Courseiva

SSCP Security Operations and Administration Practice Question

During a security audit, it is found that several employees have written their passwords on sticky notes attached to their monitors. Which policy is being violated?

⚠ Common exam trap

SSCP often tests the confusion between Password Policy and Clean Desk Policy, but the physical exposure of passwords is a clean desk violation, not a password complexity issue.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Clean Desk Policy

The Clean Desk Policy is violated because it requires employees to keep their workspaces free of sensitive information, including passwords, when not in use. Writing passwords on sticky notes and attaching them to monitors leaves credentials exposed, directly contravening this policy. The Clean Desk Policy aims to reduce the risk of unauthorized access to information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Social Media Policy

    Why it's wrong here

    Social media policies restrict what employees publish on public platforms and how the organisation is represented online. Sticky notes on monitors involve no external posting or public disclosure channel. A social media policy would be the correct answer if the audit found sensitive details posted to a public profile or feed.

  • ✓

    Clean Desk Policy

    Why this is correct

    A Clean Desk Policy requires sensitive information, including written credentials, to be secured or removed when workspaces are unattended. Sticky notes exposing passwords on monitors directly breach that requirement, since the policy explicitly covers physical artefacts left in plain view.

  • ✗

    Data Handling Policy

    Why it's wrong here

    Data handling policies classify and govern storage, transmission and disposal of organisational data assets, not employee authentication credentials. Sticky notes expose login secrets, which fall under credential management rather than data classification. A data handling policy would apply if classified information were stored or shared inappropriately.

  • ✗

    Password Policy

    Why it's wrong here

    Password policies govern complexity, length, rotation and reuse, not where credentials are physically stored. Writing passwords on sticky notes breaches requirements about protecting authentication secrets from disclosure. A password policy would be the answer if the finding concerned weak or reused passwords rather than exposed written copies.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.