SSCP Systems and Application Security Practice Question
During a security assessment, an analyst finds that multiple snapshots of a critical virtual machine are stored on the hypervisor host. Some snapshots are several months old. Which risk is MOST likely?
⚠ Common exam trap
SSCP often tests snapshot risks — candidates focus on exotic threats like VM escape or data theft, missing the mundane but most probable risk: reverting to an unpatched state.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reintroduction of unpatched vulnerabilities
Old VM snapshots preserve the exact state of the VM at the time of capture, including the OS and application binaries. If a VM is reverted to a months-old snapshot, any patches applied since then are lost, reintroducing known vulnerabilities that attackers can exploit. This is the most likely and direct risk of retaining stale snapshots on the hypervisor.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VM escape via snapshot file corruption
Why it's wrong here
Snapshot files are dormant data, not executable code, so corruption cannot trigger VM escape; escape requires a hypervisor vulnerability exploited from within a running guest. It is tempting because snapshots do contain sensitive memory and disk state, but that concerns data exposure, not hypervisor breakout.
- ✗
Unauthorized access to snapshot data
Why it's wrong here
Snapshot files typically inherit the VM's access controls and are not inherently exposed; the stem gives no permission or network weakness indicating unauthorised access. It is tempting because snapshots hold sensitive data, but the concrete risk from stale snapshots is storage consumption and data retention, not access control failure.
- ✓
Reintroduction of unpatched vulnerabilities
Why this is correct
Old snapshots preserve the VM's disk state from months earlier, including operating system and application versions that have since been patched. Restoring or reverting to such a snapshot reinstates those unpatched vulnerabilities, directly satisfying the stem's concern about stale, months-old snapshots retained on the hypervisor host.
- ✗
Hypervisor memory exhaustion
Why it's wrong here
Snapshots consume datastore capacity, not hypervisor RAM; memory exhaustion arises from running VM workloads, not stored snapshot files. It is tempting because snapshots are hosted on the hypervisor, yet the actual resource they deplete is storage, which is the concrete risk here.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.