Courseiva

SSCP Security Operations and Administration Practice Question

During a post-implementation review of a change, it is discovered that the change introduced a configuration deviation from the baseline. The deviation was not detected during testing. What is the BEST way to prevent this in the future?

⚠ Common exam trap

SSCP often tests preventive vs. detective controls — candidates pick CAB approval (governance) or more testers (manual) instead of automated configuration scanning, which is the actual technical preventive control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement automated configuration scanning in the staging environment

Automated configuration scanning in the staging environment detects deviations from the baseline before production, catching issues that manual testing missed. This provides continuous, repeatable verification against the approved configuration baseline, which is the most reliable preventive control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the number of testers

    Why it's wrong here

    Adding testers increases coverage volume but does not compare deployed configuration against the documented baseline; the deviation slipped through because testing lacked configuration verification. More testers would suit scenarios needing broader functional coverage, not baseline compliance checks.

  • ✗

    Require CAB approval for all future changes

    Why it's wrong here

    CAB approval authorises changes before implementation; it does not verify that the deployed configuration matches the baseline afterwards. The deviation passed testing because no configuration audit occurred. Mandatory CAB review suits high-risk or high-cost changes, not routine detection of baseline drift.

  • ✓

    Implement automated configuration scanning in the staging environment

    Why this is correct

    Automated configuration scanning in staging compares deployed settings against the approved baseline before production release, catching drift that functional testing misses. This satisfies the stem's constraint that the deviation escaped testing, because scanning detects configuration variance rather than relying on test cases.

  • ✗

    Use a different change management process

    Why it's wrong here

    Replacing the change management process discards the governance that already worked; the failure was the absence of configuration verification against the baseline during testing. A different process would be justified where the existing framework itself is unfit, not where a single verification step was omitted.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.