linux server to enforce mandatory access control (MAC). Which of the following tools provides MAC on Linux?

Medium
77

A cloud security architect is designing a solution to protect workloads running in a public cloud. Which THREE of the following are key security controls that should be implemented?

Medium
78

A security analyst is reviewing a web application for OWASP Top 10 vulnerabilities. Which THREE of the following are examples of injection flaws?

Hard
79

A developer is building a mobile banking application and wants to ensure that if an attacker gains physical access to a rooted or jailbroken device, the application's sensitive data stored locally cannot be easily read. The developer decides to use the secure storage provided by the mobile operating system. Which of the following BEST describes the protection offered by this secure storage?

Easy
80

A security administrator is implementing application whitelisting on a fleet of Linux servers that run a fixed set of approved binaries. The administrator wants to ensure only authorized executables can run, while still allowing legitimate administrative scripts. Which TWO of the following approaches BEST support this goal? (Choose two.)

Hard
81

A security administrator is reviewing Linux audit logs to detect unauthorized file access. Which Linux component is primarily responsible for generating these security audit logs?

Medium
82

An organization uses Linux servers and wants to implement mandatory access control (MAC) to enhance security. Which TWO technologies can be used? (Select TWO.)

Medium
83

A security administrator is reviewing how mobile devices connect to corporate email and file shares. The organization wants to protect data if a device is lost and to prevent data leakage between personal and work applications. Which TWO controls should the administrator implement? (Choose two.)

Medium
84

During a code review, a developer identifies that a web application directly concatenates user input into SQL queries without sanitization. This vulnerability is classified under which OWASP Top 10 category?

Hard
85

Which of the following tools would best help a security team detect misconfigurations in a cloud environment, such as open storage buckets or overly permissive IAM roles?

Medium
86

An administrator wants to ensure that a Linux web server only allows the www-data user to run specific commands with elevated privileges. Which configuration file should be modified?

Medium
87

A Windows system administrator needs to enforce a security policy that prevents users from installing unauthorized software. Which feature should be configured via Group Policy?

Medium
88

An organization is implementing Windows Defender Application Control (WDAC) to prevent unauthorized applications from running on company workstations. Which of the following best describes the primary security benefit of this approach?

Medium
89

A security analyst is reviewing logs from a web application and notices numerous requests with the following pattern: GET /products?category=1' OR '1'='1. The analyst suspects a SQL injection attack. Which of the following is the MOST effective control to prevent this type of attack?

Medium
90

An organization wants to prevent unauthorized applications from running on Windows workstations. Which Windows feature should be used to enforce application whitelisting?

Easy
91

During a security assessment, an analyst finds that multiple snapshots of a critical virtual machine are stored on the hypervisor host. Some snapshots are several months old. Which risk is MOST likely?

Hard
92

A small business wants to protect data stored on employee laptops. The security policy requires that if a laptop is lost or stolen, the data on its disk cannot be read by anyone without the proper authentication. Which of the following should be implemented?

Easy
93

During an application security review, a penetration tester discovers that a web application allows users to view other users' profiles by changing an ID parameter in the URL (e.g., /profile?id=123). Which OWASP Top 10 vulnerability does this represent?

Hard
94

A security analyst is reviewing OWASP Top 10 vulnerabilities in a web application. Which TWO are injection-related attacks? (Select TWO.)

Hard
95

A security engineer is reviewing the configuration of a web application that uses JSON Web Tokens (JWT) for session management. The engineer notices that the application accepts tokens signed with the 'none' algorithm. Which of the following is the most critical security risk associated with this configuration?

Hard
96

A security administrator is deploying a new web application on a Linux server and wants to prevent an attacker who compromises the web server process from reading the application's private TLS keys stored on the same host. The administrator decides to use a hardware security module (HSM) to protect the keys. Which of the following BEST describes how the HSM provides this protection?

Hard
97

An application security team is reviewing code for vulnerabilities. They find that user input is directly concatenated into an SQL query without sanitization. This is an example of which OWASP Top 10 vulnerability?

Medium
98

A company is deploying virtual machines (VMs) in a private cloud environment. To prevent VM escape attacks, which of the following is the most critical security control?

Medium
99

A security analyst is reviewing an OWASP Top 10 vulnerability report. Which vulnerability involves an attacker accessing unauthorized data by modifying URLs or API parameters?

Medium
100

A company is concerned about VM sprawl in its data center. Which of the following is the most effective mitigation strategy?

Medium
101

A security engineer is hardening a Windows server that hosts a critical database. The server currently has many unnecessary services running. Which TWO of the following actions are most effective in reducing the attack surface of this server? (Choose two.)

Hard

Frequently asked questions

What does the Systems and Application Security domain cover on the SSCP exam?
Be able to match a scenario to the right control: sudoers for Linux privilege checks, AppLocker for Windows whitelisting, customer responsibility for IaaS workloads, and lifecycle governance for VM sprawl. The most important thing is correctly assigning responsibility and choosing the precise tool or file.
How many questions are in this domain?
This page lists all 101 Systems and Application Security questions in the SSCP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Systems and Application Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-sscp ISC2-SSCP sscp systems app security Practice Questions