SSCP Systems and Application Security Practice Question
During a vulnerability scan, a security team discovers that several virtual machine snapshots contain outdated software with known vulnerabilities. Which risk is most directly associated with this scenario?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vulnerability reintroduction
VM snapshots, if left inactive and not patched, can reintroduce vulnerabilities when the snapshot is used to provision new VMs, as the software is outdated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Resource exhaustion
Why it's wrong here
Snapshots consume storage but do not directly cause resource exhaustion.
- ✗
VM sprawl
Why it's wrong here
VM sprawl is about unmanaged VM proliferation.
- ✓
Vulnerability reintroduction
Why this is correct
Outdated snapshots can reintroduce old vulnerabilities when deployed.
- ✗
VM escape
Why it's wrong here
VM escape attacks target the hypervisor, not outdated snapshots.
Go deeper
Related to this question
About these practice questions
One of 920 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which of the following is a primary security concern when using VM snapshots in a virtualized environment?
easy- A.Snapshots can be used to bypass authentication
- ✓ B.Snapshots may contain unpatched vulnerabilities if not regularly updated
- C.Snapshots can be exported and stolen
- D.Snapshots consume excessive storage space
Why B: VM snapshots capture the state at a point in time. If the snapshot is not updated with patches, reverting to it can reintroduce vulnerabilities that were previously fixed.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.