Courseiva

CCNA Sscp Security Ops Questions

18 of 93 questions · Page 2/2 · Sscp Security Ops topic · Answers revealed

76
MCQmedium

A company wants to track all hardware assets including serial numbers and locations. What is the primary repository for this information?

A.CMDB
B.Patch management tool
C.Vulnerability database
D.SIEM
AnswerA

A CMDB provides the authoritative repository for hardware assets, recording serial numbers, locations and configuration items with their relationships. It directly satisfies the requirement to track all hardware assets, unlike an asset inventory limited to listing, because the CMDB maintains configuration item attributes and interdependencies across the IT estate.

Why this answer

A Configuration Management Database (CMDB) is the authoritative repository for recording configuration items (CIs) such as hardware assets, their serial numbers, locations, owners, relationships, and lifecycle states. It underpins ITIL/ITSM processes like change, incident, and asset management. Tracking hardware serial numbers and physical locations is a canonical CMDB use case.

Exam trap

SSCP often tests the confusion between a CMDB and a SIEM or vulnerability database — candidates must recognize that asset attributes like serial number and location belong to configuration/asset management, not security event or vulnerability tracking.

How to eliminate wrong answers

Option B is wrong because a patch management tool tracks patch status and software versions on endpoints, not comprehensive hardware asset attributes like serial numbers and physical locations. Option C is wrong because a vulnerability database (e.g., NVD) catalogs known CVEs and weaknesses, not an organization's own hardware inventory. Option D is wrong because a SIEM aggregates and correlates log and event data for security monitoring; it does not serve as the system of record for hardware assets.

77
MCQeasy

A security administrator is reviewing the account lifecycle process for a large retail company. An employee in the accounting department has been promoted to a role in the same department that requires access to the payroll system, while the employee's previous duties no longer require access to the accounts payable system. Which action should the administrator take to ensure least privilege is maintained?

A.Modify the existing account to grant payroll access and remove the accounts payable access.
B.Disable the existing account and require the employee to request a new account through the help desk.
C.Create a new account for the payroll role and disable the old accounts payable account after 30 days.
D.Leave both sets of access in place so the employee can assist the accounting team during the transition.
AnswerA

Least privilege requires that an account hold only the access needed for current job duties. Since the employee remains with the company but changed roles, the existing identity should be retained and its entitlements adjusted by adding payroll access and removing accounts payable access. This keeps the account lifecycle accurate and prevents accumulation of unnecessary privileges.

Why this answer

Because the employee remains with the organization but changed job duties, the account should be modified to add the payroll entitlement and remove the accounts payable entitlement. This maintains least privilege, preserves the identity history, and avoids both account sprawl and lingering unnecessary access. The other choices either retain excessive rights, create redundant identities, or disrupt a current employee's access.

Exam trap

The trap here is assuming that a role change requires a new account or a full deprovisioning, when least privilege is achieved by adjusting entitlements on the existing identity.

78
MCQeasy

Which of the following is the PRIMARY purpose of implementing a clean desk policy?

A.To lower office cleaning costs
B.To comply with fire safety regulations
C.To reduce the risk of data breaches
D.To improve employee productivity
AnswerC

Unattended documents, unlocked screens and exposed media let anyone with physical access copy or photograph sensitive data. A clean desk policy removes that opportunistic exposure, directly lowering the likelihood of a data breach rather than merely improving tidiness or audit compliance.

Why this answer

A clean desk policy is a physical security control designed to prevent unauthorized access to sensitive information by ensuring that documents, devices, and media are securely stored when not in use. By reducing the visibility of confidential data, it directly mitigates the risk of data breaches from shoulder surfing, theft, or accidental exposure. This aligns with the principle of least exposure and supports compliance with data protection frameworks like GDPR or HIPAA.

Exam trap

The trap here is that candidates confuse a clean desk policy with general workplace organization or fire safety, overlooking its core role as a physical security control to protect confidential data from unauthorized access.

How to eliminate wrong answers

Option A is wrong because a clean desk policy does not target cleaning costs; it is a security measure, not a housekeeping budget control. Option B is wrong because while a clean desk may indirectly reduce fire hazards by clearing clutter, fire safety regulations are primarily addressed by fire codes, extinguisher placement, and egress paths, not by a policy focused on information security. Option D is wrong because although a tidy workspace can boost morale, the primary purpose of a clean desk policy is security, not productivity improvement.

79
MCQmedium

A security administrator is reviewing the organization's security awareness training program. The administrator wants to measure whether employees can recognize and report phishing emails. Which metric BEST measures the effectiveness of the training?

A.Number of employees who completed the training module
B.Percentage of simulated phishing emails that were reported by employees
C.Number of phishing emails blocked by the email gateway
D.Percentage of employees who clicked on simulated phishing emails
AnswerB

The reporting rate directly measures whether employees recognized simulated phishing emails and took the correct action to report them. This metric reflects both recognition and the desired behavior. It is the most direct indicator of the training's effectiveness in achieving its goal.

Why this answer

The percentage of simulated phishing emails reported by employees directly measures both recognition and the desired reporting behavior. It reflects whether training has successfully taught employees to identify and act on phishing attempts. Other metrics measure participation, susceptibility, or technical blocking, which do not fully capture the training's effectiveness.

Exam trap

The trap here is choosing click rate or completion rate, which measure susceptibility or participation, instead of the reporting rate that directly reflects recognition and response.

80
MCQeasy

Which backup type copies all data that has changed since the last full backup, regardless of any incremental backups?

A.Synthetic full backup
B.Full backup
C.Differential backup
D.Incremental backup
AnswerC

A differential backup captures every change made since the last full backup, ignoring any incremental backups taken in between. This directly satisfies the stem's constraint of copying all data changed since the last full backup regardless of incrementals, because each differential accumulates changes cumulatively rather than resetting after each incremental run.

Why this answer

A differential backup copies all data that has changed since the last full backup, regardless of any intermediate incremental backups. This means each differential backup grows in size as it accumulates all changes made after the last full backup, making it distinct from incremental backups which only capture changes since the last backup of any type.

Exam trap

The trap here is that candidates often confuse differential backups with incremental backups, but the key differentiator is the reference point: differential backs up all changes since the last full backup, while incremental backs up changes since the last backup of any type.

How to eliminate wrong answers

Option A is wrong because a synthetic full backup is a logical reconstruction of a full backup from previous full and incremental backups, not a backup type that copies changed data since the last full backup. Option B is wrong because a full backup copies all data, not just the data that has changed since the last full backup. Option D is wrong because an incremental backup copies only data that has changed since the last backup (which could be full, differential, or incremental), not specifically since the last full backup.

81
MCQhard

A security administrator is implementing a mandatory vacation policy for employees in sensitive roles. The administrator needs to ensure that the policy supports the detection of fraudulent activities. Which control should be implemented alongside mandatory vacations to maximize its effectiveness?

A.Security awareness training
B.Acceptable use policy
C.Job rotation
D.Background checks
AnswerC

Job rotation requires other employees to perform the duties of a role, which increases the chance of detecting fraud or errors that a single individual might conceal. Combined with mandatory vacations, it ensures that another person gains visibility into the role's transactions. This dual control strengthens detection and deterrence.

Why this answer

Job rotation ensures that multiple employees perform the same duties, increasing the likelihood that fraudulent transactions or irregularities are noticed. When paired with mandatory vacations, it removes the single-person dependency that allows fraud to remain hidden. This combination is a classic segregation of duties and detective control pairing.

Exam trap

The trap here is selecting a preventive or educational control like background checks or training, when the scenario requires a detective control that provides ongoing oversight to uncover fraud.

82
Multi-Selecthard

A security administrator is conducting a risk assessment for a new cloud-based application. The administrator needs to identify TWO factors that are most important when determining the appropriate security controls for the application. (Choose two.)

Select 2 answers
A.The regulatory requirements applicable to the data
B.The physical location of the cloud provider's data center
C.The programming language used to develop the application
D.The sensitivity of the data processed by the application
E.The number of users who will access the application
AnswersA, D

Regulations such as GDPR, HIPAA, or PCI DSS mandate specific controls for certain data types. Compliance obligations directly dictate encryption, auditing, retention, and access requirements. Ignoring them can result in legal penalties, so they are a critical factor in choosing controls for the application.

Why this answer

Data sensitivity and regulatory requirements are the two most important factors because they define the impact of a breach and the mandatory controls. Sensitivity drives risk-based decisions, while regulations impose specific obligations. User count, programming language, and data center location are secondary and do not directly determine the appropriate security controls.

Exam trap

The trap here is selecting user count or location as primary factors; they are relevant but not as fundamental as data sensitivity and compliance obligations.

83
MCQmedium

During a change management process, the Change Advisory Board (CAB) has approved a change to update a critical database server. After implementation, a rollback is necessary due to unforeseen performance issues. What should the change manager do next?

A.Execute the rollback plan and schedule a post-implementation review
B.Leave the server in its current state and escalate to the CAB for a decision
C.Patch the server with the latest updates to resolve the performance issue
D.Submit a new change request for the rollback and await CAB approval
AnswerA

The rollback plan is the pre-approved reversal path, so executing it restores the database to its last known-good state and limits disruption. Scheduling a post-implementation review then captures why performance issues arose, feeding lessons back into future change assessments.

Why this answer

The change was already approved by the CAB, and the rollback plan is a pre-approved contingency within the original change request. Executing the rollback immediately restores service stability, and scheduling a post-implementation review (PIR) captures lessons learned and ensures compliance with the change management policy. This aligns with ITIL best practices, where rollback is part of the implementation plan and does not require a new change request.

Exam trap

The trap here is that candidates mistakenly think any rollback requires a new change request, but the rollback plan is already part of the approved change, so immediate execution is permitted without further CAB approval.

How to eliminate wrong answers

Option B is wrong because leaving the server in a degraded state violates the principle of restoring service as quickly as possible, and escalating to the CAB for a decision introduces unnecessary delay when a pre-approved rollback plan exists. Option C is wrong because patching the server with latest updates is an unapproved change that bypasses the change management process and could introduce further instability or security issues. Option D is wrong because submitting a new change request for the rollback is redundant and inefficient; the rollback plan was already approved as part of the original change, so immediate execution is authorized without additional CAB approval.

84
MCQmedium

An organization uses a SIEM to alert when a server's configuration changes from its hardened baseline. This is an example of:

A.Deviation detection
B.Patch management
C.Vulnerability scanning
D.Asset management
AnswerA

Deviation detection compares current system state against a defined baseline and raises alerts on any divergence, which is precisely what the SIEM performs when a server's configuration drifts from its hardened state. It satisfies the stem's constraint of detecting configuration changes rather than preventing them or scanning for known malware signatures.

Why this answer

SIEM alerts on configuration changes from baseline are a form of deviation detection, which is part of configuration management.

85
MCQmedium

A security administrator is implementing a solution to detect unauthorized changes to critical system files on a server. Which of the following technologies is BEST suited for this purpose?

A.Security information and event management (SIEM)
B.Intrusion detection system (IDS)
C.File integrity monitoring (FIM)
D.Data loss prevention (DLP)
AnswerC

File integrity monitoring (FIM) tools compute cryptographic hashes of critical files and alert when changes occur. This directly detects unauthorized modifications. FIM is designed for this purpose, providing real-time or scheduled checks. It is the best fit for detecting changes to system files.

Why this answer

File integrity monitoring is specifically designed to detect unauthorized changes to files by comparing current hashes to known good baselines. It provides alerts when critical system files are modified, making it the best choice for this requirement.

Exam trap

The trap here is confusing general monitoring tools like SIEM or IDS with specialized file integrity monitoring.

86
Multi-Selecthard

A security administrator is implementing a formal data retention and destruction program for a financial services firm. The firm stores customer records, transaction logs, and email archives on a variety of media, including solid-state drives, magnetic tapes, and cloud object storage. Which TWO practices should the administrator include to ensure data is destroyed in a manner that is both effective and auditable? (Choose two.)

Select 2 answers
A.Define retention periods by data category and apply destruction only after the retention period expires and any legal hold is released.
B.Delegate all destruction activities to the cloud service provider and rely on the provider's standard terms of service for assurance.
C.Use the same overwriting utility on all media types to simplify the destruction procedure and reduce training requirements.
D.Maintain a certificate of destruction that records the media type, serial number, method used, date, and the personnel who performed the destruction.
E.Store all media in a locked room after the retention period expires until the media can be reused for other purposes.
AnswersA, D

Retention periods must be tied to legal, regulatory, and business requirements for each data category, and destruction should occur only after those periods end and any litigation hold is lifted. Destroying data too early can violate regulations or spoliation rules, while retaining it too long increases breach exposure. This practice ensures destruction is lawful, consistent, and defensible during audits or legal proceedings.

Why this answer

An effective destruction program pairs documented retention rules with verifiable destruction evidence. Retention periods must reflect legal and business requirements, with destruction delayed until holds are released. Certificates of destruction provide the audit trail that proves media was destroyed properly.

Using one overwrite tool for all media, delegating without assurance, or merely storing expired media fails to deliver either effective destruction or the documentation auditors require.

Exam trap

The trap here is assuming a single overwriting method works on every media type and that a cloud provider's default terms are sufficient evidence of destruction.

87
MCQhard

A security administrator is prioritizing patches for a vulnerability with a CVSS score of 9.8 that is being actively exploited in the wild. The affected server has a low criticality classification. What should the administrator do?

A.Apply the patch immediately without change management
B.Ignore the patch because the server is low criticality
C.Wait for the next scheduled patch cycle
D.Prioritize patching via the change management process
AnswerD

Active exploitation plus a CVSS of 9.8 outweighs the server's low criticality, so the patch must be expedited. Routing it through change management satisfies the stem by ensuring the urgent fix is deployed under controlled, documented approval rather than bypassing governance entirely.

Why this answer

Even though the server is low criticality, a CVSS score of 9.8 with active exploitation represents an urgent risk that must be addressed. The administrator should prioritize patching through the change management process to ensure proper approval, testing, and documentation while still expediting the fix.

Exam trap

SSCP often tests the misconception that low asset criticality justifies ignoring critical vulnerabilities—candidates may pick 'ignore' or 'wait' without considering active exploitation and lateral movement risk.

How to eliminate wrong answers

Option A is wrong because bypassing change management entirely creates audit, compliance, and operational risks; emergency changes still require some form of change control. Option B is wrong because ignoring the patch is negligent—active exploitation means the risk is real regardless of server criticality, and the server could be a pivot point. Option C is wrong because waiting for the next scheduled patch cycle leaves the organization exposed to an actively exploited vulnerability, which is unacceptable.

88
Multi-Selectmedium

Which TWO of the following are valid reasons to deny a change request during the CAB approval process?

Select 2 answers
A.The change is outside the approved budget
B.The change request lacks a rollback plan
C.The change has a low priority
D.The change has not been tested in a staging environment
E.The change was requested by a junior staff member
AnswersB, D

Without a documented rollback plan, the CAB cannot verify the change is reversible if it fails, leaving no safe recovery path. This directly violates change management's requirement that every approved change carry a tested backout strategy.

Why this answer

Option B is correct because a change request without a rollback plan presents an unacceptable risk: if the change fails in production, the organization has no defined, tested way to revert to the prior known-good state, so the CAB should deny it until a rollback (backout) plan is documented. Option D is correct because untested changes have unverified behavior and unknown failure modes; the CAB should deny approval until the change has been validated in a staging environment that mirrors production, satisfying change validation and testing requirements. Option A is not a valid denial reason in itself, since budget is a financial approval matter handled separately from CAB risk assessment, and a change can still be technically sound.

Option C is not valid because low priority affects scheduling and sequencing, not approval; a low-priority change can still be approved and deferred. Option E is not valid because the requester's seniority is irrelevant — the CAB evaluates the change's risk, impact, and readiness, not who submitted it.

Exam trap

In the SSCP exam, the pitfall is confusing administrative or financial reasons (budget, priority, requester seniority) with operational risk factors (lack of rollback plan, no staging test). The CAB's primary focus is on operational risk and technical feasibility, so only items affecting the change's safety and reliability are valid grounds for denial.

89
MCQeasy

Which of the following is the primary purpose of a configuration management database (CMDB)?

A.To provide a centralized repository of configuration items and their relationships
B.To track changes to network devices in real time
C.To automate the deployment of patches
D.To store backup copies of configuration files
AnswerA

A CMDB stores configuration items and the dependencies linking them, giving change and incident teams the impact visibility they need. This centralised record of assets and their relationships is precisely the repository function the question asks for, rather than monitoring, ticketing or licence tracking.

Why this answer

A configuration management database (CMDB) is a centralized repository that stores information about configuration items (CIs) and their relationships. Its primary purpose is to provide a single source of truth for managing IT assets, dependencies, and their interconnections, which is foundational for change management, incident management, and impact analysis.

Exam trap

In the SSCP exam, candidates may confuse the CMDB's role as a metadata repository with operational tools like change tracking systems or backup solutions. A CMDB is a vendor-neutral concept that stores configuration item data and relationships to support decision-making.

How to eliminate wrong answers

Option B is wrong because tracking changes to network devices in real time is a function of network monitoring tools (e.g., SNMP traps, NetFlow) or change detection systems, not the primary purpose of a CMDB. Option C is wrong because automating patch deployment is the role of patch management systems (e.g., WSUS, SCCM), while a CMDB stores CI data but does not execute deployment actions. Option D is wrong because storing backup copies of configuration files is a function of backup and version control systems (e.g., RANCID, Git), whereas a CMDB focuses on metadata and relationships, not file-level backups.

90
MCQmedium

A security administrator needs to dispose of hard drives that contain sensitive data. Which method provides the highest assurance that data cannot be recovered?

A.Deleting all files and emptying the recycle bin
B.Performing a quick format of the drive
C.Physically shredding the hard drives
D.Using a degausser to erase magnetic data
AnswerC

Physical shredding reduces the drive to fragments, so platters and controller chips cannot be read by any laboratory technique. Degaussing leaves solid-state media and some high-coercivity platters intact, and overwriting can miss bad sectors. Shredding therefore satisfies the stem's demand for the highest assurance of unrecoverable data.

Why this answer

Physically shredding the hard drives reduces them to small particles, making any recovery of magnetic or solid-state data physically impossible. This provides the highest level of assurance because the storage media itself is destroyed, not just the data on it. It is the recommended method for media containing highly sensitive data when reuse is not required.

Exam trap

The trap here is confusing 'erasing' with 'destroying' — candidates often pick degaussing because it sounds technical, but it does not provide the same assurance as physical shredding, especially for SSDs.

How to eliminate wrong answers

Option A is wrong because deleting files and emptying the recycle bin only removes file system references; the underlying data blocks remain intact and are easily recoverable with forensic tools. Option B is wrong because a quick format only rewrites the file system metadata and leaves the actual data sectors untouched, so recovery is still possible. Option D is wrong because a degausser only works on magnetic media and renders the drive unusable; it does not affect SSDs, and it provides less assurance than physical destruction because some high-coercivity drives may retain residual data.

91
MCQmedium

An organization needs to recover data from a backup after a ransomware attack. The backup was taken 12 hours ago, and the RPO is 4 hours. What is the impact?

A.The RPO is met because data can be recovered
B.The RPO is violated because more than 4 hours of data may be lost
C.The RTO is exceeded
D.The 3-2-1 rule is violated
AnswerB

A 12-hour-old backup means up to 12 hours of data could be lost, exceeding the 4-hour RPO. The recovery point objective defines maximum tolerable data loss, so this gap violates it regardless of restore speed. The impact is therefore an RPO breach.

Why this answer

RPO (Recovery Point Objective) defines the maximum acceptable data loss. If the backup is 12 hours old and RPO is 4 hours, the organization has lost 8 hours of data, exceeding the objective.

92
Multi-Selectmedium

Which TWO controls are examples of physical security controls that can help prevent unauthorized access to a data center? (Select TWO.)

Select 2 answers
A.Biometric readers
B.Encryption of data at rest
C.Mantraps
D.Firewalls
E.Intrusion detection system (IDS)
AnswersA, C

Biometric readers verify a unique physiological trait, such as a fingerprint or iris pattern, before releasing the door strike. Unlike a badge, credentials cannot be lent or duplicated, so the control satisfies the stem's requirement to prevent unauthorised access at the data centre perimeter.

Why this answer

Biometric readers (A) are physical security controls because they authenticate a person via a unique physical trait such as a fingerprint, iris, or retina before granting entry to the data center, directly preventing unauthorized physical access. Mantraps (C) are also physical controls: they use two interlocking doors with a small vestibule to allow only one person through at a time, preventing tailgating and piggybacking into the facility. Encryption of data at rest (B) is a logical/cryptographic control that protects data confidentiality but does not stop someone from physically entering the data center.

Firewalls (D) are logical network security controls that filter traffic, not physical access controls. An intrusion detection system (E) is a logical monitoring/detection control that alerts on malicious activity but does not physically prevent unauthorized entry.

Exam trap

The trap here is that candidates often confuse 'physical security controls' with 'technical/administrative controls'—for example, selecting encryption or firewalls because they 'secure' the data center, but they do not prevent physical entry.

93
MCQeasy

A payroll administrator at a healthcare company resigns. On her last day, the security team must ensure she can no longer access the HR payroll application, but her mailbox must remain active for 30 days so her manager can review pending correspondence. Which access management action BEST meets these requirements?

A.Change the user's password and share the new credential with her manager.
B.Delete the user account immediately after her last shift.
C.Terminate the payroll application entitlement while retaining the account for mailbox access during the review period.
D.Disable the user account and leave it disabled indefinitely.
AnswerC

Removing the payroll entitlement eliminates the risk that matters most, while the account and mailbox stay available for the 30-day review. This follows least privilege by revoking only the access no longer needed. A defined end date should be recorded so the account is disabled or deleted once the review completes.

Why this answer

Deprovisioning should remove the entitlements tied to the former role while preserving what the business still needs. Revoking the payroll application access addresses the security risk, and keeping the account for a bounded mailbox review satisfies the operational requirement. Documenting the end date prevents the account from lingering past its purpose.

Exam trap

The trap here is treating account termination as all-or-nothing, when entitlements can be revoked selectively while the account remains active for a defined purpose.

← PreviousPage 2 of 2 · 93 questions total

Ready to test yourself?

Try a timed practice session using only Sscp Security Ops questions.