Courseiva

CCNA Sscp Security Ops Questions

75 of 93 questions · Page 1/2 · Sscp Security Ops topic · Answers revealed

1
MCQmedium

A security administrator is configuring a new web server and wants to ensure that the server's operating system and applications are hardened according to organizational standards. Which of the following should the administrator apply to enforce the desired security settings?

A.Change management process
B.Incident response plan
C.Vulnerability scan
D.Security baseline
AnswerD

A security baseline is a documented set of minimum security settings that must be applied to a system to meet organizational policy. Applying it to the new web server ensures consistent hardening, reduces attack surface, and provides a known configuration to compare against during audits. It directly addresses the need to enforce desired security settings.

Why this answer

A security baseline provides the specific, documented configuration settings that must be applied to a system to meet security standards. It is the authoritative source for hardening a new server. The other options are important security processes but do not directly enforce the desired technical settings on the server.

Exam trap

The trap here is confusing procedural controls like change management with technical configuration baselines.

2
MCQmedium

An organization's backup policy states: 'Maintain three copies of data on two different media types, with one copy stored offsite.' This is known as:

A.Incremental backup strategy
B.Grandfather-father-son rotation
C.3-2-1 rule
D.Disaster recovery plan
AnswerC

The 3-2-1 rule directly encodes the policy's three constraints: three copies of data, two distinct media types, and one copy held offsite. Its whole purpose is resilient recovery, so it satisfies the stated requirement exactly, whereas alternatives such as RAID or full backups address redundancy or scope but not the offsite and media-diversity conditions.

Why this answer

The 3-2-1 rule is a foundational data backup strategy that mandates maintaining three total copies of data, stored on two different types of media (e.g., disk and tape), with one copy located offsite to protect against site-level disasters. This directly matches the policy described, making option C correct.

Exam trap

The trap here is that candidates confuse the 3-2-1 rule with backup rotation schemes like GFS or incremental strategies, because all involve 'backup' and 'copies,' but only the 3-2-1 rule explicitly defines the count, media diversity, and offsite requirement.

How to eliminate wrong answers

Option A is wrong because an incremental backup strategy refers to a backup method that only copies data changed since the last full or incremental backup, not a rule about the number of copies, media diversity, or offsite storage. Option B is wrong because the grandfather-father-son (GFS) rotation is a tape rotation scheme that manages backup retention cycles (daily, weekly, monthly), not a specification for three copies on two media types with one offsite. Option D is wrong because a disaster recovery plan (DRP) is a comprehensive document outlining procedures for recovering IT infrastructure after a disaster, not a specific backup copy and media rule.

3
Multi-Selecteasy

Which TWO of the following are examples of physical security controls? (Select TWO)

Select 2 answers
B.CCTV
C.Intrusion detection system (IDS)
D.Biometric reader
E.Encryption
AnswersB, D

CCTV is a physical security control because it monitors and records the tangible environment, deterring and detecting intrusions at a facility. It satisfies the scenario's requirement for controls operating on physical premises rather than logical access.

Why this answer

B (CCTV) is correct because closed-circuit television cameras are a physical security control that monitors and records activity in a facility to deter and detect intrusions. D (Biometric reader) is correct because it is a physical access control device that authenticates individuals via fingerprints, iris, or facial recognition to restrict entry to a protected area. A (Firewall) is incorrect because it is a logical/network security control that filters traffic based on rules, not a physical barrier.

C (Intrusion detection system) is incorrect because an IDS is a logical monitoring control that analyzes network or host activity for malicious behavior. E (Encryption) is incorrect because it is a cryptographic/logical control that protects data confidentiality, not a physical control.

Exam trap

The trap here is that candidates confuse 'security control' with 'security technology' and fail to distinguish between physical (tangible) and logical (digital) controls, leading them to select IDS or firewall as physical controls.

4
MCQhard

A security administrator is tasked with implementing a formal process for managing user access rights. The organization requires that access be granted based on job roles and that users receive only the permissions necessary to perform their duties. Which of the following should the administrator implement?

A.Role-based access control (RBAC)
B.Discretionary access control (DAC)
C.Mandatory access control (MAC)
D.Attribute-based access control (ABAC)
AnswerA

RBAC assigns permissions to roles rather than individuals, and users are assigned to roles based on their job functions. This directly enforces least privilege because users inherit only the permissions of their role. It matches the requirement to grant access based on job roles and minimal necessary permissions.

Why this answer

Role-based access control (RBAC) is designed to assign permissions to roles and then assign users to those roles, ensuring that users have only the access required for their job functions. This satisfies the requirement for role-based provisioning and least privilege. Other models like MAC, DAC, or ABAC do not align as directly with the stated need.

Exam trap

The trap here is confusing RBAC with ABAC; while both can enforce least privilege, the scenario explicitly mentions job roles, which is the defining characteristic of RBAC.

5
MCQhard

A company has a backup policy that performs a full backup every Sunday and incremental backups on other days. On Wednesday, a server fails. How many backup sets are needed to restore the server to its state on Tuesday night?

A.One
B.Two
C.Four
D.Three
AnswerD

Restoring Wednesday's failure to Tuesday night requires the Sunday full backup plus Monday's and Tuesday's incrementals — three sets. Incrementals capture only changes since the previous backup, so each intervening day must be applied sequentially; the full alone is insufficient and Tuesday's incremental cannot reconstruct Monday's changes.

Why this answer

To restore the server to its state on Tuesday night, you need the full backup from Sunday and the incremental backups from Monday and Tuesday. Incremental backups only capture changes since the last backup (full or incremental), so you must restore them in sequence: full backup first, then Monday's incremental, then Tuesday's incremental. This requires three backup sets total, making option D correct.

Exam trap

The trap here is confusing incremental backups with differential backups; candidates often think two sets are enough (full + latest incremental) or mistakenly count the days incorrectly, leading them to choose option B or C instead of recognizing the sequential dependency of incremental chains.

How to eliminate wrong answers

Option A is wrong because a single backup set cannot restore the state after multiple days of changes; only the full backup alone would restore Sunday's state, not Tuesday's. Option B is wrong because two backup sets would only cover the full backup and one incremental, missing the changes from the other day (e.g., full + Monday would miss Tuesday's changes). Option C is wrong because four backup sets would be needed only if the policy used differential backups (which accumulate all changes since the last full backup) or if there were additional days; with incremental backups, the number of sets equals the number of days since the last full backup plus one (the full), which is three for Tuesday.

6
MCQmedium

A security administrator is reviewing the organization's awareness program after a recent phishing campaign. Several employees clicked the link, and one entered credentials on the fake page. The administrator wants to reduce the likelihood of credential theft in future campaigns. Which control should the administrator implement to best address this risk?

A.Increase the frequency of phishing simulation campaigns to once per month.
B.Implement a policy that prohibits employees from clicking links in external email messages.
C.Deploy a secure email gateway that quarantines messages containing known malicious URLs.
D.Require multi-factor authentication for all user accounts and privileged access.
AnswerD

Multi-factor authentication requires a second factor beyond the password, so stolen credentials alone are insufficient for an attacker to authenticate. If the employee had entered credentials on the fake page, MFA would have blocked the account takeover unless the attacker also compromised the second factor. This directly reduces the impact of successful phishing and is the most effective control for credential theft in this scenario.

Why this answer

Multi-factor authentication is the strongest control against credential theft because it requires a second factor that a phishing page cannot capture with the password alone. Email filtering, awareness simulations, and link-clicking policies are valuable layers, but none of them prevents an attacker from using stolen credentials to authenticate. MFA directly interrupts the attack path after credentials are compromised.

Exam trap

The trap here is choosing user awareness or email filtering as the primary fix for credential theft, when the technical control that defeats stolen passwords is multi-factor authentication.

7
MCQeasy

Which backup type copies all data that has changed since the last full backup, regardless of subsequent backups?

A.Incremental backup
B.Snapshot backup
C.Differential backup
D.Full backup
AnswerC

A differential backup captures every block changed since the last full backup, so successive differentials each grow larger until the next full backup resets the baseline. This matches the stem's requirement of copying changes since the last full backup regardless of subsequent backups.

Why this answer

A differential backup copies all data that has changed since the last full backup, regardless of any intermediate backups. This means each differential backup grows in size as it accumulates all changes made since the last full backup, making it distinct from incremental backups which only capture changes since the last backup of any type.

Exam trap

ISC2 often tests the distinction that differential backups grow over time because they accumulate all changes since the last full backup, while incremental backups are smaller but require a chain of backups for restoration.

How to eliminate wrong answers

Option A is wrong because an incremental backup copies only data that has changed since the last backup (whether full or incremental), not since the last full backup. Option B is wrong because a snapshot backup captures the state of a system at a point in time using copy-on-write technology, not by tracking changes since a full backup. Option D is wrong because a full backup copies all selected data regardless of change status, not just data that has changed since a previous backup.

8
MCQhard

A security administrator must verify that a third-party service provider meets the organization's security requirements before signing a contract. The provider will process regulated customer data. Which action provides the most reliable assurance?

A.Obtain and review an independent third-party audit report covering the provider's relevant controls.
B.Ask the provider to confirm verbally during a call that it follows industry best practices.
C.Rely on the provider's marketing materials describing its security program.
D.Accept the provider's completed security questionnaire signed by its sales director.
AnswerA

An independent audit report, such as a SOC 2 report, provides evidence that controls were examined by a qualified external party against defined criteria. Reviewing the scope, period, and exceptions gives reliable assurance for regulated data handling. It is stronger than self-attestation because the provider does not control the assessment.

Why this answer

Independent third-party audit reports give the most reliable assurance because an external auditor examines the provider's controls against recognized criteria and reports scope, period, and exceptions. Self-signed questionnaires, marketing claims, and verbal confirmations are unverified and unsuitable as primary evidence when regulated customer data is involved.

Exam trap

The trap here is treating a provider's self-reported questionnaire or verbal assurance as equivalent to independent audit evidence when regulated data is at stake.

9
MCQmedium

An employee is leaving the company. As part of the offboarding process, which action should be taken regarding the hardware assigned to the employee?

A.Keep the hardware in storage indefinitely
B.Sanitise the hard drive and then dispose or reassign
C.Recycle the hardware without any data removal
D.Reassign the hardware to a new employee without wiping
AnswerB

Sanitising overwrites or cryptographically erases residual data before the drive leaves the departing employee's control, satisfying the offboarding requirement to prevent unauthorised data recovery. Reassignment or disposal without sanitisation would expose company data, so this action directly addresses the hardware handling constraint in the stem.

Why this answer

Sanitising the hard drive before disposal or reassignment is the correct action because it ensures all sensitive company and employee data is securely removed, preventing data leakage. This aligns with data remanence best practices and regulatory requirements for media sanitisation. Reassigning or disposing without sanitisation exposes the organization to data breach risks.

Exam trap

SSCP often tests the misconception that simply deleting files or reformatting a drive is sufficient for sanitisation, when in fact secure overwrite or purge is required to prevent data remanence.

How to eliminate wrong answers

Option A is wrong because keeping hardware in storage indefinitely does not address data security and wastes assets; it also fails to sanitise the data, leaving it vulnerable if the storage is compromised. Option C is wrong because recycling hardware without data removal leaves sensitive data intact, violating data protection policies and increasing the risk of unauthorized access. Option D is wrong because reassigning hardware without wiping it allows the new employee to access the previous employee's data, which is a serious security and privacy violation.

10
MCQmedium

An organization wants to ensure that sensitive data on laptops is protected in case of loss or theft. Which control is MOST effective?

A.Full disk encryption
B.Strong password policy
C.Asset tracking software
D.Remote wiping capability
AnswerA

Full disk encryption renders the entire volume unreadable without the decryption key, so a stolen laptop's data stays confidential even if the drive is removed. This directly satisfies the loss-or-theft constraint, unlike file-level or database controls that leave unencrypted remnants exposed.

Why this answer

Full disk encryption (FDE) is the most effective control because it renders data unreadable at rest on the entire drive, including the operating system, swap files, and temporary files. Without the decryption key (e.g., a pre-boot PIN or TPM-bound key), an attacker cannot access any data even if the laptop is physically removed. This directly addresses the threat of data exposure from loss or theft, unlike controls that only limit access or track the device.

Exam trap

The trap here is that candidates often choose remote wiping (D) because it seems proactive, but they overlook the critical requirement that the device must be online and powered on to execute the wipe, whereas full disk encryption protects data even if the device is never turned on again.

How to eliminate wrong answers

Option B (Strong password policy) is wrong because it only protects against unauthorized login attempts; if the attacker bypasses the OS (e.g., by booting from a live USB or removing the hard drive), the data is fully accessible without decryption. Option C (Asset tracking software) is wrong because it only helps locate or recover the laptop after loss, but does not prevent data exposure if the device is stolen and the hard drive is removed or imaged. Option D (Remote wiping capability) is wrong because it relies on the laptop being powered on and connected to a network to receive the wipe command; if the thief immediately disconnects the device or removes the drive, the data remains intact and accessible.

11
MCQhard

A change request to update a critical database server has been approved by the Change Advisory Board (CAB). During testing, a major compatibility issue is discovered. What is the best course of action?

A.Report the issue to the CAB and request a revised change
B.Reject the change request and close it permanently
C.Implement the change but have a rollback plan ready
D.Proceed with the change and resolve the issue after implementation
AnswerA

The CAB owns change approval, so a discovered compatibility issue invalidates the approved change and must be escalated for reassessment. Proceeding without reapproval bypasses change control; reporting back and requesting a revised change preserves governance and satisfies the stem's testing constraint.

Why this answer

Reporting the issue to the CAB and requesting a revised change is the best course because the change management process requires that any significant deviation from the approved change, such as a major compatibility issue, be re-evaluated by the CAB. This ensures proper risk assessment and approval before proceeding. It maintains the integrity of the change control process and prevents unintended outages.

Exam trap

SSCP often tests the misconception that an approved change can proceed despite new critical findings, when in fact any significant issue requires re-evaluation by the CAB.

How to eliminate wrong answers

Option B is wrong because rejecting and closing the change permanently ignores the possibility of revising and resubmitting a modified change that addresses the compatibility issue; it is not a constructive step. Option C is wrong because implementing the change with a rollback plan still proceeds despite a known major compatibility issue, which could cause significant disruption and violates the principle of not implementing changes with unresolved critical issues. Option D is wrong because proceeding and resolving after implementation is risky and can lead to system failures, data loss, or downtime, and it bypasses the change control process.

12
MCQhard

A vulnerability scan identifies a critical vulnerability on a web server with a CVSS score of 9.8. The server hosts a public-facing application. However, the patch would require a reboot that would cause downtime during business hours. What should the security administrator do FIRST?

A.Assess the risk and implement compensating controls if possible
B.Schedule the patch for the next maintenance window without further analysis
C.Apply the patch immediately during business hours
D.Document the exception and ignore the vulnerability
AnswerA

Assessing risk and applying compensating controls, such as a web application firewall rule or network segmentation, addresses the exposure without rebooting. This satisfies the stem's constraint of avoiding business-hours downtime while the critical 9.8 CVSS vulnerability remains unpatched on the public-facing server.

Why this answer

Assessing the risk and implementing compensating controls if possible is the first step because it balances the need to address the critical vulnerability with the business impact of downtime. This approach follows risk management principles: evaluate the severity, exploitability, and potential impact, then apply mitigations such as virtual patching, network segmentation, or increased monitoring until a patch can be safely applied. It is not prudent to ignore or immediately disrupt business operations without analysis.

Exam trap

SSCP often tests the tendency to prioritize immediate patching over business continuity, but the correct first step is always risk assessment and compensating controls when downtime is a concern.

How to eliminate wrong answers

Option B is wrong because scheduling the patch without further analysis ignores the possibility of compensating controls that could reduce risk in the interim, and it does not consider the criticality of the vulnerability. Option C is wrong because applying the patch immediately during business hours could cause unplanned downtime, affecting business operations and potentially violating SLAs. Option D is wrong because documenting the exception and ignoring the vulnerability leaves the organization exposed to a critical risk, which is unacceptable for a public-facing server with a CVSS score of 9.8.

13
MCQmedium

A security administrator at a financial services firm is reviewing the organization's data retention practices. The legal team has mandated that certain transaction records be kept for exactly seven years and then destroyed. The administrator must ensure records are deleted automatically after seven years. Which of the following should be implemented to enforce this requirement?

A.A data loss prevention (DLP) solution that blocks exfiltration of transaction records
B.A backup schedule that archives transaction records every quarter to tape
C.A data classification scheme that labels transaction records as confidential
D.A retention policy with automated deletion after the seven-year period
AnswerD

A retention policy defines how long data must be kept and automates its destruction when the period expires. This directly enforces the legal mandate without relying on manual intervention, ensuring records are deleted exactly at seven years and reducing the risk of non-compliance or accidental over-retention.

Why this answer

A retention policy is the formal control that specifies how long records must be kept and triggers their destruction when the period ends. It aligns legal requirements with operational procedures and can be automated. Classification, backups, and DLP address different concerns and do not enforce time-based deletion.

Exam trap

The trap here is confusing data protection controls like classification or DLP with lifecycle management controls that actually enforce retention and destruction.

14
MCQmedium

During a security audit, it is found that several employees have written their passwords on sticky notes attached to their monitors. Which policy is being violated?

A.Social Media Policy
B.Clean Desk Policy
C.Data Handling Policy
D.Password Policy
AnswerB

A Clean Desk Policy requires sensitive information, including written credentials, to be secured or removed when workspaces are unattended. Sticky notes exposing passwords on monitors directly breach that requirement, since the policy explicitly covers physical artefacts left in plain view.

Why this answer

The Clean Desk Policy is violated because it requires employees to keep their workspaces free of sensitive information, including passwords, when not in use. Writing passwords on sticky notes and attaching them to monitors leaves credentials exposed, directly contravening this policy. The Clean Desk Policy aims to reduce the risk of unauthorized access to information.

Exam trap

SSCP often tests the confusion between Password Policy and Clean Desk Policy, but the physical exposure of passwords is a clean desk violation, not a password complexity issue.

How to eliminate wrong answers

Option A is wrong because a Social Media Policy governs employee use of social media platforms, not the physical security of passwords. Option C is wrong because a Data Handling Policy defines how data should be classified, stored, and transmitted, but the specific act of leaving passwords on monitors is a clean desk issue. Option D is wrong because a Password Policy typically dictates password complexity, rotation, and storage, but the violation here is the physical exposure of the password, which falls under clean desk rather than password construction rules.

15
MCQeasy

A company wants to ensure that employees understand the proper use of corporate email and internet. Which policy should they implement?

A.Data Handling Policy
B.Remote Access Policy
C.Acceptable Use Policy
D.Password Policy
AnswerC

An Acceptable Use Policy defines permitted employee behaviour for corporate email and internet resources, directly addressing the stated need. It specifies what staff may and may not do with these assets, unlike password or access policies that govern credentials.

Why this answer

An Acceptable Use Policy (AUP) defines the rules and guidelines for using corporate IT resources, including email and internet. It specifies permitted and prohibited activities, such as personal browsing, sending sensitive data, or accessing inappropriate content, ensuring employees understand their responsibilities. This policy directly addresses the company's goal of educating employees on proper usage, unlike other policies that focus on data classification, remote connectivity, or authentication.

Exam trap

The SSCP exam often tests the distinction between policies that are broad (like AUP) versus those that are narrowly focused on specific technical controls (like password or remote access), leading candidates to confuse a general usage guideline with a security control policy.

How to eliminate wrong answers

Option A is wrong because a Data Handling Policy governs how data is classified, stored, transmitted, and disposed of, not the general use of email and internet by employees. Option B is wrong because a Remote Access Policy specifies requirements for connecting to the corporate network from external locations (e.g., VPN protocols, multi-factor authentication), not day-to-day email and internet usage. Option D is wrong because a Password Policy defines password complexity, rotation, and management rules, not acceptable behaviors for email and internet use.

16
MCQeasy

What is the primary purpose of a baseline configuration in configuration management?

A.To provide a consistent, secure starting point for systems
B.To store configuration items in the CMDB
C.To detect malware infections
D.To track software licenses
AnswerA

A baseline configuration defines the approved, hardened settings — services, ports, registry values — that every system must match, giving configuration management a measurable reference for detecting drift. This satisfies the stem's purpose by establishing the consistent, secure starting point from which deviations are identified and corrected.

Why this answer

A baseline configuration in configuration management defines a known, secure, and consistent state for a system at a specific point in time. This baseline serves as the foundation for all subsequent changes, ensuring that systems are deployed with hardened settings and that any deviations can be detected and remediated. It directly supports security operations by enforcing minimum security standards and simplifying compliance auditing.

Exam trap

ISC2 often tests the distinction between a baseline configuration (the desired secure state) and the CMDB (the database that stores configuration items), so candidates mistakenly select the CMDB option because they confuse the repository with the purpose of the baseline itself.

How to eliminate wrong answers

Option B is wrong because storing configuration items in the CMDB is a function of the Configuration Management Database, not the purpose of a baseline configuration; a baseline is a snapshot of configuration items, not the storage repository itself. Option C is wrong because detecting malware infections is the role of antivirus or endpoint detection and response (EDR) tools, not a baseline configuration; while a baseline can help identify unauthorized changes that may indicate malware, its primary purpose is not detection. Option D is wrong because tracking software licenses is a function of license management or asset management tools, not the primary purpose of a baseline configuration; baselines focus on system settings and security posture, not license compliance.

17
MCQmedium

A company uses a backup strategy that backs up all data every Sunday and backs up only data that has changed since the last full backup on other days. This is an example of which backup type?

A.Full backup
B.Differential backup
C.Copy backup
D.Incremental backup
AnswerB

Differential backups copy every change made since the last full backup, so Sunday's full plus each day's cumulative changes matches this description. Incremental backups would capture only changes since the previous backup, which the stem explicitly excludes.

Why this answer

The described strategy backs up all data on Sunday (a full backup) and then on other days backs up only data that has changed since the last full backup. This is the defining characteristic of a differential backup: it always references the most recent full backup, not the previous day's backup. Unlike incremental backups, differential backups do not reset the archive bit after each run, so each differential backup grows in size until the next full backup.

Exam trap

The trap here is confusing 'changed since the last full backup' (differential) with 'changed since the last backup' (incremental), causing candidates to mistakenly select incremental backup when the key phrase 'since the last full backup' clearly indicates differential.

How to eliminate wrong answers

Option A is wrong because a full backup backs up all data every time, not just on Sundays with changes-only on other days. Option C is wrong because a copy backup backs up selected files without clearing the archive bit, but it does not follow a schedule of full-then-changes-only; it is a one-off copy. Option D is wrong because an incremental backup backs up only data changed since the last backup (full or incremental), not since the last full backup; it resets the archive bit after each run, resulting in smaller daily backups that require all previous incrementals to restore.

18
MCQeasy

A security administrator is implementing a defense-in-depth strategy for a new data center. Which of the following BEST describes the role of security awareness training within this strategy?

A.It enforces mandatory vacation policies to detect fraud.
B.It encrypts sensitive data at rest and in transit.
C.It reduces the likelihood of successful social engineering attacks by educating users.
D.It provides a technical control that blocks malware from executing on endpoints.
AnswerC

Security awareness training educates users about phishing, pretexting, and other social engineering tactics, making them less likely to fall victim. This directly reduces the risk of human-based attacks, which are a common initial access vector. It is a key administrative control in defense-in-depth.

Why this answer

Security awareness training is an administrative control that educates users on recognizing and avoiding social engineering attacks, thereby reducing the likelihood of successful phishing or pretexting attempts. It complements technical controls like firewalls and antivirus, forming a layer of defense that addresses the human element.

Exam trap

The trap here is confusing administrative controls like training with technical controls like encryption or malware blocking; training changes user behavior, not system behavior.

19
Multi-Selectmedium

A security administrator is selecting security metrics for the organization. Which TWO metrics are most useful for measuring the effectiveness of patching? (Select TWO)

Select 2 answers
A.Help desk ticket volume
B.Number of security incidents
C.Average time to patch critical vulnerabilities
D.Number of users trained
E.Patch compliance rate
AnswersC, E

Average time to patch critical vulnerabilities directly quantifies remediation speed, the core objective of a patching programme. It satisfies the stem's effectiveness requirement by measuring elapsed duration from vulnerability disclosure to deployed fix, exposing process delays that raw patch counts conceal. Shorter averages indicate a responsive, well-functioning patch management capability.

Why this answer

Option C, average time to patch critical vulnerabilities, is correct because it directly measures the speed of the remediation process, showing how quickly the organization closes exposure windows for high-risk flaws. Option E, patch compliance rate, is correct because it quantifies the percentage of systems that have the required patches applied, directly reflecting how thoroughly patching is executed across the estate. Together these two metrics capture both timeliness and coverage, which are the core dimensions of patching effectiveness.

The unmarked options do not belong: help desk ticket volume (A) is a workload indicator that may be unrelated to patching, number of security incidents (B) is an outcome measure influenced by many controls beyond patching, and number of users trained (D) measures awareness activity rather than patch deployment performance.

Exam trap

The trap here is that candidates often confuse 'number of security incidents' (a reactive, outcome-based metric) with a proactive patching metric, or they mistakenly think 'help desk ticket volume' reflects patching problems rather than user support load.

20
MCQeasy

Which of the following is the correct order of steps in the change management process?

A.Change request, impact assessment, CAB approval, testing, implementation, post-implementation review
B.Change request, CAB approval, impact assessment, testing, implementation, post-implementation review
C.Impact assessment, change request, CAB approval, testing, implementation, post-implementation review
D.Change request, testing, impact assessment, CAB approval, implementation, post-implementation review
AnswerA

The sequence begins with a formal change request, followed by impact assessment, approval from the change advisory board, testing, implementation, and finally a post-implementation review to confirm the change achieved its objective without adverse effects.

Why this answer

The standard change management lifecycle begins with a formal change request, followed by an impact/risk assessment so the CAB has the information needed to evaluate the change. Only after that assessment does the CAB approve or reject, then testing occurs in a non-production environment, then implementation, and finally a post-implementation review to confirm success and capture lessons learned. This sequence ensures decisions are made with full information and that changes are validated before touching production.

Exam trap

The trap is that candidates reorder CAB approval before impact assessment because approval 'feels' like it should come early — but the CAB needs the impact assessment as its input, so assessment must precede approval.

How to eliminate wrong answers

Option B is wrong because it places CAB approval before impact assessment — the CAB cannot make an informed decision without first knowing the impact and risk, so this order is logically inverted. Option C is wrong because it starts with impact assessment before a change request exists; there is nothing to assess until the change has been formally requested and documented. Option D is wrong because it places testing before impact assessment and CAB approval — testing a change that has not been approved or risk-assessed wastes resources and bypasses governance.

21
MCQmedium

A security administrator is reviewing the organization's backup strategy for a database server that must meet a recovery point objective (RPO) of 15 minutes. The server currently uses a full backup every Sunday and differential backups every night. The administrator finds that the current strategy cannot meet the RPO. Which backup method should the administrator implement to meet the RPO while minimizing backup storage consumption?

A.Differential backups every 15 minutes
B.Transaction log backups every 15 minutes
C.Full backups every 15 minutes
D.Snapshot backups every 15 minutes
AnswerB

Transaction log backups capture all committed transactions since the last log backup, enabling point-in-time recovery with an RPO as low as the backup interval. Scheduling them every 15 minutes directly meets the 15-minute RPO. They also consume far less storage than full backups because they contain only the log records, not the entire database.

Why this answer

Transaction log backups capture every committed transaction since the previous log backup, so a 15-minute schedule delivers an RPO of 15 minutes. They are also far more storage-efficient than full or differential backups because they contain only log records. This combination of frequent recovery points and low storage overhead makes them the correct choice for meeting the stated RPO.

Exam trap

The trap here is assuming that any frequent backup type satisfies an RPO, when only transaction log backups provide the granular, low-overhead recovery points required for a database with a 15-minute RPO.

22
MCQhard

During a post-implementation review of a change, it is discovered that the change introduced a configuration deviation from the baseline. The deviation was not detected during testing. What is the BEST way to prevent this in the future?

A.Increase the number of testers
B.Require CAB approval for all future changes
C.Implement automated configuration scanning in the staging environment
D.Use a different change management process
AnswerC

Automated configuration scanning in staging compares deployed settings against the approved baseline before production release, catching drift that functional testing misses. This satisfies the stem's constraint that the deviation escaped testing, because scanning detects configuration variance rather than relying on test cases.

Why this answer

Automated configuration scanning in the staging environment detects deviations from the baseline before production, catching issues that manual testing missed. This provides continuous, repeatable verification against the approved configuration baseline, which is the most reliable preventive control.

Exam trap

SSCP often tests preventive vs. detective controls — candidates pick CAB approval (governance) or more testers (manual) instead of automated configuration scanning, which is the actual technical preventive control.

How to eliminate wrong answers

Option A is wrong because adding testers increases manual effort but does not guarantee detection of configuration deviations — it is not a systematic control. Option B is wrong because CAB approval is a governance gate, not a technical detection mechanism; it does not verify configuration compliance. Option D is wrong because changing the change management process does not address the root cause (lack of automated configuration verification) and is vague.

23
MCQhard

A security administrator is implementing a new file integrity monitoring (FIM) solution on critical servers. The administrator needs to ensure that the solution can detect unauthorized changes to system binaries and configuration files. Which of the following should the administrator configure to establish a trusted baseline for the FIM solution?

A.Generate cryptographic hashes of the files and store them in a secure, offline location.
B.Schedule a daily full backup of the critical servers and store the backups on a separate network share.
C.Configure the FIM solution to monitor the Windows Registry for changes to critical keys.
D.Enable auditing of file access events in the operating system's security log.
AnswerA

FIM works by comparing current file hashes against a known good baseline. Storing the baseline hashes offline prevents an attacker who compromises the server from altering the baseline to hide their changes. This ensures the integrity of the comparison and allows detection of unauthorized modifications. Cryptographic hashes provide a unique fingerprint for each file, so any change will be detected.

Why this answer

To establish a trusted baseline for FIM, the administrator must capture the current state of critical files, typically by generating cryptographic hashes. Storing these hashes securely offline prevents tampering. File access auditing, backups, and registry monitoring do not provide a file content baseline.

Therefore, the correct action is to generate and securely store file hashes.

Exam trap

The trap here is confusing file access auditing or backups with file integrity baseline creation, when the key is to capture and protect a cryptographic hash of file contents.

24
MCQmedium

A company is implementing a new access control system for its data center. Which physical security control is best for preventing tailgating?

A.Mantrap
B.Biometric reader
C.Security guard
D.CCTV cameras
AnswerA

A mantrap uses two interlocking doors with an enclosed vestibule, admitting one person at a time and preventing an unauthorised individual from following closely behind. This interlock mechanism directly defeats tailgating, unlike turnstiles, guards or cameras that detect but do not physically stop it.

Why this answer

A mantrap is specifically designed to prevent tailgating by using a small vestibule with two interlocking doors. Only one door can open at a time, and the system typically requires authentication (e.g., badge or biometric) to proceed, ensuring that only one authorized person enters per cycle. This physical barrier directly blocks unauthorized individuals from following an authorized user through a single entry point.

Exam trap

SSCP candidates often mistake authentication methods like biometric readers or key cards as preventive controls for tailgating. However, these are identification/authentication controls; preventing tailgating requires a physical barrier such as a mantrap that enforces one-at-a-time entry.

How to eliminate wrong answers

Option B is wrong because a biometric reader authenticates identity but does not physically prevent multiple people from entering together; tailgating can still occur if an authorized user opens the door and an unauthorized person follows. Option C is wrong because while a security guard can deter tailgating, they are not a mechanical or automated control and can be distracted, overwhelmed, or bypassed, making them less reliable than a mantrap. Option D is wrong because CCTV cameras only provide surveillance and recording of tailgating incidents after they occur; they do not actively prevent the act of tailgating in real time.

25
MCQhard

A security administrator at a software company is reviewing the organization's security assessment strategy. The administrator must select an assessment method that evaluates the effectiveness of implemented controls through direct observation and testing, rather than relying on interviews or documentation review alone. Which assessment method should the administrator choose?

A.An independent security assessment that includes interviews, documentation review, and control testing.
B.A compliance review of the organization's written security policies and standards.
C.A self-assessment questionnaire completed by each department manager.
D.A vulnerability scan of all internet-facing systems using an automated scanner.
AnswerA

An independent security assessment combines multiple evidence-gathering techniques, including interviews, documentation review, observation, and direct testing of controls. Because it validates that controls operate as intended rather than merely existing on paper, it satisfies the requirement to evaluate effectiveness through observation and testing. The independence of the assessor also reduces bias compared with self-reported results.

Why this answer

Evaluating control effectiveness requires evidence beyond what people say or what policies state. An independent assessment that performs control testing through observation, sampling, and technical verification provides that evidence and reduces bias. Self-assessments, policy reviews, and vulnerability scans each address only part of the picture and cannot confirm that controls operate as designed across the organization.

Exam trap

The trap here is equating a vulnerability scan or a policy review with a full control effectiveness assessment, when only direct testing and observation validate that controls actually work.

26
MCQmedium

A security administrator is reviewing log files and notices that a user logged in at 3:00 AM from an IP address in a foreign country. The user's manager confirms the user is not authorized for remote access. Which type of policy has likely been violated?

A.Remote access policy
B.Data handling policy
C.Password policy
D.Acceptable use policy (AUP)
AnswerA

A remote access policy defines who may connect remotely, from where, and under what conditions. The login from a foreign IP at 03:00 breaches the manager-confirmed restriction that this user lacks remote access authorisation, so the access control constraint in the stem is directly violated.

Why this answer

The scenario describes a user logging in from an unauthorized location (foreign country) at an unusual time (3:00 AM) without remote access authorization. This directly violates the remote access policy, which defines who can connect remotely, from where, and under what conditions. The policy typically specifies allowed authentication methods (e.g., VPN with multi-factor authentication), permitted IP ranges, and time-of-day restrictions to prevent unauthorized external connections.

Exam trap

SSCP candidates often confuse Acceptable Use Policy (AUP) with Remote Access Policy. While AUP covers general appropriate use of systems, this specific violation involves unauthorized remote logins from a foreign IP at an odd hour, which falls under Remote Access Policy restrictions.

How to eliminate wrong answers

Option B (Data handling policy) is wrong because it governs how data is classified, stored, transmitted, and disposed of, not the conditions under which remote logins occur. Option C (Password policy) is wrong because it specifies password complexity, expiration, and reuse rules, not the authorization for remote access or geographic restrictions. Option D (Acceptable use policy) is wrong because it defines permissible activities on company resources (e.g., browsing, email usage), not the specific rules for remote connectivity or location-based access control.

27
MCQmedium

A security metric tracking the percentage of systems with critical patches applied within 48 hours is an example of which type of metric?

A.Service level agreement (SLA)
B.Key performance indicator (KPI)
C.Control objective
D.Key risk indicator (KRI)
AnswerB

A KPI measures progress toward a strategic objective, such as patch-management effectiveness, rather than raw operational volume. Tracking the percentage of systems meeting the 48-hour critical-patch window directly satisfies the stem's requirement for a performance-oriented metric, since it evaluates how well the patching process achieves its target, not merely how many patches were deployed.

Why this answer

A Key Performance Indicator (KPI) is a measurable value that demonstrates how effectively an organization is achieving key business objectives. The percentage of systems with critical patches applied within 48 hours is a performance metric that tracks the efficiency of the patch management process, making it a KPI. It indicates how well the security team is performing against a defined target.

Exam trap

The trap is confusing KPIs with KRIs or SLAs; candidates may think any security metric is a KRI, but KPIs measure performance of controls, while KRIs measure risk levels.

How to eliminate wrong answers

Option A is wrong because an SLA is a contractual agreement with defined service levels and penalties, not a metric itself; the metric could be used to measure SLA compliance but is not an SLA. Option C is wrong because a control objective is a statement of the desired outcome of a control, not a quantitative measure. Option D is wrong because a KRI measures risk exposure or likelihood, such as the number of unpatched critical vulnerabilities, rather than the performance of the patching process.

28
MCQmedium

An organization's security policy requires that all portable media containing sensitive data be encrypted. Which type of control does this requirement represent?

A.Detective control
B.Administrative control
C.Technical control
D.Physical control
AnswerB

Administrative controls are policy-level directives governing behaviour, and the stem's requirement is precisely a mandated rule rather than a technical mechanism. Encryption itself is the technical control; the policy compelling its use on portable media is administrative. It satisfies the constraint by defining expected practise without enforcing it through hardware or software.

Why this answer

This requirement is an administrative control because it is a policy mandate that defines rules and procedures for handling sensitive data. Administrative controls are management directives, such as security policies, standards, and guidelines, that govern behavior and processes. The encryption itself is a technical control, but the requirement to encrypt is a policy statement, which falls under administrative controls.

Exam trap

ISC2 SSCP exams test the distinction between administrative and technical controls. The requirement to encrypt is a policy (administrative control), while the encryption algorithm itself is a technical control. Candidates often select 'Technical control' because they focus on the encryption mechanism rather than the mandate.

How to eliminate wrong answers

Option A is wrong because detective controls are designed to identify and alert on security incidents after they occur (e.g., audit logs, intrusion detection systems), not to mandate encryption. Option C is wrong because technical controls are the actual mechanisms (e.g., BitLocker, AES-256 encryption software) that enforce the policy, not the policy requirement itself. Option D is wrong because physical controls protect assets through tangible means (e.g., locks, guards, safes), not through policy directives about data encryption.

29
MCQeasy

Which physical security control is designed to prevent tailgating by allowing only one person to enter at a time?

A.CCTV camera
B.Security guard
C.Biometric reader
D.Mantrap
AnswerD

A mantrap uses two interlocking doors with an occupancy sensor, admitting one person into a holding vestibule before the second door releases. This directly enforces the single-person entry constraint that defeats tailgating, unlike turnstiles or access badges, which cannot verify that only one individual passes per authentication.

Why this answer

A mantrap (also called an access control vestibule or airlock) is a small enclosed space with two interlocking doors that allows only one person through at a time, directly preventing tailgating. The first door must close and the person must be authenticated before the second door opens, so an unauthorized follower cannot slip in behind an authorized user. This is the physical control explicitly designed for anti-tailgating.

Exam trap

SSCP often tests the distinction between preventive and detective physical controls — candidates pick CCTV or guards because they 'watch the door,' but only a mantrap physically enforces one-person-at-a-time entry.

How to eliminate wrong answers

Option A is wrong because CCTV cameras are detective controls that record activity for later review; they do not physically prevent a second person from entering. Option B is wrong because a security guard is a deterrent and detective control that relies on human vigilance, which can be bypassed or distracted, and does not mechanically enforce one-person-at-a-time entry. Option C is wrong because a biometric reader authenticates an individual but does not by itself stop a second person from walking through the same open door behind the authenticated user — tailgating remains possible without a physical barrier.

30
MCQmedium

A security administrator at a healthcare company must ensure that audit logs from a critical patient-record system are retained for seven years and cannot be altered even by system administrators. Which solution BEST meets these requirements?

A.Use a SIEM with role-based access control (RBAC) to limit who can view or delete logs.
B.Enable local logging with daily log rotation and store the logs on a separate encrypted volume.
C.Configure the system to send logs to a remote syslog server with file permissions restricted to root.
D.Implement a write-once read-many (WORM) storage solution for log archival with a seven-year retention policy.
AnswerD

WORM storage physically or logically prevents modification or deletion of data once written, directly satisfying the immutability requirement even against privileged administrators. A seven-year retention policy ensures compliance with the stated retention period. This is the standard approach for tamper-evident audit log archiving in regulated industries.

Why this answer

WORM storage ensures that once audit logs are written, they cannot be modified or deleted, even by users with administrative privileges, directly meeting the immutability and seven-year retention requirements. Other options focus on access control or encryption but do not provide the non-repudiation and tamper-evidence needed for compliance.

Exam trap

The trap here is assuming that restricting permissions or using RBAC is sufficient to make logs tamper-proof, when in fact only WORM or similar immutable storage guarantees that even administrators cannot alter the data.

31
MCQhard

An organization uses a mantrap at its main entrance. An employee badges in, enters the first door, but then the second door fails to open. What should the employee do?

A.Return through the first door
B.Use the intercom to contact security
C.Force the second door open
D.Wait for someone to open from the other side
AnswerB

Using the intercom to contact security is the safe response when the mantrap's second door fails. A mantrap is a physical access control vestibule designed to prevent tailgating and trap intruders; remaining inside and alerting security preserves that containment. Forcing the door or exiting backwards could breach the controlled entry and defeat the mantrap's purpose.

Why this answer

In a mantrap (access control vestibule), if the second door fails to open after the first door closes, the employee should use the intercom to contact security. This ensures that security personnel can assess the situation, verify identity, and manually override the door if appropriate, while maintaining the security integrity of the mantrap.

Exam trap

The trap is choosing an action that seems convenient (like returning or waiting) but violates security protocols; candidates may not realize that contacting security is the correct procedure to maintain security and safety.

How to eliminate wrong answers

Option A is wrong because returning through the first door may not be possible if it has locked behind the employee, and it could also trigger an alarm or violate security protocols. Option C is wrong because forcing the second door open defeats the purpose of the mantrap and could cause damage or security breach. Option D is wrong because waiting for someone to open from the other side is passive and may not happen; it also bypasses security procedures.

32
Multi-Selectmedium

Which TWO of the following are key components of a configuration management database (CMDB)? (Select TWO)

Select 2 answers
A.Password hashes
B.Change request approvals
C.Relationships between configuration items
D.Incident tickets
E.Hardware inventory details such as serial numbers
AnswersC, E

Relationships between configuration items are a core CMDB component because they map dependencies and connections across the IT estate. This satisfies the stem's requirement for key components, distinguishing a CMDB from a plain asset inventory, which records items without capturing how they interlink or affect one another.

Why this answer

Option C is correct because a CMDB's defining feature is storing configuration items (CIs) together with their dependencies and relationships, which enables impact analysis and service mapping. Option E is correct because CIs include hardware assets and their attributes, such as serial numbers, model, and location, which are core inventory data held in the CMDB. Options A, B, and D are not CMDB components: password hashes belong to credential/identity stores such as Active Directory or a secrets vault, change request approvals belong to a change management/workflow system (e.g., ITIL change records), and incident tickets belong to an incident management or ITSM ticketing system, even though these tools may integrate with the CMDB.

Exam trap

The trap here is confusing the CMDB with other ITIL processes or data stores, leading candidates to select change request approvals (a change management artifact) or incident tickets (an incident management artifact) as CMDB components, when they are separate records linked to CIs but not stored within the CMDB itself.

33
MCQeasy

A security administrator is implementing a policy that requires all employees to use a password manager and enable multi-factor authentication. This policy is BEST described as a:

A.Data handling policy
B.Password policy
C.Social media policy
D.Remote access policy
AnswerB

A password policy defines rules for password creation, management, and authentication, including multi-factor authentication.

Why this answer

The policy requires all employees to use a password manager and enable multi-factor authentication, which directly governs the creation, storage, and authentication strength of user credentials. This is the core function of a password policy, as defined in security frameworks like NIST SP 800-53 (IA-5) and ISO 27001 (A.9.2.1). It specifically addresses password complexity, rotation, and MFA enforcement, not data classification or access methods.

Exam trap

The trap is that candidates may confuse a password policy (which includes MFA as an authentication control) with a remote access policy, because MFA is often associated with VPN logins. However, the question explicitly states the policy applies to all employees, not just remote workers, so the correct classification is a password policy.

How to eliminate wrong answers

Option A is wrong because a data handling policy governs how data is classified, stored, transmitted, and disposed of (e.g., encryption at rest, data retention schedules), not the authentication credentials used to access systems. Option C is wrong because a social media policy regulates employee behavior on public platforms (e.g., posting confidential information, representing the company), not internal authentication mechanisms. Option D is wrong because a remote access policy defines the methods and controls for connecting to the corporate network from external locations (e.g., VPN protocols, split tunneling), not the password and MFA requirements that apply to all access, including local.

34
Multi-Selecteasy

A security administrator is designing physical security for a high-security area. Which TWO controls are most effective for preventing unauthorized entry? (Select TWO)

Select 2 answers
A.Biometric reader
B.Visitor log
C.Clean desk policy
D.Mantrap
E.Screen locks
AnswersA, D

A biometric reader verifies a unique physiological trait, so credentials cannot be shared, copied or lost like badges and PINs. This satisfies the high-security constraint by binding entry to a specific enrolled person, preventing unauthorised individuals from gaining access with stolen or borrowed credentials.

Why this answer

A biometric reader (A) is correct because it authenticates identity using a unique physical trait such as a fingerprint or iris pattern, which cannot be easily shared, stolen, or forged like a badge or password, making it a strong preventive access control for a high-security area. A mantrap (D) is correct because it is an interlocking double-door vestibule that admits only one person at a time and prevents tailgating or piggybacking, directly stopping unauthorized individuals from following an authorized person into the secured space. Together these controls enforce both identity verification and single-person entry, which is why they are the most effective preventive measures listed.

A visitor log (B) is only a detective/administrative record and does nothing to stop someone from entering. A clean desk policy (C) protects information from casual observation or theft but does not control physical entry. Screen locks (E) are a logical access control that secures a workstation session, not a barrier to entering a room.

Exam trap

The trap here is confusing administrative/detective controls (visitor logs, clean desk, screen locks) with preventive physical controls — SSCP often tests whether candidates can classify controls by function (preventive vs. detective vs. administrative) rather than just recognizing security-sounding terms.

35
Multi-Selectmedium

A company is implementing a change management process. Which THREE elements are essential for every change request? (Select THREE)

Select 3 answers
A.Description of the change
B.Impact assessment
C.Rollback plan
D.Employee performance review
E.Budget approval
AnswersA, B, C

A description of the change is essential because it defines the scope, affected systems and intended outcome, enabling the change advisory board to assess risk and impact before approval. Without it, reviewers cannot evaluate the request against the change management process, so this element satisfies the stem's requirement for every change request.

Why this answer

A description of the change (A) is essential because it defines exactly what will be modified, including the systems, services, and scope involved, so that approvers and implementers understand the request. An impact assessment (B) is required to identify the risks, affected users, dependencies, and potential downtime, which allows the change advisory board to evaluate and prioritize the change. A rollback plan (C) is critical because it provides a tested, documented procedure to revert the change if it fails or causes an outage, minimizing business disruption.

Employee performance review (D) is unrelated to change management, as it evaluates individual job performance rather than a technical or process change. Budget approval (E) may be needed for some changes, but it is not an essential element of every change request, since many changes involve no direct cost.

Exam trap

The trap here is that candidates confuse 'essential change request elements' with general business processes like HR reviews or financial approvals, but the SSCP focuses strictly on technical and operational controls for security and stability.

36
MCQeasy

A security administrator is implementing a new access control system. The organization wants to ensure that users are granted only the permissions necessary to perform their job functions and nothing more. Which principle is being applied?

A.Least privilege
B.Implicit deny
C.Separation of duties
D.Defense in depth
AnswerA

Least privilege means granting users only the access required to perform their job and no more. This directly matches the requirement to avoid excessive permissions. It reduces attack surface and limits damage from compromised accounts, making it the correct principle for this scenario.

Why this answer

Least privilege is the principle of providing users with only the access rights required for their tasks. It minimizes the potential for accidental or malicious misuse of privileges. Separation of duties, defense in depth, and implicit deny are related but distinct concepts that do not directly address minimizing granted permissions.

Exam trap

The trap here is conflating least privilege with implicit deny; implicit deny is about default denial, while least privilege is about minimizing what is explicitly granted.

37
MCQeasy

A security awareness training program is being developed. Which topic is most important to include to reduce the risk of credential theft?

A.Proper use of social media
B.Physical security procedures
C.Recognizing phishing attempts
D.Data backup procedures
AnswerC

Phishing is the leading vector for stolen credentials, tricking users into surrendering passwords on fraudulent pages. Training staff to recognise suspicious senders, links and urgent requests directly reduces that risk, addressing the credential-theft constraint more effectively than general policy or password topics.

Why this answer

Phishing is the primary vector for credential theft, as attackers use deceptive emails or messages to trick users into revealing usernames and passwords. Training users to recognize phishing attempts—such as spoofed sender addresses, suspicious URLs, and urgent language—directly mitigates this risk by preventing credential disclosure at the point of attack. Unlike other topics, phishing awareness specifically targets the social engineering techniques most commonly used to steal credentials.

Exam trap

The trap here is that candidates may choose physical security procedures (Option B) because they associate credential theft with stolen hardware, but the SSCP exam emphasizes that the most common and effective method of credential theft is phishing, not physical access.

How to eliminate wrong answers

Option A is wrong because proper use of social media, while important for privacy, does not directly address credential theft; attackers typically harvest credentials through phishing rather than social media posts. Option B is wrong because physical security procedures, such as locking doors or securing badges, protect against physical theft of devices or documents but do not prevent remote phishing attacks that steal credentials via email or web forms. Option D is wrong because data backup procedures focus on recovering from data loss due to ransomware or hardware failure, not on preventing the initial compromise of credentials through social engineering.

38
Multi-Selectmedium

An organization is implementing a software inventory management process. Which TWO of the following should be tracked for each software asset?

Select 2 answers
A.License type and number of licenses
B.Physical location of the installed software
C.Version and patch level
D.Serial number of the installation media
E.Name of the user who installed it
AnswersA, C

Tracking licence type and count directly satisfies the inventory's licensing-compliance constraint, since each asset's entitlement must be reconcilable against deployed instances. Licence type distinguishes perpetual, subscription, and concurrent models, while the count exposes over-deployment or shortfalls during audits. This pairing is therefore essential for software asset management.

Why this answer

Option A (License type and number of licenses) is correct because software inventory management must track licensing entitlements—such as perpetual, subscription, or concurrent-user licenses and the quantity purchased—to ensure license compliance, avoid over-deployment penalties, and support audits. Option C (Version and patch level) is correct because knowing the exact version and patch level of each installed application is essential for vulnerability management, patch remediation, and confirming supportability. Option B is not a standard inventory attribute for software assets; physical location is typically tracked for hardware assets, not installed software.

Option D is unnecessary because installation media serial numbers are not meaningful inventory data for deployed software. Option E is not required for inventory purposes; the installing user does not determine licensing, versioning, or compliance status.

Exam trap

(ISC)² often tests the distinction between physical asset tracking (e.g., hardware serial numbers) and logical software inventory attributes, leading candidates to mistakenly select the serial number of installation media as a tracked item.

39
Multi-Selecthard

A security administrator is implementing physical security for a data center. Which THREE of the following controls should be included to provide layered security?

Select 3 answers
A.Mantrap at the main entrance
B.Screen locks on all workstations
C.CCTV monitoring of all entry points
D.Clean desk policy for employees
E.Biometric readers on server room doors
AnswersA, C, E

A mantrap permits only one person through at a time, using interlocking doors to prevent tailgating and credential passback. It enforces strict identity verification at the perimeter, forming the outermost layer of defence-in-depth for the data centre.

Why this answer

A mantrap at the main entrance (A) is correct because it creates a physical buffer zone that allows only one person through at a time, preventing tailgating and piggybacking into the facility. CCTV monitoring of all entry points (C) is correct because it provides continuous surveillance and recording of access points, enabling detection, deterrence, and forensic review of security incidents. Biometric readers on server room doors (E) are correct because they enforce strong authentication based on unique physiological traits for the most sensitive area, adding a distinct layer beyond perimeter controls.

Screen locks on workstations (B) and a clean desk policy (D) are administrative and logical controls for protecting information, not physical controls for securing a data center's entry points and rooms.

Exam trap

The trap here is that candidates confuse administrative or logical controls (like screen locks or clean desk policies) with physical security controls, which must be tangible barriers or detection systems that protect the facility's perimeter and access points.

40
MCQmedium

A healthcare organization's security team is reviewing a third-party cloud provider that will store electronic protected health information. The provider's SOC 2 Type II report is two years old, and the provider has since migrated to a new data center. Which action should the security administrator take FIRST to determine whether the provider still meets the organization's security requirements?

A.Request the provider's current SOC 2 Type II report or bridge letter covering the new data center period.
B.Immediately terminate the contract and select a new cloud provider with a current SOC 2 report.
C.Accept the existing SOC 2 Type II report because it demonstrates the provider has a mature security program.
D.Perform a full penetration test of the provider's new data center without notifying the provider.
AnswerA

A SOC 2 Type II report covers a historical period, and the migration to a new data center means the controls assessed in the old report may no longer be representative. Requesting an updated report or a bridge letter that covers the gap is the appropriate first step because it gives current, independent evidence of control effectiveness before any contractual or technical decisions are made.

Why this answer

A SOC 2 Type II report is point-in-time evidence covering a defined audit period and specific systems. Because the provider migrated to a new data center after the report was issued, the prior opinion does not cover the current environment. Requesting an updated report or a bridge letter is the correct first action because it provides current, independent assurance before the organization makes contractual or technical decisions.

Exam trap

The trap here is assuming that any SOC 2 Type II report satisfies due diligence regardless of its age or the scope of systems it covered.

41
MCQhard

An organization wants to ensure that servers are configured securely before deployment. They plan to use a hardened operating system image and regularly scan for deviations using SCAP. Which concept does this represent?

A.Change management
B.Asset management
C.Configuration management
D.Patch management
AnswerC

Configuration management maintains a known, hardened baseline image and detects drift through SCAP scans, directly satisfying the requirement to verify servers are securely configured before deployment. It governs the full lifecycle of configuration items, ensuring deviations are identified and remediated, which is precisely the control the organisation seeks.

Why this answer

C is correct because configuration management involves establishing and maintaining consistent baseline configurations for systems, such as using a hardened OS image, and then monitoring for deviations using tools like SCAP (Security Content Automation Protocol). SCAP enables automated vulnerability scanning and compliance checking against defined security baselines, ensuring servers remain in a known secure state before and after deployment.

Exam trap

The trap here is that candidates confuse configuration management with patch management, thinking that scanning for deviations always means checking for missing patches, when in fact SCAP scans assess a wide range of configuration settings (e.g., registry keys, file permissions, service states) beyond just patch levels.

How to eliminate wrong answers

Option A is wrong because change management focuses on controlling and documenting changes to systems after deployment, not on establishing a secure baseline image or scanning for deviations from that baseline. Option B is wrong because asset management deals with tracking and inventorying hardware and software assets throughout their lifecycle, not with enforcing secure configurations or scanning for compliance. Option D is wrong because patch management specifically addresses the application of software updates to fix vulnerabilities, whereas the scenario describes using a hardened image and SCAP scanning for configuration deviations, which is broader than patching.

42
Multi-Selecteasy

Which THREE of the following are examples of security awareness training topics?

Select 3 answers
A.How to apply patches to servers
B.Recognizing phishing emails
C.Configuring firewall rules
D.Physical security best practices (e.g., locking screens)
E.Social engineering tactics
AnswersB, D, E

Recognising phishing emails is a core security awareness topic, teaching staff to identify suspicious senders, links and requests. It directly reduces credential theft and malware risk, satisfying the question's requirement for a valid awareness training subject.

Why this answer

Security awareness training targets the general workforce's day-to-day behavior rather than specialized technical administration. Option B (Recognizing phishing emails) is correct because teaching users to spot suspicious senders, spoofed links, and urgent lures is a core awareness objective that reduces credential theft and malware infections. Option D (Physical security best practices such as locking screens) is correct because awareness programs cover everyday physical controls like clean-desk policies, tailgating prevention, and screen locking to protect data from unauthorized access.

Option E (Social engineering tactics) is correct because understanding pretexting, baiting, and impersonation helps employees resist manipulation attempts that bypass technical controls. Options A (applying server patches) and C (configuring firewall rules) are not awareness topics; they are hands-on technical administration tasks performed by IT/security staff, not general-user training content.

Exam trap

The trap here is that candidates confuse technical administration tasks (patching, firewall configuration) with awareness-level training, which is designed for all employees and focuses on behavioral change rather than technical skills.

43
MCQhard

An organization wants to ensure that all new servers are deployed with a hardened baseline configuration. Which of the following is the most effective control to enforce this?

A.Requiring post-deployment security reviews for each server
B.Using a configuration management tool to deploy a hardened image automatically
C.Requiring administrators to manually apply CIS benchmarks after installation
D.Performing periodic vulnerability scans on all servers
AnswerB

Automated configuration management enforces the hardened baseline consistently across every new server, removing manual drift. Deploying a hardened image automatically satisfies the stem's requirement for guaranteed baseline configuration at deployment, unlike documentation or manual checklists.

Why this answer

Using a configuration management tool (e.g., Ansible, Puppet, Chef) to deploy a hardened image automatically ensures that every new server is built from a pre-defined, secure baseline without relying on manual steps. This enforces consistency and prevents configuration drift from the moment of deployment, which is the most effective control for ensuring compliance with hardening standards.

Exam trap

The trap here is that candidates often choose post-deployment reviews or vulnerability scans because they seem like thorough security measures, but the question specifically asks for the most effective control to *enforce* a hardened baseline, which requires a preventive, automated approach rather than a reactive or manual one.

How to eliminate wrong answers

Option A is wrong because post-deployment security reviews are reactive and do not prevent insecure configurations from being deployed; they only identify issues after the fact. Option C is wrong because requiring administrators to manually apply CIS benchmarks after installation introduces human error and inconsistency, and it does not guarantee that hardening is applied before the server is placed into production. Option D is wrong because periodic vulnerability scans detect existing weaknesses but do not enforce a hardened baseline at deployment time; they are a detective control, not a preventive one.

44
MCQhard

A company is implementing a new patch management process. After scanning for missing patches, the team must prioritize which patches to apply first. Which combination of factors is most critical for prioritization?

A.CVSS score and asset criticality
B.Number of systems affected and patch size
C.Age of the patch and vendor reputation
D.Cost of the patch and availability of workarounds
AnswerA

CVSS score quantifies technical severity, while asset criticality reflects business impact if that host is compromised. Combining both prevents wasting effort on severe flaws on trivial systems and ensures patches for exploitable vulnerabilities on high-value assets are applied first.

Why this answer

CVSS score quantifies the technical severity of a vulnerability (base, temporal, and environmental metrics), while asset criticality reflects the business impact if that asset is compromised. Combining these two factors ensures patches that are both highly exploitable and protect the most valuable systems are applied first, which is the standard risk-based prioritization approach in patch management frameworks like those from NIST and CIS.

Exam trap

SSCP often tests the distinction between technical severity (CVSS) and business impact (asset criticality), tricking candidates into choosing operational metrics like patch size or cost that feel practical but are not risk-based prioritization factors.

How to eliminate wrong answers

Option B is wrong because the number of systems affected and patch size do not reflect the severity of the vulnerability or the business value of the affected assets — patch size is irrelevant to risk. Option C is wrong because patch age and vendor reputation are not quantitative risk factors; a patch's age does not indicate exploitability, and vendor reputation is subjective. Option D is wrong because cost and workaround availability are operational considerations, not risk-prioritization factors — a cheap patch for a low-severity issue should still rank below an expensive patch for a critical vulnerability.

45
MCQmedium

A security administrator needs to ensure that all servers are configured with a hardened baseline. Which tool is best suited to detect deviations from the baseline configuration?

A.Vulnerability scanner
B.Asset management database
C.SCAP scanner
D.SIEM
AnswerC

An SCAP scanner evaluates system configurations against standardised checklists such as DISA STIG or CIS benchmarks, reporting deviations from the hardened baseline. This satisfies the requirement to detect configuration drift, which signature-based vulnerability scanners alone would not reliably identify.

Why this answer

SCAP (Security Content Automation Protocol) scanners are specifically designed to automate the verification of system configurations against a defined baseline, such as a hardened image or a security policy. They use standardized checklists (e.g., XCCDF, OVAL) to detect deviations, making them the ideal tool for this task. Unlike vulnerability scanners, SCAP scanners focus on configuration compliance rather than known vulnerabilities.

Exam trap

The trap here is that candidates confuse a vulnerability scanner (which finds weaknesses) with a configuration compliance scanner (which checks for policy drift), but the question specifically asks for detecting deviations from a baseline, not vulnerabilities.

How to eliminate wrong answers

Option A is wrong because a vulnerability scanner (e.g., Nessus, Qualys) primarily identifies known software vulnerabilities (CVEs) and missing patches, not configuration drift from a hardened baseline. Option B is wrong because an asset management database (e.g., CMDB) stores inventory and configuration items but does not actively scan or detect real-time deviations from a baseline. Option D is wrong because a SIEM (Security Information and Event Management) aggregates and correlates logs for incident detection, but it does not perform proactive configuration compliance checks against a baseline.

46
Multi-Selectmedium

A security administrator is reviewing the organization's incident response plan. The plan must include procedures for handling security incidents. Which of the following are appropriate steps to include in the incident response process? (Choose two.)

Select 2 answers
A.Immediate shutdown of all network services to isolate the incident.
B.Public disclosure of the incident details to all employees.
C.Containment of the incident to prevent further damage.
D.Immediate deletion of all logs to prevent attacker access.
E.Eradication of the root cause of the incident.
AnswersC, E

Containment is a critical step in incident response that aims to limit the scope and impact of an incident. It involves isolating affected systems, disabling compromised accounts, and preventing the spread of malware. This step follows identification and precedes eradication and recovery. Without containment, the incident could escalate and cause more damage, so it is an essential part of the process.

Why this answer

The incident response process typically includes preparation, identification, containment, eradication, recovery, and lessons learned. Containment and eradication are two key steps. Deleting logs destroys evidence, public disclosure to all employees is not a standard step, and shutting down all network services is overly broad and disruptive.

Thus, containment and eradication are the correct steps to include.

Exam trap

The trap here is thinking that drastic actions like deleting logs or shutting down all services are part of incident response, when in fact containment and eradication are the structured steps.

47
MCQeasy

Which of the following backup methods copies all data that has changed since the last full backup, regardless of any intermediate backups?

A.Differential backup
B.Full backup
C.Incremental backup
D.Snapshot backup
AnswerA

Differential backups capture all data changed since the last full backup, ignoring intermediate backups entirely. Incremental backups would only copy changes since the most recent backup of any type, so differential is the precise match for the stem's wording.

Why this answer

A differential backup copies all data that has changed since the last full backup, regardless of any intermediate backups. This means each differential backup grows in size as it accumulates all changes made since the last full backup, making it distinct from incremental backups which only capture changes since the last backup of any type.

Exam trap

The trap here is that candidates often confuse differential and incremental backups, mistakenly thinking differential only captures changes since the last backup of any type, when it actually captures all changes since the last full backup.

How to eliminate wrong answers

Option B is wrong because a full backup copies all data, not just changed data since the last full backup. Option C is wrong because an incremental backup copies only data that has changed since the last backup (whether full or incremental), not since the last full backup. Option D is wrong because a snapshot backup captures the state of a system at a point in time, often using copy-on-write technology, and is not a traditional backup method that tracks changes since a full backup.

48
MCQhard

A security administrator is drafting a data handling standard for a retail company that processes payment cards. The standard must state how long transaction records may be retained and how they must be destroyed. Which source should PRIMARILY drive these retention and destruction requirements?

A.The storage capacity available in the primary transaction database.
B.The vendor's default configuration settings for the point-of-sale system.
C.Legal, regulatory, and contractual requirements applicable to payment card data.
D.The preferences of the marketing department for customer analytics.
AnswerC

Retention and destruction rules for payment card data flow from laws, industry standards such as the Payment Card Industry Data Security Standard, and contracts with acquiring banks. These obligations define minimum and maximum retention periods and acceptable destruction methods. Basing the standard on them ensures the company can demonstrate compliance and avoid penalties.

Why this answer

Data retention and destruction standards must be anchored in the obligations that apply to the data. For payment card information, those obligations come from laws, the payment card industry standard, and acquiring bank contracts. Operational factors such as storage capacity or analytics desires inform implementation but cannot define the retention period or destruction method.

Exam trap

The trap here is letting a convenient technical or business factor, such as available storage or analytics value, stand in for the legal and contractual obligations that actually govern retention.

49
MCQhard

A company's backup strategy uses a full backup on Sundays and differential backups on other days. On Thursday, the storage system fails. How many backups are required to restore the data?

A.One (the full backup only)
B.Five (the full backup and all differentials from Monday to Thursday)
C.Two (the full backup and the Thursday differential)
D.Six (all backups from Sunday to Thursday)
AnswerC

Differential backups capture all changes since the last full backup, so Thursday's differential already contains Monday through Thursday's modifications. Restoration therefore needs only the Sunday full plus that single Thursday differential — two sets — satisfying the stem's recovery requirement without replaying intermediate daily backups.

Why this answer

A differential backup copies all data changed since the last full backup. Therefore, to restore data on Thursday, you need the last full backup (Sunday) and the most recent differential backup (Thursday), which contains all changes from Sunday through Thursday. This totals two backups.

Exam trap

The trap here is confusing differential backups with incremental backups, leading candidates to think they need all backups from Monday to Thursday (Option B) or all backups (Option D), when in fact only the full and the latest differential are required.

How to eliminate wrong answers

Option A is wrong because a full backup alone does not include changes made after Sunday, so data from Monday through Thursday would be lost. Option B is wrong because differential backups are cumulative; you do not need all differentials from Monday to Thursday—only the latest differential (Thursday) contains all changes since the full backup. Option D is wrong because you do not need every backup from Sunday to Thursday; the full backup plus the Thursday differential is sufficient, and including the other differentials is redundant and inefficient.

50
Multi-Selectmedium

A security administrator is implementing a data loss prevention strategy for a company that handles credit card data. The administrator must ensure the organization meets PCI DSS requirements for protecting stored cardholder data. Which TWO practices should the administrator implement? (Choose two.)

Select 2 answers
A.Encrypt cardholder data with a strong algorithm and manage cryptographic keys using documented key management procedures.
B.Transmit cardholder data over public networks using a proprietary encryption scheme that is not reviewed by independent experts.
C.Retain all cardholder data indefinitely to support future fraud investigations.
D.Render the primary account number unreadable anywhere it is stored using strong cryptography.
E.Store the full magnetic stripe data in a central repository for backup and reconciliation purposes.
AnswersA, D

PCI DSS requires strong cryptography and secure key management for stored cardholder data. Keys must be protected against disclosure and misuse, with documented processes for generation, distribution, storage, rotation, and destruction. Encryption alone without proper key management is ineffective, so implementing both encryption and formal key management procedures is a required practice for protecting stored cardholder data.

Why this answer

PCI DSS requires that stored cardholder data be protected through rendering the primary account number unreadable and through strong cryptography with proper key management. These two practices reduce the likelihood and impact of unauthorized disclosure. Retaining full track data, keeping data indefinitely, or relying on proprietary encryption all violate PCI DSS requirements or accepted security practice for cardholder data protection.

Exam trap

The trap here is selecting data retention or transmission controls when the scenario specifically asks about protecting stored cardholder data.

51
MCQeasy

A security administrator is reviewing the organization's account management procedures. The administrator discovers that user accounts for terminated employees remain active for up to 30 days after departure. Which account management control should the administrator implement to address this risk?

A.Enforce a password expiration policy of 30 days
B.Implement an automated account deprovisioning process tied to HR termination records
C.Conduct quarterly access reviews of all user accounts
D.Require multi-factor authentication for all user accounts
AnswerB

Automated deprovisioning triggered by HR termination records ensures accounts are disabled or removed as soon as the employment status changes. This directly reduces the window of unauthorized access and eliminates reliance on manual, error-prone processes. It addresses the root cause: accounts remaining active after termination.

Why this answer

An automated deprovisioning process linked to HR termination records disables accounts immediately upon termination, eliminating the 30-day window of exposure. Manual or periodic controls cannot match this timeliness. This is the most direct and effective control for ensuring departed employees lose access promptly.

Exam trap

The trap here is selecting a control that strengthens authentication or reviews access periodically, when the actual gap is the delay in disabling accounts after termination.

52
MCQhard

A financial services firm is implementing role-based access control for its trading platform. An auditor finds that several traders can approve their own trades in addition to executing them. Which principle is being violated, and which control should the security administrator implement to remediate the finding?

A.Separation of duties; enforce distinct roles so the trade executor cannot also approve the same transaction.
B.Need to know; restrict traders from viewing market data unrelated to their assigned portfolios.
C.Least privilege; implement just-in-time privileged access with approval workflows.
D.Mandatory access control; classify trades by sensitivity and apply system-enforced labels.
AnswerA

Separation of duties requires that no single individual controls all parts of a critical transaction. Allowing a trader to both execute and approve trades creates an opportunity for fraud or undetected error. Remediation is to define mutually exclusive roles so the approval function is performed by a different authorized person, which directly addresses the conflicting duties observed by the auditor.

Why this answer

The auditor observed that the same individual can execute and approve a trade, which is a classic separation of duties violation. Separation of duties ensures that critical tasks are divided among multiple people so that no single person can complete a sensitive transaction alone. Implementing mutually exclusive roles that separate execution from approval directly remediates the finding.

Exam trap

The trap here is confusing least privilege with separation of duties when a user has two legitimate but conflicting business functions.

53
MCQhard

A critical vulnerability with a CVSS score of 9.8 is discovered in a web server that cannot be patched due to vendor dependency. What is the best compensating control?

A.Increase the frequency of vulnerability scans
B.Apply a virtual patch via a WAF
C.Decommission the server immediately
D.Disable the server's network connectivity
AnswerB

A WAF virtual patch inspects and blocks exploit traffic targeting the known vulnerability signature, mitigating risk without touching the vendor-locked server. This satisfies the unpatachable constraint by compensating at the network layer rather than the host.

Why this answer

A WAF can apply a virtual patch by inspecting HTTP/HTTPS traffic and blocking exploit attempts against the unpatched vulnerability. This provides a compensating control at the application layer without modifying the vulnerable server, allowing the server to remain operational while mitigating the risk.

Exam trap

The trap here is that candidates may confuse compensating controls with detection or removal actions, choosing increased scanning (A) as a proactive measure, when in fact only a WAF provides active mitigation at the application layer.

How to eliminate wrong answers

Option A is wrong because increasing vulnerability scan frequency only detects the vulnerability; it does not prevent exploitation, so the risk remains unmitigated. Option C is wrong because decommissioning the server immediately may be too disruptive and is not a compensating control; it is a removal of the asset, not a control that allows continued operation. Option D is wrong because disabling network connectivity effectively removes the server from service, which is a last-resort isolation measure, not a compensating control that permits ongoing functionality.

54
MCQeasy

Which of the following is a key principle of the 3-2-1 backup rule?

A.Two copies on three different media types with one onsite
B.One copy on two different media types with three offsite
C.Three copies on two different media types with one offsite
D.Three copies on three different media types with two offsite
AnswerC

The rule mandates three total copies of data, stored across two distinct media types, with one copy held offsite. That separation protects against simultaneous loss: a single media failure, theft or site disaster cannot destroy every copy at once.

Why this answer

The 3-2-1 backup rule is a foundational data protection strategy: maintain three copies of your data (one primary and two backups), store them on two different media types (e.g., disk and tape, or local SSD and cloud object storage), and ensure at least one copy is stored offsite to protect against site-level disasters. Option C correctly captures this: three copies, two media types, one offsite.

Exam trap

The trap here is that candidates often misremember the numbers, confusing the '3' copies with '3' media types or '2' offsite, leading them to select options like A or D that sound plausible but violate the exact 3-2-1 structure.

How to eliminate wrong answers

Option A is wrong because it states 'two copies on three different media types with one onsite' — the rule requires three copies, not two, and only two different media types, not three. Option B is wrong because it says 'one copy on two different media types with three offsite' — the rule mandates three copies total, with only one offsite, not three offsite. Option D is wrong because it specifies 'three copies on three different media types with two offsite' — the rule requires only two different media types, not three, and only one offsite copy, not two.

55
MCQmedium

A security administrator is reviewing an incident response plan and finds that the team has no agreed way to classify how severe a detected event is before deciding whether to escalate. Which artifact should be created to standardize this decision?

A.A vulnerability management scanning schedule.
B.A memorandum of understanding with the legal department.
C.A service level agreement with the managed security service provider.
D.An incident severity matrix that maps impact and scope to response tiers.
AnswerD

A severity matrix defines levels such as low, medium, high, and critical based on factors like business impact, data sensitivity, and number of affected systems. It gives responders a consistent, repeatable way to decide escalation and notification. Because the gap is inconsistent triage, a documented classification scheme directly resolves the problem and supports metrics reporting.

Why this answer

Consistent incident triage depends on predefined criteria that translate technical indicators and business impact into response tiers. A severity matrix supplies those criteria, so different analysts reach the same escalation decision. It also enables meaningful metrics, since severity levels become comparable across incidents and reporting periods.

Exam trap

The trap here is confusing documents that govern vendor or legal relationships with the operational standard needed to classify incident severity.

56
MCQhard

After a patch is deployed to a critical server, the system becomes unstable. The change management plan includes a rollback procedure. What should be done FIRST?

A.Create a new change request for the rollback
B.Conduct a post-implementation review
C.Execute the rollback procedure
D.Notify the Change Advisory Board
AnswerC

Executing the documented rollback restores the unstable server to its last known-good state, immediately containing the outage. The change management plan already authorises this procedure, so it takes precedence over investigation, which can follow once service is restored.

Why this answer

When a patch deployment causes system instability, the immediate priority is to restore service stability by executing the pre-approved rollback procedure. The change management plan already includes this procedure, so no new approvals are needed; acting quickly minimizes downtime and risk.

Exam trap

Candidates may incorrectly think that a new change request is required for the rollback, but the change management plan already includes the rollback procedure, so it can be executed immediately without additional approvals.

How to eliminate wrong answers

Option A is wrong because creating a new change request would introduce unnecessary delay; the rollback is already authorized under the original change plan. Option B is wrong because a post-implementation review is conducted after stability is restored, not during an active incident. Option D is wrong because notifying the Change Advisory Board (CAB) is not the first action; the rollback should be executed immediately, and notification can follow as per the plan.

57
MCQeasy

Which of the following physical security controls is designed to prevent tailgating by requiring two doors to be interlocked?

A.Security guard
B.Biometric reader
C.Mantrap
D.CCTV
AnswerC

A mantrap interposes two interlocked doors so only one opens at a time, holding each person alone in the vestibule before the second door releases. This directly satisfies the requirement to prevent tailgating, since a follower cannot pass through while the first door remains secured.

Why this answer

A mantrap is a physical security control consisting of two interlocking doors that create a small vestibule. Only one door can be opened at a time, preventing an unauthorized person from following an authorized person through a single entry point (tailgating). This design forces each individual to be authenticated before the second door unlocks, ensuring only one person passes per authentication event.

Exam trap

Candidates often mistake a mantrap for a simple turnstile or revolving door, but the defining characteristic of a mantrap is the interlocking mechanism that prevents both doors from opening simultaneously, ensuring only one authenticated person passes at a time.

How to eliminate wrong answers

Option A is wrong because a security guard can deter tailgating through observation but does not mechanically enforce the interlocking of two doors; tailgating can still occur if the guard is distracted. Option B is wrong because a biometric reader authenticates identity but does not physically prevent a second person from slipping through the same door; it lacks the interlocking door mechanism. Option D is wrong because CCTV provides surveillance and recording of tailgating incidents but does not actively prevent the act; it is a detective control, not a preventive one.

58
MCQhard

A security administrator is implementing a new system that will process credit card payments. The organization must comply with PCI DSS. Which of the following controls is specifically required by PCI DSS to protect stored cardholder data?

A.Implementing a web application firewall (WAF) in front of the payment application
B.Encrypting cardholder data at rest using strong cryptography
C.Conducting quarterly external network scans by an Approved Scanning Vendor (ASV)
D.Enforcing a minimum password length of eight characters for all users
AnswerB

PCI DSS requires that stored cardholder data be rendered unreadable, typically through strong encryption, truncation, or tokenization. Encryption at rest is a direct requirement to protect data if storage media is compromised. This control is explicitly mandated and is essential for compliance.

Why this answer

PCI DSS requires that stored cardholder data be protected by rendering it unreadable, commonly through strong encryption. This directly addresses the risk of data exposure from compromised storage. A WAF, ASV scans, and password policies are required or recommended for other aspects of PCI DSS but do not fulfill the specific stored-data protection requirement.

Exam trap

The trap here is selecting a general security control like a WAF or password policy when the question asks specifically about protecting stored cardholder data.

59
Multi-Selecthard

An organization is enhancing its backup strategy. According to the 3-2-1 rule, which THREE characteristics must the backup strategy include? (Select THREE)

Select 3 answers
A.At least two different media types
B.Daily full backups
C.At least one copy stored offsite
D.At least three copies of the data
E.Encryption of all backups
AnswersA, C, D

Two distinct media types ensure a single media failure cannot destroy every copy, satisfying the redundancy element of the 3-2-1 rule. This complements the three copies and one offsite copy the strategy must also include.

Why this answer

The 3-2-1 backup rule requires three copies of the data (option D), meaning the original plus two backups, which ensures redundancy if one copy is lost or corrupted. It also requires at least two different media types (option A), such as disk and tape or local disk and cloud storage, so a single media failure cannot destroy all backups. Finally, it requires at least one copy stored offsite (option C), protecting against site-wide disasters like fire, flood, or theft.

Option B (daily full backups) is a scheduling/retention choice, not part of the 3-2-1 rule, and option E (encryption) is a security best practice but not one of the 3-2-1 characteristics.

Exam trap

Candidates often confuse the 3-2-1 rule with other backup best practices like encryption or frequency. The rule strictly requires: three copies, two different media types, and one offsite copy. Security professionals may mistakenly think daily full backups or encryption are part of the rule, but they are not.

60
MCQeasy

A security administrator needs to ensure that a terminated employee loses access to all systems immediately upon departure. Which action best accomplishes this?

A.Remove the employee from the payroll system only.
B.Schedule the account for deletion at the next quarterly access review.
C.Disable the user account in the central directory and revoke active sessions and tokens.
D.Change the employee's password and notify the manager of the new credential.
AnswerC

Disabling the directory account stops new authentications, while revoking sessions and tokens terminates existing access that would otherwise persist. Together they provide immediate, comprehensive revocation across federated and single sign-on systems. This is the standard offboarding action for prompt access removal.

Why this answer

Immediate access removal requires disabling the identity in the central directory and revoking any active sessions or tokens. Directory disablement blocks new logins across connected systems, and session revocation closes the gap for already-authenticated connections. Password changes, payroll-only removal, or delayed deletion all leave exploitable access in place.

Exam trap

The trap here is believing that changing a password or removing payroll access terminates system access, when active sessions and directory identities remain valid.

61
MCQmedium

A security administrator is reviewing the organization's account management process. The policy states that user accounts must be reviewed at least quarterly to ensure that only authorized individuals retain access. During an audit, it is discovered that several former employees still have active accounts. Which of the following is the MOST appropriate action to address this finding?

A.Immediately disable the accounts and then review the account management process to identify why the accounts were not removed.
B.Delete the accounts and then perform a full audit of all user accounts to ensure no other former employees have access.
C.Document the finding in the audit report and schedule the account removals for the next quarterly review cycle.
D.Reset the passwords on the accounts and notify the former employees' managers to confirm whether access is still needed.
AnswerA

Disabling the accounts immediately removes the unauthorized access risk posed by former employees. Following that, reviewing the process identifies the root cause of the failure to remove accounts, such as a missing trigger from HR, and allows the administrator to implement corrective controls to prevent recurrence. This aligns with the SSCP principle of least privilege and timely access revocation.

Why this answer

The most critical step is to immediately disable the accounts to eliminate the unauthorized access. Then, the administrator should investigate why the accounts were not removed to prevent similar issues. Deleting accounts can destroy evidence and is not best practice; resetting passwords does not revoke access; and delaying action increases risk.

Thus, disabling and then reviewing the process is the correct approach.

Exam trap

The trap here is assuming that resetting passwords or deleting accounts is sufficient, when the primary goal is to revoke access quickly while preserving audit trails and addressing the root cause.

62
Multi-Selecthard

Which THREE of the following are critical elements of a patch management policy? (Select THREE)

Select 3 answers
A.Patch prioritization based on CVSS score and asset criticality
B.Immediate deployment of all patches without testing
C.Annual review of patch status
D.Vulnerability scanning to identify missing patches
E.Testing patches in a staging environment
AnswersA, D, E

Prioritisation using CVSS severity combined with asset criticality directs remediation effort to the most exploitable flaws on the most valuable systems, satisfying the policy's need to sequence patching within limited maintenance windows rather than treating every vulnerability identically.

Why this answer

Option A is correct because a sound patch management policy must rank patches by risk, combining the CVSS base score (e.g., 9.8 Critical) with the business criticality of the affected asset so that the most dangerous exposures on the most important systems are remediated first. Option D is correct because you cannot patch what you have not found; regular authenticated vulnerability scanning (e.g., credentialed scans with Nessus or Qualys) is the mechanism that identifies missing patches and misconfigurations and feeds the remediation workflow. Option E is correct because patches should be validated in a staging or test environment that mirrors production before broad rollout, catching application compatibility and regression issues while still meeting the policy's remediation deadlines.

Option B is not part of a policy because deploying every patch immediately with no testing risks outages and is the opposite of a controlled, risk-based process. Option C is not adequate because reviewing patch status only annually leaves systems exposed for months; effective policies require continuous or at least monthly monitoring and reporting of patch compliance.

Exam trap

In this question, the trap is that candidates might select 'Immediate deployment of all patches without testing' (Option B) or 'Annual review of patch status' (Option C) thinking they are critical elements. However, patch management requires testing, prioritization, and continuous verification, not haphazard deployment or infrequent reviews.

63
Multi-Selectmedium

A financial services firm must demonstrate to auditors that access to its core banking platform follows least privilege and is reviewed regularly. Which TWO practices BEST support this objective? (Choose two.)

Select 2 answers
A.Grant permanent elevated access to any user who requests it to reduce help desk tickets.
B.Implement role-based access control with entitlements mapped to documented job functions.
C.Assign all platform administrators a shared emergency account for routine maintenance.
D.Disable audit logging on the platform to improve performance during peak transaction periods.
E.Conduct periodic user access reviews with business owners certifying each entitlement.
AnswersB, E

Role-based access control ties permissions to defined job functions, so users receive only what their role requires. It makes excessive access easier to spot and simplifies reviews because entitlements are grouped logically. This supports least privilege at scale and gives auditors a clear model showing how access decisions are derived.

Why this answer

Least privilege is sustained through two complementary mechanisms: a design that grants only role-appropriate entitlements, and a recurring review that confirms those grants remain justified. Role-based access control structures the grants, while owner certification validates them over time. Together they produce both the control and the evidence auditors expect.

Exam trap

The trap here is accepting operational shortcuts, such as shared or permanently elevated accounts, as reasonable trade-offs when they actually dissolve the accountability and minimal-access principles being audited.

64
Multi-Selectmedium

A security administrator is implementing the 3-2-1 backup rule. Which THREE actions are required to comply with this rule? (Select THREE.)

Select 3 answers
A.Store one copy offsite
B.Maintain at least three copies of the data
C.Use two different media types (e.g., disk and tape)
D.Perform daily full backups
E.Use encryption for all backup copies
AnswersA, B, C

The 3-2-1 rule's final component requires one copy stored at a separate physical location, protecting against site-level loss such as fire, flood or theft destroying all on-premises backups simultaneously. Offsite storage satisfies that geographic-separation requirement.

Why this answer

The 3-2-1 backup rule requires three things: at least three copies of the data (option B), stored on two different media types (option C), with one copy kept offsite (option A). Option B is correct because the '3' means the original data plus two backup copies, totaling three copies. Option C is correct because the '2' means two distinct media or storage types, such as disk and tape, to avoid a single failure mode.

Option A is correct because the '1' means at least one copy must be stored offsite for disaster recovery. Option D is not required by the rule, since backup frequency is a separate scheduling decision. Option E is also not part of the 3-2-1 rule, as encryption is a security control rather than a copy-count or media requirement.

Exam trap

SSCP often tests the exact components of the 3-2-1 rule, and candidates frequently confuse it with general backup best practices like encryption or daily full backups, which are not part of the rule.

65
MCQmedium

A security administrator receives an alert from the SIEM indicating a configuration change on a critical server. The change was not part of any approved change request. What should be the first step?

A.Investigate the change to determine its source and impact
B.Notify the server owner
C.Revert the server to the last known good configuration
D.Disable the server's network access
AnswerA

Investigating first establishes whether the unapproved configuration change is malicious or accidental and what it affected, which determines the appropriate containment or rollback. This satisfies the stem's requirement to identify the change's source and impact before acting.

Why this answer

The first step when an unauthorized configuration change is detected is to investigate the change to determine its source and impact. This aligns with the incident response process, where initial assessment (identification and scoping) precedes containment or remediation. Without investigation, reverting or disabling could destroy forensic evidence or disrupt legitimate services.

Exam trap

The trap here is that candidates often jump to immediate containment (revert or disable) without recognizing that the first step in incident response is always to verify and scope the incident before taking action.

How to eliminate wrong answers

Option B is wrong because notifying the server owner is premature; the security administrator must first gather information about the change to provide accurate context. Option C is wrong because reverting the server to the last known good configuration could destroy forensic evidence and may not address the root cause, potentially allowing the change to reoccur. Option D is wrong because disabling the server's network access is a containment step that should only be taken after investigation confirms malicious intent or immediate threat, as it could cause unnecessary service disruption.

66
MCQmedium

A security metric shows that patch compliance is at 85%. The goal is 95%. Which action should be taken first?

A.Increase the frequency of vulnerability scans
B.Disable automatic updates to prevent issues
C.Prioritize patching based on vulnerability criticality
D.Exclude non-critical systems from patching
AnswerC

Prioritising by vulnerability criticality directs remediation toward the highest-risk exposures first, satisfying the stem's requirement to close the 10% compliance gap efficiently. Rather than chasing every missing patch equally, risk-based sequencing reduces exploitable attack surface fastest when resources cannot immediately achieve full coverage.

Why this answer

When patch compliance is below target, the first step is to prioritize patching based on vulnerability criticality so that the most exploitable and highest-impact systems are remediated first. This maximizes risk reduction per unit of effort and directly addresses the gap between 85% and 95% by focusing resources where they matter most. Simply scanning more or excluding systems does not improve compliance meaningfully.

Exam trap

The trap is choosing 'increase scanning frequency' because it sounds proactive, when the metric measures patching — candidates must distinguish detection activities from remediation activities.

How to eliminate wrong answers

Option A is wrong because increasing scan frequency identifies vulnerabilities but does not remediate them — compliance is about patching, not detection, so this does not move the metric. Option B is wrong because disabling automatic updates would reduce patch coverage and worsen compliance, directly contradicting the goal. Option D is wrong because excluding non-critical systems from patching artificially inflates the compliance percentage without reducing actual risk, which is a policy violation and a security anti-pattern.

67
MCQmedium

A security administrator is implementing a security awareness training program. The administrator wants to measure the effectiveness of the training in reducing phishing susceptibility. Which of the following metrics would be MOST indicative of the training's success?

A.The total number of phishing emails blocked by the email gateway.
B.The average time taken by employees to complete the training module.
C.The number of phishing emails reported by employees during simulated campaigns.
D.The percentage of employees who completed the training module.
AnswerC

The number of phishing emails reported by employees during simulations directly measures their ability to recognize and respond to phishing attempts. An increase in reporting indicates improved awareness and vigilance. This metric reflects behavioral change, which is the ultimate goal of security awareness training. It is a strong indicator of the training's effectiveness in reducing susceptibility.

Why this answer

To measure the effectiveness of phishing awareness training, the best metric is behavioral. The number of phishing emails reported during simulations shows whether employees are applying what they learned. Completion rate, gateway blocks, and training time do not directly measure reduced susceptibility.

Therefore, reported phishing emails is the most indicative metric.

Exam trap

The trap here is equating training completion or technical blocks with behavioral change, when the real measure of effectiveness is how employees act when faced with a phishing attempt.

68
MCQeasy

A security administrator is tasked with implementing a defense-in-depth strategy for the organization's data center. The administrator wants to ensure that physical access to servers is restricted to authorized personnel only. Which of the following controls should be implemented to achieve this?

A.Install security cameras throughout the data center.
B.Deploy a mantrap at the entrance to the data center.
C.Use raised flooring to protect cabling and improve airflow.
D.Implement biometric authentication for server logins.
AnswerB

A mantrap is a physical security control that consists of a small space with two interlocking doors. It allows only one person to enter at a time and can detect tailgating. By requiring authentication at both doors, it ensures that only authorized personnel can access the data center. This directly restricts physical access to authorized individuals and is a strong preventive control.

Why this answer

To restrict physical access to authorized personnel, a preventive physical control is needed. A mantrap enforces one-person-at-a-time entry and prevents tailgating, directly restricting access. Cameras are detective, biometric server logins are logical, and raised flooring is infrastructural.

Therefore, the mantrap is the correct choice.

Exam trap

The trap here is confusing detective controls like cameras with preventive controls, or logical controls with physical ones, when the requirement is specifically for physical access restriction.

69
MCQeasy

Which of the following is the BEST definition of Recovery Point Objective (RPO)?

A.The cost of data recovery
B.The time it takes to recover data after a disaster
C.The maximum acceptable data loss in terms of time
D.The number of backup copies stored
AnswerC

RPO defines the maximum tolerable data loss measured as elapsed time before the disruption, setting the required backup or replication frequency. This satisfies the definition requested: it expresses how much data, in time terms, the organisation can afford to lose.

Why this answer

Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time, indicating how far back in time the data must be restored to resume operations after a disaster. It directly drives backup frequency and replication intervals, such as setting a 15-minute RPO requiring transaction log backups every 15 minutes in SQL Server or continuous data replication in a SAN environment.

Exam trap

ISC2 often tests the confusion between RPO and RTO, where candidates mistakenly select 'the time it takes to recover data' (RTO) instead of the maximum acceptable data loss in time (RPO).

How to eliminate wrong answers

Option A is wrong because RPO is not a cost metric; cost of data recovery is typically associated with Recovery Cost Objective (RCO) or total cost of ownership, not RPO. Option B is wrong because the time to recover data after a disaster is defined as Recovery Time Objective (RTO), not RPO; RTO focuses on downtime duration, while RPO focuses on data loss tolerance. Option D is wrong because the number of backup copies stored relates to backup retention policies or the 3-2-1 rule, not RPO; RPO is a time-based metric, not a count of copies.

70
MCQhard

A patch management process is being audited. Which finding indicates a critical gap in the process?

A.Exception requests for unpatched systems are documented
B.Patches are not tested in a staging environment before production deployment
C.Critical systems are patched monthly
D.Patches are deployed within 30 days of release
AnswerB

Deploying untested patches straight to production risks breaking critical systems and forces emergency rollback, so defects escape detection. Staging validation is the control that catches compatibility and regression issues before they affect live services, making its absence a critical process gap.

Why this answer

A patch management process must include testing patches in a staging environment before production deployment to validate compatibility and avoid breaking critical systems. Without staging validation, patches can introduce regressions, incompatibilities, or outages in production. This is a critical gap because it removes the safety net that catches patch-related issues before they impact live operations.

Exam trap

SSCP often tests whether candidates confuse 'documented exceptions' or 'monthly patching' with process gaps — the real gap is skipping pre-production validation, not the cadence or documentation.

How to eliminate wrong answers

Option A is wrong because documenting exception requests for unpatched systems is actually a sign of a mature process — exceptions should be tracked and approved. Option C is wrong because patching critical systems monthly is a reasonable cadence for many environments and does not by itself indicate a critical gap. Option D is wrong because deploying patches within 30 days of release is a common and acceptable SLA for non-emergency patches, not a critical flaw.

71
Multi-Selecthard

Which THREE of the following are valid steps in the change management process? (Select THREE)

Select 3 answers
A.Post-implementation review
B.Vulnerability scanning
C.Baseline configuration update
D.Impact assessment
E.Change request submission
AnswersA, D, E

A post-implementation review closes the change management lifecycle by verifying the change achieved its intended outcome and identifying any unanticipated effects. It is a recognised procedural step, distinct from implementation itself, and satisfies the stem's requirement for a valid change process stage.

Why this answer

Option E (Change request submission) is correct because the change management process formally begins when a Request for Change (RFC) is submitted and logged, often via a ticketing or ITSM system, so the change can be reviewed and authorized. Option D (Impact assessment) is correct because after the RFC is raised, the change advisory board or reviewers evaluate risk, scope, affected systems, and potential downtime to decide whether the change should be approved. Option A (Post-implementation review) is correct because after the change is deployed, the process includes verifying that it achieved its objective, did not cause unintended issues, and capturing lessons learned for future changes.

Option B (Vulnerability scanning) is not a change management step; it is a security assessment activity typically performed under vulnerability management, even though its findings may trigger an RFC. Option C (Baseline configuration update) is not a step in the change management process itself; updating the configuration baseline is a configuration management activity that occurs after an approved change is implemented.

Exam trap

The trap here is that candidates may confuse operational security activities like vulnerability scanning or configuration updates with formal change management process steps, which are specifically about the lifecycle of a change request from submission through review.

72
MCQmedium

A security administrator is reviewing audit logs and discovers that a user account with administrative privileges was used to access a file server outside of normal business hours. The administrator needs to determine whether this access was authorized. Which of the following should the administrator do FIRST?

A.Escalate the incident to law enforcement as a potential breach
B.Review the change management records and on-call schedule for that time period
C.Contact the user to ask whether they performed the access
D.Disable the administrative account immediately to prevent further access
AnswerB

Checking change management records and on-call schedules provides context to determine if the access was planned or expected. This is a non-intrusive first step that can quickly validate or refute the need for further investigation. It preserves evidence and avoids disrupting operations prematurely.

Why this answer

The first step in investigating suspicious access is to gather context from non-intrusive sources such as change management and on-call schedules. This helps determine if the access was authorized without disrupting operations or alerting a potential insider. Disabling accounts, contacting users, or escalating externally should come after initial verification.

Exam trap

The trap here is jumping to containment or notification before verifying whether the activity was legitimate; always gather context first.

73
MCQmedium

A security administrator is reviewing the organization's data retention policy. The policy states that customer financial records must be kept for seven years, but the IT team currently archives them indefinitely. Which action should the administrator take to align data handling with the policy while preserving records for legal discovery?

A.Delete all archived financial records immediately to reduce the organization's data footprint.
B.Configure the archival system to apply a retention period of seven years and automatically purge records after that period.
C.Move the archived records to a lower-cost storage tier and continue retaining them indefinitely.
D.Reclassify financial records as public so they are exempt from retention requirements.
AnswerB

Setting a seven-year retention with automatic purge directly enforces the documented policy and limits unnecessary data exposure. It satisfies legal hold requirements during the retention window while reducing storage and breach impact afterward. This is the corrective action that brings technical controls in line with the approved data retention policy.

Why this answer

The correct action is to enforce the documented seven-year retention with automatic purge. That aligns operational data handling with policy, reduces long-term breach impact, and still preserves records during the required legal window. Indefinite retention, immediate deletion, or reclassification all fail to meet the policy's specific retention requirement.

Exam trap

The trap here is assuming that reducing storage cost or reclassifying data satisfies a retention policy, when the policy actually requires a specific retention duration and purge.

74
MCQeasy

A security administrator needs to ensure that only authorized devices can connect to the corporate wireless network. Which of the following should be implemented to meet this requirement?

A.WPA2-Enterprise with 802.1X
B.MAC address filtering
C.SSID broadcasting disabled
D.Pre-shared key (PSK) authentication
AnswerA

WPA2-Enterprise with 802.1X provides strong, certificate-based or credential-based authentication for each device or user before network access is granted. It ensures that only authorized devices with valid credentials can connect, and it supports dynamic key management. This meets the requirement for strict device authorization.

Why this answer

WPA2-Enterprise with 802.1X authenticates each device or user individually, typically against a RADIUS server, before granting network access. This ensures that only authorized devices can connect. MAC filtering, PSK, and SSID hiding are either weak or do not provide per-device authorization.

Exam trap

The trap here is assuming that hiding the SSID or using MAC filtering provides strong access control, when both are easily bypassed.

75
MCQmedium

A security awareness training program aims to reduce successful phishing attacks. Which metric is most appropriate for measuring the effectiveness of this training?

A.Percentage of employees who click simulated phishing links
B.Training completion rate
C.Number of reported phishing emails
D.Number of security incidents caused by phishing
AnswerA

Click rate on simulated phishing links directly measures whether employees apply the training, since clicking is the behaviour the programme targets. It satisfies the stem's effectiveness requirement by quantifying real susceptibility rather than completion or awareness, which do not prove reduced phishing success.

Why this answer

The percentage of employees who click simulated phishing links is the most appropriate metric because it directly measures the behavior the training aims to change—whether employees can recognize and avoid phishing attempts. A decrease in click rate over time indicates improved awareness and reduced susceptibility. This is a direct, outcome-based measure of training effectiveness, unlike completion rates which only show participation.

Exam trap

The trap here is confusing activity metrics (like completion rate) with outcome metrics (like click rate). Candidates often pick completion rate because it's easy to measure, but the exam expects you to choose the metric that directly reflects the training's goal: reducing successful phishing attacks.

How to eliminate wrong answers

Option B is wrong because training completion rate measures participation, not whether employees actually learned to avoid phishing; someone can complete training and still click a malicious link. Option C is wrong because the number of reported phishing emails can be influenced by many factors (e.g., increased attack volume, reporting culture) and does not directly measure whether employees avoid clicking; in fact, more reports could indicate better awareness but doesn't prove reduced susceptibility. Option D is wrong because the number of security incidents caused by phishing is a lagging indicator and may be affected by other controls (e.g., email filters, endpoint protection); it does not isolate the effect of training.

Page 1 of 2 · 93 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Sscp Security Ops questions.