SSCP Security Operations and Administration Practice Question
During a security audit, it is found that several employees have written their passwords on sticky notes attached to their monitors. Which policy is being violated?
⚠ Common exam trap
SSCP often tests the confusion between Password Policy and Clean Desk Policy, but the physical exposure of passwords is a clean desk violation, not a password complexity issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Clean Desk Policy
The Clean Desk Policy is violated because it requires employees to keep their workspaces free of sensitive information, including passwords, when not in use. Writing passwords on sticky notes and attaching them to monitors leaves credentials exposed, directly contravening this policy. The Clean Desk Policy aims to reduce the risk of unauthorized access to information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Social Media Policy
Why it's wrong here
Social media policies restrict what employees publish on public platforms and how the organisation is represented online. Sticky notes on monitors involve no external posting or public disclosure channel. A social media policy would be the correct answer if the audit found sensitive details posted to a public profile or feed.
- ✓
Clean Desk Policy
Why this is correct
A Clean Desk Policy requires sensitive information, including written credentials, to be secured or removed when workspaces are unattended. Sticky notes exposing passwords on monitors directly breach that requirement, since the policy explicitly covers physical artefacts left in plain view.
- ✗
Data Handling Policy
Why it's wrong here
Data handling policies classify and govern storage, transmission and disposal of organisational data assets, not employee authentication credentials. Sticky notes expose login secrets, which fall under credential management rather than data classification. A data handling policy would apply if classified information were stored or shared inappropriately.
- ✗
Password Policy
Why it's wrong here
Password policies govern complexity, length, rotation and reuse, not where credentials are physically stored. Writing passwords on sticky notes breaches requirements about protecting authentication secrets from disclosure. A password policy would be the answer if the finding concerned weak or reused passwords rather than exposed written copies.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.