SSCP Systems and Application Security Practice Question
During a vulnerability scan, a security team discovers that several virtual machine snapshots contain outdated software with known vulnerabilities. Which risk is most directly associated with this scenario?
⚠ Common exam trap
SSCP often tests the distinction between different VM-related risks, and candidates may confuse vulnerability reintroduction with VM sprawl or resource exhaustion, especially when snapshots are involved.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vulnerability reintroduction
Virtual machine snapshots capture the state of a VM at a point in time, including the operating system and installed software. If a snapshot contains outdated software with known vulnerabilities, restoring that snapshot or using it to create new VMs can reintroduce those vulnerabilities into the environment, even if they were previously patched. This is known as vulnerability reintroduction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Resource exhaustion
Why it's wrong here
Snapshots preserve dormant copies of vulnerable software, but they consume storage rather than CPU or memory, so resource exhaustion does not follow. It is tempting because snapshots do accumulate and can fill datastores, and that scenario would make resource exhaustion the direct risk.
- ✗
VM sprawl
Why it's wrong here
VM sprawl describes uncontrolled proliferation of unmanaged virtual machines, not the exposure created by stale snapshot contents. It tempts because both involve neglected VM artefacts, but the direct risk here is data exposure: snapshots retain vulnerable software and potentially sensitive data long after patching.
- ✓
Vulnerability reintroduction
Why this is correct
Snapshots preserve a point-in-time disk state, so reverting a virtual machine restores the outdated software and its known vulnerabilities, undoing prior patching. This directly satisfies the stem's constraint: dormant snapshot images retaining vulnerable code that re-enters production upon restore, which is precisely vulnerability reintroduction.
- ✗
VM escape
Why it's wrong here
VM escape requires a hypervisor or guest-to-host breakout vulnerability; stale software inside a snapshot is not executing, so it cannot exploit the hypervisor. It is tempting because snapshots share the host, and escape would be the concern if a running guest exploited a hypervisor flaw.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which of the following is a primary security concern when using VM snapshots in a virtualized environment?
easy- A.Snapshots can be used to bypass authentication
- ✓ B.Snapshots may contain unpatched vulnerabilities if not regularly updated
- C.Snapshots can be exported and stolen
- D.Snapshots consume excessive storage space
Why B: VM snapshots capture the complete state of a virtual machine—including its disk, memory, and configuration—at a specific point in time. If the guest OS inside the snapshot has not been patched since the snapshot was taken, restoring that snapshot reintroduces all the vulnerabilities that were present at capture time, effectively rolling back security updates. This makes unpatched vulnerabilities the primary security concern, since snapshots can silently undo remediation efforts.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.