Courseiva

CCNA Sscp Systems App Security Questions

75 of 101 questions · Page 1/2 · Sscp Systems App Security topic · Answers revealed

1
MCQmedium

A cloud security team wants to continuously monitor for misconfigured cloud resources that could expose data. Which tool category is specifically designed for this purpose?

A.Cloud Workload Protection Platform (CWPP)
B.Identity and Access Management (IAM)
C.Cloud Security Posture Management (CSPM)
D.Web Application Firewall (WAF)
AnswerC

Cloud Security Posture Management continuously scans cloud infrastructure for misconfigurations, comparing deployed resource settings against security baselines and compliance frameworks. It directly satisfies the stem's requirement for ongoing detection of exposed data risks, unlike CWPP (workload protection) or CASB (access control), which address different layers.

Why this answer

CSPM (Cloud Security Posture Management) tools detect misconfigurations like open storage buckets or overly permissive IAM roles. CWPP focuses on runtime workload protection. WAF protects web apps.

IAM manages identities, not configuration monitoring.

2
MCQeasy

A company is implementing application whitelisting on all endpoints. Which of the following is a primary consideration for maintaining operational efficiency?

A.Ensuring that all users have local administrator rights
B.Deploying a host-based firewall on each endpoint
C.Establishing a process to add approved applications to the whitelist
D.Disabling Windows Defender Antivirus to reduce resource usage
AnswerC

Whitelisting only permits explicitly approved executables, so any legitimate business application not yet listed is blocked. A defined approval process lets administrators vet and add new or updated software promptly, preserving user productivity while keeping the default-deny posture intact.

Why this answer

Application whitelisting only allows approved applications to run. To maintain operational efficiency, organizations must have a streamlined process to review and add new or updated applications to the whitelist as business needs evolve. Without this, users may be blocked from necessary tools, causing productivity loss.

Exam trap

SSCP often tests the misconception that whitelisting is a set-and-forget control, ignoring the need for ongoing management and user support to avoid operational disruptions.

How to eliminate wrong answers

Option A is wrong because granting local administrator rights undermines whitelisting by allowing users to bypass restrictions. Option B is wrong because a host-based firewall controls network traffic, not application execution, and does not address whitelist maintenance. Option D is wrong because disabling antivirus reduces security and does not relate to whitelisting efficiency.

3
MCQeasy

An organization uses Infrastructure as a Service (IaaS) in the public cloud. Which of the following security responsibilities is the customer responsible for?

A.Network infrastructure security
B.Hypervisor security and patching
C.Operating system security and patch management
D.Physical security of the data center
AnswerC

In IaaS the provider secures the physical hosts, hypervisor and network fabric, but the guest operating system remains the customer's layer. Patching, hardening and OS-level controls therefore fall to the customer, satisfying the stem's IaaS responsibility split.

Why this answer

In IaaS, the customer is responsible for securing the operating system, including patch management, because the provider only manages the hypervisor and physical infrastructure. Operating system security and patching is therefore a customer responsibility. The other options are provider responsibilities in IaaS.

Exam trap

The trap is assuming the provider patches everything in IaaS — candidates forget that the customer owns the guest OS, so OS patching remains a customer duty even though the hypervisor is provider-managed.

How to eliminate wrong answers

Option A is wrong because network infrastructure security (physical network, routers, switches) is managed by the cloud provider in IaaS. Option B is wrong because hypervisor security and patching is always the provider's responsibility, as the customer has no access to the hypervisor. Option D is wrong because physical security of the data center is entirely the provider's responsibility in a public cloud.

4
MCQmedium

A security analyst is reviewing an application that accepts a user-supplied file path and uses it to read a configuration file from disk. The analyst observes that a user can enter ../../etc/passwd and the application returns the contents of that system file. Which of the following best describes this vulnerability?

A.Server-side request forgery
B.Insecure direct object reference
C.Path traversal
D.Cross-site scripting
AnswerC

Path traversal, also called directory traversal, occurs when user-supplied input containing sequences like ../ is used to access files outside the intended directory. The analyst's observation that ../../etc/passwd returns a system file demonstrates exactly this flaw. The application fails to validate or normalize the path, allowing access to arbitrary files readable by the process.

Why this answer

The ability to enter ../ sequences and retrieve a file outside the intended directory is the defining behavior of path traversal. The application fails to canonicalize and validate the supplied path, allowing access to files such as /etc/passwd. The other choices describe client-side script injection, object identifier manipulation, or forced server requests, none of which match the observed file-read behavior.

Exam trap

The trap here is confusing any unauthorized file or data access with insecure direct object reference, when the distinguishing feature of path traversal is the use of relative path sequences to escape the intended directory.

5
MCQhard

A security operations team suspects that an attacker has compromised a Linux web server and is maintaining persistence. The team wants to identify unauthorized scheduled tasks that survive reboots. Which set of locations should the team review FIRST?

A.The /etc/hosts file and the resolver configuration in /etc/resolv.conf.
B.The systemd timer units, cron tables in /etc/cron* and /var/spool/cron, and the /etc/rc.local startup script.
C.The bash history files in each user's home directory.
D.The /var/log/auth.log and /var/log/secure authentication logs.
AnswerB

On modern Linux, persistence that survives reboot is typically implemented through systemd timers, user and system cron entries, or legacy startup scripts such as rc.local. Reviewing these locations directly targets mechanisms that re-launch malicious code after a restart, making this the correct first step for identifying reboot-surviving persistence.

Why this answer

Reboot-surviving persistence on Linux resides in scheduled execution mechanisms such as systemd timers, cron directories, and legacy startup scripts. These are the components that automatically run code after a restart. Name resolution files, shell history, and authentication logs are valuable for context and detection but do not themselves relaunch an implant.

Exam trap

The trap here is equating general incident-response artifacts such as logs and shell history with persistence mechanisms, when only scheduled execution structures survive a reboot.

6
Multi-Selectmedium

A security analyst is reviewing a web application that stores user session identifiers in cookies. The analyst wants to recommend cookie attributes that reduce the risk of session hijacking through cross-site scripting (XSS) and cross-site request forgery (CSRF). Which TWO of the following cookie attributes should the analyst recommend? (Choose two.)

Select 2 answers
A.Max-Age
B.Domain
C.SameSite
D.HttpOnly
E.Secure
AnswersC, D

The SameSite attribute controls whether the browser sends the cookie with cross-site requests. Setting SameSite to Lax or Strict prevents the cookie from being included in requests originating from other sites, which blocks CSRF attacks. This directly addresses the CSRF concern and complements HttpOnly for XSS protection, making it one of the two correct recommendations.

Why this answer

HttpOnly prevents JavaScript from reading the session cookie, mitigating session theft via XSS. SameSite restricts the browser from sending the cookie on cross-site requests, mitigating CSRF. Together they address both threats named in the scenario.

Secure, Domain, and Max-Age provide other benefits but do not directly counter XSS cookie theft or CSRF in the way the analyst requires.

Exam trap

The trap here is selecting Secure as a mitigation for XSS, when Secure only protects cookies in transit and does not stop client-side script access.

7
Multi-Selecteasy

A system administrator is applying CIS Benchmarks to a Windows server. Which TWO hardening measures are typically recommended by CIS? (Select TWO.)

Select 2 answers
A.Enable all Windows features by default
B.Disable audit logging
C.Enforce strong password policies
D.Disable unused services
E.Allow anonymous enumeration of SAM accounts
AnswersC, D

Strong password policies enforce complexity, length and expiry through Group Policy, blocking weak credentials that brute-force and credential-stuffing attacks exploit. CIS Benchmarks recommend this account-policy hardening for Windows servers, satisfying the stem's requirement for a typically recommended measure.

Why this answer

Option C (Enforce strong password policies) is correct because CIS Benchmarks for Windows Server explicitly require configuring account policies such as minimum password length (typically 14 characters), password complexity, maximum password age, and password history to reduce the risk of brute-force and credential-guessing attacks. Option D (Disable unused services) is correct because CIS hardening guidance mandates disabling or setting to Disabled any unnecessary services (e.g., Fax, Windows Search, Remote Registry) to shrink the attack surface and eliminate unneeded listening ports and privileged functionality. Option A is wrong because enabling all Windows features by default directly contradicts CIS least-functionality principles, which call for removing or not installing unneeded roles and features.

Option B is wrong because CIS Benchmarks require enabling and configuring audit logging (e.g., via Advanced Audit Policy) to capture security-relevant events, not disabling it. Option E is wrong because allowing anonymous enumeration of SAM accounts is a known information-disclosure weakness that CIS explicitly prohibits by requiring the Anonymous Enumeration of SAM Accounts and Shares setting to be Disabled.

Exam trap

The trap here is that 'enable all features' sounds like maximum functionality, but hardening exams consistently test that CIS Benchmarks are about minimization — fewer services, fewer features, stronger authentication, and more logging.

8
MCQhard

An organization using PaaS (Platform as a Service) for application hosting wants to ensure the application code is secure. Which of the following is the customer's responsibility under the shared responsibility model?

A.Physical security of the data center
B.Patching the web server runtime
C.Patching the underlying operating system
D.Securing the application code from SQL injection
AnswerD

In PaaS, the provider secures the runtime, OS and infrastructure, but the customer retains ownership of the deployed application. Input validation and parameterised queries to prevent SQL injection sit squarely with the customer, satisfying the stem's requirement to secure application code.

Why this answer

Under the shared responsibility model for PaaS, the cloud provider manages the physical infrastructure, the operating system, and the runtime environment, while the customer is responsible for the security of the application code and data they deploy. Securing application code against SQL injection is therefore the customer's responsibility because it involves how the application is written and how it handles input.

Exam trap

SSCP often tests the shared responsibility model by presenting platform-layer tasks (OS patching, runtime patching) as if they were customer duties; the trap is forgetting that in PaaS the provider owns everything below the application, so only application code and data remain with the customer.

How to eliminate wrong answers

Option A is wrong because physical security of the data center is always the cloud provider's responsibility in any cloud service model (IaaS, PaaS, SaaS). Option B is wrong because patching the web server runtime is part of the platform layer managed by the PaaS provider, not the customer. Option C is wrong because patching the underlying operating system is also handled by the PaaS provider, unlike in IaaS where the customer patches the guest OS.

9
MCQhard

An organization is migrating a legacy application to a PaaS cloud environment. According to the shared responsibility model, which security control is the organization still responsible for?

A.Configuring the network firewall at the cloud perimeter
B.Securing the application code against SQL injection
C.Patching the underlying operating system
D.Managing the hypervisor and virtualization layer
AnswerB

In PaaS, the provider secures the platform, runtime and OS, but the customer retains responsibility for their application code. Input validation and parameterised queries preventing SQL injection remain the organisation's duty, satisfying the shared responsibility boundary for application-layer controls.

Why this answer

In the shared responsibility model for PaaS, the cloud provider manages the underlying infrastructure (network, OS, hypervisor, runtime), while the customer is responsible for the security of their application code and data. Securing application code against SQL injection is therefore the customer's responsibility. The other options are provider-managed in PaaS.

Exam trap

The trap is overestimating provider responsibility in PaaS — candidates assume the provider handles everything below the application, but the customer still owns application code security, IAM, and data protection.

How to eliminate wrong answers

Option A is wrong because in PaaS the cloud provider manages the network firewall at the perimeter as part of the platform infrastructure. Option C is wrong because patching the underlying operating system is the provider's responsibility in PaaS (the customer does not manage the OS). Option D is wrong because the hypervisor and virtualization layer are always managed by the cloud provider in any cloud service model (IaaS, PaaS, SaaS).

10
MCQhard

A financial services firm is migrating a customer-facing web application to a containerized platform. The security team wants to reduce the risk of a compromised container accessing the host kernel or other containers. Which of the following is the MOST effective control to limit the impact of a container breakout?

A.Scanning container images for known vulnerabilities before deployment
B.Enabling verbose logging of container stdout and stderr
C.Running containers with a read-only root filesystem
D.Enforcing a seccomp profile that allows only required system calls
AnswerD

Seccomp filters restrict which system calls a container process may invoke, directly limiting the kernel attack surface an attacker can use during a breakout attempt. By allowing only the calls the application needs, the profile blocks dangerous syscalls that are commonly abused for privilege escalation or container escape. This makes it the most effective control for reducing breakout impact.

Why this answer

Seccomp profiles constrain the system call interface exposed to container processes, directly shrinking the kernel attack surface an attacker can use to escape. Read-only filesystems, image scanning, and logging all add value at different stages but do not restrict runtime kernel interactions. Restricting syscalls is the most effective way to limit breakout impact on a shared host.

Exam trap

The trap here is equating preventive scanning or logging with runtime containment, when the control that actually limits a breakout must restrict what the running process can ask the kernel to do.

11
MCQhard

A cloud security team is using Cloud Security Posture Management (CSPM) to identify misconfigurations. Which of the following scenarios is MOST likely to be detected by CSPM?

A.An application running on a cloud VM has a memory leak causing performance degradation
B.A cloud storage bucket is configured with public read access
C.A cloud-based database is experiencing slow query response times
D.An employee's credentials were used from an unusual geographic location
AnswerB

CSPM evaluates cloud resource configurations against security baselines and benchmarks. A storage bucket set to public read access is a classic configuration drift that CSPM detects and flags, since it inspects control-plane settings rather than runtime traffic or application behaviour.

Why this answer

CSPM tools continuously scan cloud configurations against security benchmarks (CIS, NIST, PCI-DSS) and detect misconfigurations like publicly accessible storage buckets, overly permissive IAM policies, unencrypted volumes, and disabled logging. A publicly readable S3 bucket is a textbook CSPM finding.

Exam trap

SSCP often tests whether candidates can distinguish CSPM (configuration/posture) from runtime monitoring, APM, and UEBA tools — the key is whether the issue is a static misconfiguration versus a behavioral or performance anomaly.

How to eliminate wrong answers

Option A is wrong because memory leaks are runtime application performance issues detected by APM tools (e.g., CloudWatch, Datadog), not configuration scanners. Option C is wrong because slow database queries are performance concerns surfaced by database monitoring tools (Performance Insights, slow query logs), not posture management. Option D is wrong because anomalous credential usage from unusual geographies is detected by UEBA/behavioral analytics tools (GuardDuty, CloudTrail Insights), not CSPM.

12
MCQmedium

A security administrator is configuring a mobile device management (MDM) policy for company-owned smartphones. The organization wants to ensure that if a device is lost or stolen, corporate data can be removed without affecting the user's personal data. Which of the following MDM capabilities should be enabled?

A.Selective wipe of corporate data
B.Enforcing a strong screen lock PIN
C.Containerization of corporate applications
D.Remote wipe of the entire device
AnswerA

Selective wipe (or enterprise wipe) removes only corporate data and configurations from a device, leaving personal data intact. This meets the requirement of protecting corporate information while respecting user privacy. It is a standard MDM feature for BYOD or company-owned devices with personal use.

Why this answer

Selective wipe is designed to remove only corporate data and settings from a mobile device, preserving personal data. This is essential for scenarios where devices are used for both work and personal purposes. It ensures that sensitive company information is not exposed if the device is lost or stolen, while not intruding on the user's personal data.

Exam trap

The trap here is choosing full remote wipe as the solution, which would erase personal data and is not appropriate when personal data must be preserved.

13
MCQeasy

A healthcare organization is developing a mobile application that stores patient data locally on the device. The security team must ensure that if a device is lost or stolen, the data cannot be accessed without the user's authentication. Which of the following controls should be implemented to meet this requirement?

A.Use obfuscation to hide the application's code and data structures.
B.Store all patient data in a remote database and cache nothing locally.
C.Enable full-device encryption and require a strong passcode.
D.Implement certificate pinning for all API communications.
AnswerC

Full-device encryption protects all data at rest, including the application's local storage. When combined with a strong passcode, the encryption keys are derived from the passcode, so without it the data remains inaccessible. This directly satisfies the requirement that lost or stolen devices do not expose patient data, as the attacker cannot decrypt the storage without the passcode.

Why this answer

The most direct control to prevent access to locally stored data on a lost or stolen device is full-device encryption tied to a passcode. This ensures that without the correct passcode, the encryption keys cannot be derived, rendering the data unreadable. Other options address different threats such as network interception or reverse engineering, but not data-at-rest confidentiality.

Exam trap

The trap here is confusing data-in-transit protections like certificate pinning with data-at-rest protections, which are needed for lost device scenarios.

14
MCQmedium

A healthcare SaaS provider runs its application stack on Docker containers orchestrated by Kubernetes in a public cloud. A security administrator must reduce the risk of a compromised container accessing the underlying node's kernel. Which control BEST addresses this requirement?

A.Deploy containers with gVisor or Kata Containers to provide a sandboxed kernel boundary.
B.Set CPU and memory resource requests and limits on each container specification.
C.Configure Kubernetes Secrets to encrypt environment variables used by the application.
D.Enable Kubernetes NetworkPolicy to restrict pod-to-pod traffic on the cluster network.
AnswerA

gVisor and Kata Containers insert an isolation layer between the container and the host kernel. gVisor intercepts system calls in user space, while Kata runs each pod in a lightweight virtual machine with its own kernel. Either approach prevents a container breakout from directly reaching the node kernel, directly satisfying the requirement to limit kernel-level exposure.

Why this answer

Sandboxed container runtimes such as gVisor and Kata Containers create a kernel boundary between the workload and the node, directly reducing the impact of a compromised container. Network policies, secret encryption, and resource quotas address networking, confidentiality, and availability respectively, but none of them prevent a container from interacting with the host kernel.

Exam trap

The trap here is assuming that any Kubernetes security feature, such as NetworkPolicy or Secrets, provides workload isolation, when only sandboxed runtimes change the kernel trust boundary.

15
MCQeasy

Which Windows feature provides mandatory integrity controls and helps prevent unauthorized changes to system settings by requiring administrator approval?

A.Windows Defender Application Control
B.Security Audit Policy
C.User Account Control (UAC)
D.Group Policy
AnswerC

User Account Control enforces mandatory integrity levels, prompting for administrator approval before privileged actions elevate a process. This prevents unauthorised changes to system settings by standard users, satisfying the requirement for mandatory integrity controls with administrator approval.

Why this answer

User Account Control (UAC) is the Windows feature that enforces mandatory integrity controls and prompts for administrator approval before allowing changes that require elevated privileges. It ensures that even administrator accounts run with standard-user rights by default and must explicitly consent to elevation, preventing unauthorized system changes.

Exam trap

SSCP often tests the confusion between UAC (elevation/integrity prompts) and WDAC or Group Policy (application control and centralized configuration) — candidates must match 'administrator approval for system changes' specifically to UAC.

How to eliminate wrong answers

Option A is wrong because Windows Defender Application Control (WDAC) restricts which applications and code can run via allow-listing — it controls execution, not privilege elevation prompts. Option B is wrong because Security Audit Policy governs logging of security-relevant events (logon, object access), not integrity enforcement or elevation approval. Option D is wrong because Group Policy is a centralized configuration-management mechanism for applying settings across users and computers; it can configure UAC but is not itself the integrity/elevation control.

16
MCQmedium

A company uses virtualization extensively. The security team discovers that developers have created many unmanaged virtual machines that are not tracked in the configuration management database (CMDB). Which risk is MOST directly associated with this situation?

A.VM escape
B.VM sprawl
C.Snapshot vulnerability reintroduction
D.Insecure hypervisor configuration
AnswerB

Unmanaged VMs consume hypervisor CPU, memory, storage and licensing without lifecycle oversight, which is the defining characteristic of VM sprawl. Because these instances bypass the CMDB, they escape patching and vulnerability tracking, so sprawl is the risk most directly created by the missing inventory records.

Why this answer

VM sprawl refers to the proliferation of unmanaged VMs, increasing attack surface and management complexity.

17
MCQeasy

A healthcare organization stores protected health information on a database server. Auditors require that the data remain unreadable if the physical disk is stolen, and that encryption keys never reside on the same disk as the ciphertext. Which approach BEST satisfies these requirements?

A.Use file-level encryption on individual tablespaces with passwords stored in a local script.
B.Apply column-level encryption using a symmetric key embedded in the application configuration file.
C.Implement database transparent data encryption with keys managed by the database instance on the same volume.
D.Enable full disk encryption using a key stored in a hardware security module or external key manager.
AnswerD

Full disk encryption protects data at rest if the drive is removed, and storing the key in an HSM or external key manager ensures the key is not on the same disk as the ciphertext. This satisfies both auditor conditions: confidentiality of stolen media and separation of key material from encrypted data. It is the standard approach for data-at-rest protection on servers.

Why this answer

The auditors require protection of data at rest plus separation of keys from ciphertext. Full disk encryption with keys held in an HSM or external key manager meets both conditions by ensuring a stolen disk yields only ciphertext and the key remains in a controlled, separate system. The other approaches either leave key material on the same disk or fail to provide equivalent protection.

Exam trap

The trap here is treating any form of encryption as sufficient, when the scenario specifically requires that key material not reside on the same disk as the encrypted data.

18
MCQmedium

A system administrator is configuring a Linux server to ensure that only authorized users can execute commands with superuser privileges. Which file should be edited to control sudo access?

A./etc/shadow
B./etc/passwd
C./etc/group
D./etc/sudoers
AnswerD

/etc/sudoers defines which users and groups may run commands as root via sudo, using User_Spec and Cmnd_Spec entries. Editing it satisfies the stem's requirement to restrict superuser command execution to authorised users, unlike /etc/passwd or /etc/shadow.

Why this answer

The /etc/sudoers file is the central configuration file that defines which users and groups may run which commands with elevated privileges via sudo. It uses a specific syntax (user/group, host, runas, command) and is edited with visudo to prevent syntax errors that could lock out sudo access. Editing this file is the standard way to control sudo authorization on Linux.

Exam trap

The trap here is confusing authentication files (/etc/passwd, /etc/shadow) with authorization files (/etc/sudoers) — SSCP often tests whether candidates know that sudo rights are defined in sudoers, not in the password or group databases.

How to eliminate wrong answers

Option A is wrong because /etc/shadow stores hashed user passwords and aging information, not sudo authorization rules. Option B is wrong because /etc/passwd contains basic user account attributes (UID, GID, home, shell) but no sudo privilege definitions. Option C is wrong because /etc/group defines group membership, which can be referenced in sudoers but does not itself grant or control sudo access.

19
MCQmedium

A system administrator is hardening a Linux server. After installing the OS, which of the following steps should be taken to ensure that only authorized users can execute commands with elevated privileges?

A.Edit the /etc/sudoers file to restrict sudo access
B.Enable auditd to log all commands
C.Configure PAM to enforce password complexity
D.Set the setuid bit on critical binaries
AnswerA

Editing /etc/sudoers defines exactly which users or groups may run which commands via sudo, satisfying the requirement that only authorised accounts gain elevated execution. This replaces blanket root access with granular, auditable privilege delegation, so unauthorised users cannot escalate.

Why this answer

The /etc/sudoers file defines which users and groups may run which commands with elevated privileges via sudo. Restricting sudo access by editing this file (preferably with visudo) ensures that only authorized users can execute commands as root or another privileged account. This directly satisfies the requirement to control who can execute commands with elevated privileges.

Exam trap

The trap is confusing logging or authentication controls with authorization — candidates may pick auditd or PAM because they sound security-related, but only sudoers governs who may execute commands with elevated privileges.

How to eliminate wrong answers

Option B is wrong because auditd logs command execution for auditing and forensic purposes — it records what happened but does not restrict or authorize who can run privileged commands. Option C is wrong because PAM password complexity controls authentication strength (password length, character classes) but does not govern authorization to execute commands with elevated privileges. Option D is wrong because setting the setuid bit on binaries allows any user executing that binary to run it with the file owner's privileges — this actually broadens the attack surface and is a hardening anti-pattern, not a control for restricting elevated command execution.

20
MCQmedium

A Linux server is being hardened. The security team wants to enforce mandatory access control policies that confine processes to limited access to files and resources. Which technology should be implemented?

A.SELinux
B.PAM
C.iptables
D.auditd
AnswerA

SELinux enforces mandatory access control through type enforcement, confining each process to only the files and resources its policy permits, regardless of user identity. Standard discretionary permissions cannot constrain a compromised daemon this way, which is the hardening requirement.

Why this answer

SELinux (Security-Enhanced Linux) implements mandatory access control (MAC) by labeling processes and files with security contexts and enforcing policy rules that confine processes to only the resources they are permitted to access. This is exactly what the security team needs to enforce MAC and limit process access to files and resources.

Exam trap

The trap is conflating authentication (PAM), network filtering (iptables), and auditing (auditd) with mandatory access control — only SELinux (or AppArmor) enforces MAC at the process/resource level.

How to eliminate wrong answers

Option B is wrong because PAM (Pluggable Authentication Modules) handles authentication, account, session, and password management — it does not enforce mandatory access control over process-to-file interactions. Option C is wrong because iptables is a packet-filtering firewall that controls network traffic based on IP addresses, ports, and protocols — it operates at the network layer and does not confine processes' access to local files and resources. Option D is wrong because auditd is the Linux auditing daemon that records security-relevant events for compliance and forensics — it observes and logs but does not enforce access control policies.

21
MCQmedium

A company deploys a web application and wants to protect against SQL injection and XSS attacks. Which security control is specifically designed to inspect HTTP traffic and block such attacks?

A.Intrusion Detection System (IDS)
B.Network segmentation
C.Web Application Firewall (WAF)
D.Host-based firewall
AnswerC

A Web Application Firewall inspects inbound HTTP/HTTPS requests at layer 7, matching signatures and rules to block SQL injection and cross-site scripting payloads before they reach the application. This directly satisfies the stem's requirement for a control specifically designed to inspect HTTP traffic.

Why this answer

A Web Application Firewall (WAF) operates at the application layer (HTTP/HTTPS) and inspects request and response payloads for attack signatures such as SQL injection and cross-site scripting (XSS). It can block or filter malicious requests before they reach the web application, making it the control specifically designed for this purpose.

Exam trap

The trap is confusing detection with prevention — candidates may pick IDS because it 'monitors attacks,' but only a WAF is designed to inspect HTTP traffic and actively block SQLi and XSS.

How to eliminate wrong answers

Option A is wrong because an IDS detects and alerts on suspicious traffic but does not sit inline to block application-layer attacks — it is passive and focused on detection, not prevention. Option B is wrong because network segmentation divides the network into zones to limit lateral movement; it does not inspect HTTP payloads or block SQLi/XSS. Option D is wrong because a host-based firewall filters traffic by IP, port, and protocol at the host level — it does not parse HTTP content to detect application-layer attacks like SQL injection or XSS.

22
MCQmedium

A security administrator at a hospital is configuring a server that processes electronic health records. The server runs a Linux-based operating system, and the administrator needs to select a mandatory access control (MAC) framework that can enforce granular, policy-based restrictions on how processes interact with files, network ports, and other system resources. Which of the following should the administrator choose?

A.Password complexity and account lockout policies
B.Role-based access control (RBAC) through group membership
C.Discretionary access control (DAC) via standard file permissions
D.SELinux
AnswerD

SELinux is a mandatory access control framework integrated into the Linux kernel that enforces security policies based on labels applied to processes, files, ports, and other objects. It restricts even root-level processes according to administrator-defined policy, which fits the hospital's need for granular, system-wide MAC enforcement on a Linux host handling sensitive health records.

Why this answer

SELinux provides mandatory access control by labeling subjects and objects and enforcing administrator-defined policy in the kernel, restricting processes regardless of user identity. The other choices describe authentication hardening or discretionary and role-based models that do not enforce system-wide mandatory policy. For a Linux server holding regulated health data, SELinux is the correct framework to meet the granular MAC requirement.

Exam trap

The trap here is assuming that any access-control model labeled as role-based or permission-based satisfies a mandatory access control requirement, when MAC specifically requires kernel-enforced policy independent of object ownership.

23
MCQmedium

A security administrator is building a Security Information and Event Management (SIEM) correlation rule to detect a specific attack pattern on a Linux web server. The rule must identify attempts where an attacker sends a single malicious HTTP request that causes the server to execute an arbitrary operating system command. Which of the following event sources would provide the most reliable and immediate evidence for this rule?

A.Apache access logs with the Combined Log Format enabled
B.NetFlow records exported from the network router
C.Linux auditd logs configured to monitor execve system calls
D.Syslog messages from the SSH daemon
AnswerC

auditd can monitor the execve system call, which is invoked whenever a new process is executed. By configuring a rule to watch execve, the SIEM will receive an event containing the full command line and the parent process. This directly detects the arbitrary command execution caused by the malicious HTTP request, providing immediate and reliable evidence.

Why this answer

Detecting arbitrary command execution requires visibility into process creation on the host. Linux auditd can monitor the execve system call, capturing the exact command line and parent process for every new program. This gives the SIEM immediate, high-fidelity evidence of the attack, unlike network flow or web access logs that lack process-level context.

Exam trap

The trap here is assuming that web server access logs alone can confirm command execution, when they only show the request, not the resulting process activity.

24
MCQmedium

A Linux administrator needs to configure access controls so that a specific user can run certain commands with root privileges without entering a password. Which configuration file should be modified?

A./etc/shadow
B./etc/passwd
C./etc/sudoers
D./etc/security/limits.conf
AnswerC

Editing /etc/sudoers lets you grant the named user targeted command privileges via a NOPASSWD entry, satisfying the passwordless requirement. The sudoers file maps users to permitted commands and their authentication rules, unlike /etc/passwd or /etc/shadow, which hold account and password data rather than privilege-escalation policy.

Why this answer

The /etc/sudoers file defines which users or groups may run which commands as root (or other users), and supports the NOPASSWD tag to allow passwordless execution. Editing it with visudo ensures syntax validation and prevents concurrent-edit corruption. This is the standard mechanism for granting granular, password-free privilege escalation on Linux.

Exam trap

SSCP often tests the misconception that /etc/passwd or /etc/shadow control command privileges — candidates must remember that sudoers is the sole file governing delegated command execution, and that visudo is the safe editing tool.

How to eliminate wrong answers

Option A (/etc/shadow) is wrong because it stores hashed user passwords and aging information — it has nothing to do with command-level privilege delegation. Option B (/etc/passwd) is wrong because it holds basic account attributes (UID, GID, home directory, shell) and does not control sudo command permissions. Option D (/etc/security/limits.conf) is wrong because it enforces resource limits (e.g., max open files, CPU time) via PAM, not command execution privileges.

25
MCQmedium

An organization is experiencing VM sprawl, with many unmanaged virtual machines running in the environment. Which of the following is the most significant security risk associated with VM sprawl?

A.Unpatched and misconfigured VMs
B.License compliance violations
C.Increased power consumption and cooling costs
D.VM escape attacks from older hypervisors
AnswerA

Unmanaged VMs are often forgotten, leading to security gaps.

Why this answer

Unmanaged VMs often lack proper patching and configuration management, leading to unpatched vulnerabilities that can be exploited.

26
MCQeasy

A small accounting firm wants to ensure that if a laptop is lost, the data on its full-disk-encrypted drive cannot be recovered by an attacker who removes the drive and mounts it elsewhere. Which additional control is MOST important to meet this goal?

A.Install endpoint detection and response software on the laptop.
B.Enable a screen saver that locks the console after ten minutes of inactivity.
C.Enforce automatic backup of user documents to a cloud file-sharing service.
D.Configure a strong pre-boot authentication password or PIN that is not stored on the disk.
AnswerD

Full-disk encryption with a key protector that requires a secret known only to the user means the volume encryption key cannot be unwrapped without that secret. An attacker who extracts the drive still lacks the input needed to decrypt, so pre-boot authentication is the control that converts encryption at rest into meaningful protection for a lost device.

Why this answer

Encryption at rest only protects a lost device when the key is protected by a secret the attacker does not possess. Requiring pre-boot authentication with a PIN or password ensures the volume master key cannot be unwrapped offline, whereas screen locks, EDR, and backups operate on different threat models and cannot prevent offline decryption of a removed drive.

Exam trap

The trap here is assuming that enabling full-disk encryption by itself protects a stolen drive, when the protection depends entirely on how the encryption key is protected.

27
MCQhard

A security architect is reviewing cloud security for a SaaS application used by the company. According to the shared responsibility model, which security controls are PRIMARILY the customer's responsibility?

A.Data classification and user access management
B.Network infrastructure security
C.Physical security of data centers
D.Operating system patching
AnswerA

In SaaS, the provider secures the application, runtime and infrastructure, while the customer retains responsibility for its own data classification and managing which users may access that data. These controls sit above the provider's boundary, satisfying the stem's shared responsibility constraint.

Why this answer

In SaaS, the customer is responsible for data classification and managing user access (IAM).

28
MCQmedium

A financial services company runs a customer-facing mobile banking API on Linux containers. A penetration test reveals that when the API receives an oversized JSON payload, the application returns a stack trace containing internal file paths and database connection strings. The developer wants to prevent this information disclosure without changing the API's core business logic. Which control should the security practitioner recommend FIRST?

A.Deploy a web application firewall in blocking mode with signatures for known stack trace patterns.
B.Configure the application to return generic error messages and log detailed exceptions server-side only.
C.Increase the maximum allowed request body size in the API gateway to reject oversized payloads.
D.Enable full verbose logging in the API and ship logs to a centralized SIEM for alerting.
AnswerB

Generic client-facing errors with detailed server-side logging prevent attackers from learning internal file paths and connection strings while preserving diagnostic data for developers. This directly addresses the information disclosure observed in the stack trace without altering business logic. It is a standard secure coding practice aligned with SSCP guidance on error handling and preventing sensitive data exposure in application responses.

Why this answer

The core issue is an information disclosure vulnerability caused by improper error handling. Returning generic messages to clients while logging details internally removes the sensitive data from the response path and preserves troubleshooting capability. WAFs and logging are useful compensating or detective controls, but they do not eliminate the root cause, which is the application revealing internal implementation details.

Exam trap

The trap here is assuming that a perimeter control such as a WAF or expanded logging eliminates the disclosure, when the flaw actually lives in how the application constructs its error responses.

29
Multi-Selectmedium

A company is migrating to the cloud and wants to understand the shared responsibility model. For an IaaS deployment, which THREE are customer responsibilities? (Select THREE.)

Select 3 answers
A.Managing application security (e.g., patching web app code)
B.Configuring the host-based firewall on VMs
C.Patching the guest operating system
D.Physical security of the data center
E.Securing the hypervisor
AnswersA, B, C

Under IaaS the provider manages the platform beneath the VM, leaving everything above the operating system to the tenant. Application security, including patching web app code, therefore falls to the customer, satisfying the stem's customer-responsibility constraint rather than the provider's managed scope.

Why this answer

In IaaS, customer manages OS, applications, and network traffic controls (guest OS firewall).

30
MCQhard

An organization using cloud IAM wants to grant a compute instance permissions to access a cloud storage bucket without storing long-term credentials on the instance. Which IAM feature should be used?

A.IAM role assigned to the compute instance
B.Service-level access policies
C.Long-term user access keys
D.Resource-based policies on the storage bucket
AnswerA

An IAM role attached to the compute instance issues short-lived, automatically rotated credentials through the instance metadata service, so no long-term secret is stored on disk. This satisfies the requirement of granting bucket access without embedding persistent credentials on the instance.

Why this answer

IAM roles for compute instances allow the instance to assume a role and obtain temporary credentials from a security token service, avoiding the need for long-term keys.

31
MCQmedium

To prevent VM escape attacks in a virtualized environment, which of the following is the most critical security measure?

A.Disable unnecessary VM guest tools
B.Apply the latest patches to the hypervisor
C.Use VLAN segmentation for VM networks
D.Use snapshots for quick recovery
AnswerB

Hypervisor patches close the vulnerabilities that let guest code break out of its VM boundary and reach the host. Since the hypervisor is the isolation layer itself, keeping it patched directly addresses the VM escape constraint in the stem.

Why this answer

The hypervisor is the software layer that creates and runs virtual machines, and it is the primary target for VM escape attacks because it sits between the guest VMs and the host hardware. A vulnerability in the hypervisor (e.g., in its emulation of devices or in its memory management) can allow a guest VM to break out and execute code on the host. Applying the latest patches to the hypervisor directly addresses these vulnerabilities, making it the most critical measure to prevent VM escape.

Without patching, other measures like network segmentation or disabling guest tools do not fix the underlying exploitable flaw.

Exam trap

SSCP often tests the misconception that network segmentation or guest hardening alone can prevent VM escape, when the root cause is hypervisor vulnerabilities that require patching.

How to eliminate wrong answers

Option A is wrong because disabling unnecessary VM guest tools reduces the attack surface within the guest but does not address hypervisor vulnerabilities that enable escape; guest tools are not the primary vector for escape. Option C is wrong because VLAN segmentation is a network control that limits lateral movement between VMs but does nothing to prevent a VM from escaping to the host via a hypervisor exploit. Option D is wrong because snapshots provide recovery and rollback capabilities after an incident, but they do not prevent the escape from occurring in the first place.

32
Multi-Selectmedium

A security engineer is hardening a Windows server. Which TWO actions should be taken to reduce the attack surface? (Select TWO.)

Select 2 answers
A.Increase the number of active user accounts for auditing
B.Enable auto-run for removable media to improve user convenience
C.Disable unnecessary services and accounts
D.Apply the latest security patches
E.Install additional third-party software for monitoring
AnswersC, D

Disabling unnecessary services and accounts removes unused listening ports and dormant credentials, directly shrinking exploitable entry points. This satisfies the hardening requirement by eliminating attack vectors that patching alone cannot address, since unused services still expose the Windows server.

Why this answer

Option C is correct because disabling unnecessary services and accounts directly shrinks the attack surface by removing exploitable entry points, listening ports, and credentials that attackers could abuse for privilege escalation or lateral movement. Option D is correct because applying the latest security patches remediates known vulnerabilities (e.g., remote code execution flaws) that malware and threat actors actively exploit, which is a foundational hardening step. Option A is wrong because creating more active user accounts expands the attack surface and increases credential-management risk rather than reducing it.

Option B is wrong because enabling AutoRun for removable media facilitates malware propagation via USB drives and should typically be disabled. Option E is wrong because installing additional third-party software adds new code, services, and potential vulnerabilities, enlarging rather than reducing the attack surface.

Exam trap

SSCP often tests whether candidates recognize that adding software, accounts, or convenience features increases attack surface — the trap is picking options that sound like monitoring or auditing improvements but actually expand risk.

33
MCQmedium

During a security assessment, it is discovered that a Linux server has unnecessary services running, including Telnet and FTP. The server is also missing critical security patches. Which of the following is the MOST effective approach to harden this server according to industry best practices?

A.Move the server to a more secure network segment and implement network access controls.
B.Enable SELinux and configure a host-based firewall using iptables.
C.Install a host-based intrusion detection system (HIDS) to monitor for attacks.
D.Disable Telnet and FTP services, and apply all critical security patches.
AnswerD

Disabling Telnet and FTP removes insecure cleartext protocols, while patching closes known vulnerabilities. Together they eliminate both the exposed attack surface and the exploitable flaws, satisfying the hardening requirement more completely than either measure alone.

Why this answer

The most effective hardening approach directly addresses the identified vulnerabilities: disabling insecure services (Telnet and FTP, which transmit credentials in cleartext) and applying critical security patches to close known exploitable flaws. This removes the actual attack vectors rather than merely monitoring or isolating them, aligning with CIS and NIST hardening guidance.

Exam trap

SSCP often tests whether candidates choose compensating or detective controls (segmentation, HIDS) over direct remediation — the trap is overlooking that the question asks for the most effective hardening action against the specific findings.

How to eliminate wrong answers

Option A is wrong because moving the server to a segmented network with access controls reduces exposure but does not remediate the insecure services or missing patches on the host itself — the vulnerabilities remain exploitable from within the segment. Option B is wrong because enabling SELinux and configuring iptables improves host security posture but does not remove Telnet/FTP or patch the system; these are complementary controls, not the primary remediation for the stated issues. Option C is wrong because a HIDS detects and alerts on attacks but does not prevent them or fix the underlying vulnerabilities — detection without remediation leaves the server exploitable.

34
MCQeasy

In Linux, which command is used to change file permissions to restrict access so that only the owner can read and write, and the group and others have no access?

A.chmod 600 file.txt
B.chown 600 file.txt
C.umask 077 file.txt
D.setfacl -m u::rw file.txt
AnswerA

chmod 600 file.txt sets the permission bits to rw-------, giving the owner read and write while group and others receive none. The octal 6 encodes read (4) plus write (2) for the owner, and the two trailing zeros deny all group and other access, satisfying the stem's restriction requirement.

Why this answer

chmod 600 file.txt sets permissions so the owner has read and write (6 = rw-), while group and others have no permissions (0 = ---). This matches the requirement that only the owner can read and write and no one else has access. The numeric (octal) mode 600 is the standard way to express owner rw, group none, others none.

Exam trap

SSCP often tests the confusion between chmod (change permissions), chown (change ownership), and umask (set default creation mask) — candidates pick umask or chown when the question asks to modify an existing file's permissions.

How to eliminate wrong answers

Option B is wrong because chown changes file ownership (user and/or group), not permissions, and '600' is not a valid chown argument. Option C is wrong because umask sets default permission bits for newly created files and directories; it does not modify an existing file's permissions and cannot be applied to a specific file like file.txt. Option D is wrong because setfacl manages access control lists for granular permissions; the syntax given only sets the owner's ACL entry to rw and does not explicitly remove group and other access, nor is it the standard command for the stated requirement.

35
MCQeasy

Which of the following OWASP Top 10 vulnerabilities involves an attacker sending malicious data to an interpreter as part of a command or query?

A.Security Misconfiguration
B.Injection
C.Broken Authentication
D.Cross-Site Scripting (XSS)
AnswerB

Injection flaws occur when untrusted data is sent to an interpreter as part of a command or query, causing it to execute unintended commands. This matches the stem's description of malicious data reaching an interpreter directly, distinguishing it from broken access control or misconfiguration.

Why this answer

Injection is the OWASP Top 10 category that directly involves an attacker sending malicious data to an interpreter as part of a command or query. This occurs when untrusted data is concatenated into a command or query without proper validation or parameterization, allowing the attacker to alter the intended execution. Examples include SQL injection, OS command injection, and LDAP injection, where the interpreter executes the attacker's injected commands.

The core reasoning is that the vulnerability arises from the lack of separation between data and code, enabling the attacker to control the interpreter's behavior.

Exam trap

SSCP often tests the distinction between injection attacks and other OWASP Top 10 categories like XSS, which also involve injecting malicious data but target the client-side browser rather than a server-side interpreter.

How to eliminate wrong answers

Option A is wrong because Security Misconfiguration refers to insecure default settings, incomplete configurations, or verbose error messages, not the direct injection of malicious data into an interpreter. Option C is wrong because Broken Authentication involves flaws in authentication mechanisms (e.g., weak passwords, session fixation) that allow attackers to compromise credentials or impersonate users, not the injection of data into commands or queries. Option D is wrong because Cross-Site Scripting (XSS) is a client-side code injection attack where malicious scripts are executed in a victim's browser, not an attack against a server-side interpreter via commands or queries.

36
MCQhard

During a vulnerability scan, a security team discovers that several virtual machine snapshots contain outdated software with known vulnerabilities. Which risk is most directly associated with this scenario?

A.Resource exhaustion
B.VM sprawl
C.Vulnerability reintroduction
D.VM escape
AnswerC

Snapshots preserve a point-in-time disk state, so reverting a virtual machine restores the outdated software and its known vulnerabilities, undoing prior patching. This directly satisfies the stem's constraint: dormant snapshot images retaining vulnerable code that re-enters production upon restore, which is precisely vulnerability reintroduction.

Why this answer

Virtual machine snapshots capture the state of a VM at a point in time, including the operating system and installed software. If a snapshot contains outdated software with known vulnerabilities, restoring that snapshot or using it to create new VMs can reintroduce those vulnerabilities into the environment, even if they were previously patched. This is known as vulnerability reintroduction.

Exam trap

SSCP often tests the distinction between different VM-related risks, and candidates may confuse vulnerability reintroduction with VM sprawl or resource exhaustion, especially when snapshots are involved.

How to eliminate wrong answers

Option A is wrong because resource exhaustion refers to running out of resources like CPU, memory, or storage, which is not directly related to outdated software in snapshots. Option B is wrong because VM sprawl refers to the uncontrolled proliferation of VMs, not the reintroduction of vulnerabilities. Option D is wrong because VM escape is an exploit where an attacker breaks out of a VM to access the host, which is a different risk and not directly associated with outdated software in snapshots.

37
Multi-Selectmedium

An organization is hardening a Linux server. Which TWO of the following are effective steps to reduce the attack surface?

Select 2 answers
A.Disable SELinux for better performance
B.Install all available packages to ensure compatibility
C.Remove unnecessary services and software packages
D.Set file permissions using chmod and chown to restrict access
E.Enable the root account for direct login
AnswersC, D

Removing unnecessary services and packages eliminates unused daemons, open ports and vulnerable libraries, shrinking the number of exploitable entry points on the host. This directly reduces the attack surface, which is the hardening goal stated in the scenario.

Why this answer

Removing unnecessary services and software reduces potential vulnerabilities. Proper file permissions using chmod and chown enforce least privilege.

38
MCQmedium

A cloud security team is implementing a Cloud Security Posture Management (CSPM) tool. What is the primary purpose of a CSPM solution?

A.Manage user identities and access
B.Protect workloads from runtime threats
C.Encrypt data at rest
D.Detect and remediate cloud misconfigurations
AnswerD

CSPM continuously assesses cloud environments against security baselines and compliance frameworks, identifying misconfigurations such as public buckets or overly permissive roles, then alerting or auto-remediating. This detection and remediation of misconfigurations is its primary purpose, distinct from workload protection or identity governance.

Why this answer

CSPM tools continuously monitor cloud environments against security benchmarks (CIS, PCI-DSS, ISO 27001) and compliance frameworks, detecting misconfigurations such as public S3 buckets, overly permissive security groups, or disabled logging, then providing remediation guidance. The primary purpose is posture management — identifying and fixing configuration drift and policy violations before they are exploited.

Exam trap

SSCP often tests the boundary between CSPM, CWPP, and CIEM — candidates confuse posture management (configuration) with workload protection (runtime) or identity management (permissions).

How to eliminate wrong answers

Option A is wrong because managing user identities and access is the domain of CIEM (Cloud Infrastructure Entitlement Management) or IAM tools, not CSPM. Option B is wrong because protecting workloads from runtime threats is the role of CWPP (Cloud Workload Protection Platform) or runtime defense tools like Defender for Servers. Option C is wrong because encrypting data at rest is a data protection control, often handled by cloud-native encryption services or DSPM tools, not the core function of CSPM.

39
Multi-Selecthard

A company is migrating to a PaaS cloud environment. According to the shared responsibility model, which THREE security responsibilities remain with the customer? (Select THREE.)

Select 3 answers
A.Patch management of the underlying OS
B.User access and identity management
C.Data classification and encryption
D.Security of the application code
E.Physical security of the data center
AnswersB, C, D

In PaaS, the provider secures the platform and runtime, but the customer still controls who accesses the service. Managing user accounts, authentication and authorisation remains the customer's duty, satisfying the stem's shared responsibility constraint for identity.

Why this answer

In PaaS, the customer manages access policies, application-level security, and data protection, while the provider manages the runtime, OS, and infrastructure.

40
MCQhard

A DevOps team deploys containerized microservices and wants to reduce the impact of a compromised container. They need a control that limits which system calls each container process can make, without changing the application image. Which Linux kernel feature should they enable?

A.Read-only root file system for the container
B.seccomp profiles applied to the container
C.Dropping all Linux capabilities from the container
D.Linux cgroups v2 memory limits
AnswerB

seccomp filters the system calls a process may invoke, so a compromised container can be blocked from dangerous calls such as mounting file systems or loading kernel modules. Profiles are applied by the runtime at container start, requiring no change to the application image, which fits the team's constraint exactly.

Why this answer

seccomp attaches a filter to each process that permits or denies individual system calls, so even a fully compromised container is constrained at the kernel boundary. Because profiles are supplied by the container runtime at launch, the team avoids modifying the application image while gaining strong containment.

Exam trap

The trap here is treating resource limits or read-only file systems as syscall restrictions, when only seccomp filters the actual kernel calls a container may make.

41
Multi-Selecteasy

A Linux administrator is hardening a server. Which TWO commands are used to manage file permissions? (Select TWO.)

Select 2 answers
A.usermod
B.passwd
C.groupadd
D.chmod
E.chown
AnswersD, E

chmod alters the read, write and execute bits of a file's permission mode, applying symbolic or octal changes to owner, group and others. Hardening requires tightening these access bits, so chmod directly satisfies the task of managing file permissions on the server.

Why this answer

Option D, chmod, is correct because it directly manages file permissions by changing the read, write, and execute bits (the mode) for the owner, group, and others on files and directories, using symbolic or octal notation. Option E, chown, is correct because it manages file ownership, changing the owning user and/or group of a file, which is a core part of file permission management since permissions are evaluated against the owner and group. Option A, usermod, is incorrect because it modifies user account attributes such as group membership, home directory, and shell, not file permissions.

Option B, passwd, is incorrect because it manages user authentication passwords, not file permissions. Option C, groupadd, is incorrect because it creates new groups in the system, not file permissions.

Exam trap

SSCP often tests whether candidates confuse user account management commands (usermod, passwd, groupadd) with file permission commands (chmod, chown) — the question's 'file permissions' phrasing is the key.

42
MCQhard

A security analyst investigates a suspicious process on a Linux web server that is making outbound connections to an unknown IP address. The analyst wants to confirm which executable file is running and whether it has been modified since installation. Which combination of actions best accomplishes this?

A.Check the process owner with the ps command and confirm it is not root
B.Inspect the process's /proc/<pid>/exe link and compare the file hash against a known-good baseline
C.Run netstat to list the established outbound connection
D.Review the process's open file descriptors in /proc/<pid>/fd
AnswerB

The /proc/<pid>/exe symbolic link points to the actual executable backing the running process, even if the file was deleted or renamed, so it reveals the true binary. Hashing that file and comparing it to a trusted baseline shows whether the executable has been altered, satisfying both questions.

Why this answer

Resolving the /proc/<pid>/exe link identifies the exact executable behind the process, and hashing that file against a trusted baseline detects tampering. Used together, these steps confirm both the binary's identity and its integrity, which is what the investigation requires.

Exam trap

The trap here is stopping at network evidence such as the established connection, which proves activity but never identifies the executable or whether it was modified.

43
MCQmedium

A security analyst is reviewing Linux server logs after a suspected breach. Which auditing tool should be used to examine detailed records of system calls and file access events?

A.SELinux
B.PAM
C.auditd
D.iptables
AnswerC

auditd hooks into the Linux kernel audit subsystem, recording system calls and file access events with full context. It captures the detailed syscall-level records a breach investigation needs, unlike syslog or application logs, which omit kernel-level activity.

Why this answer

auditd is the Linux userspace auditing daemon that works with the kernel audit subsystem to record system calls, file access, authentication events, and other security-relevant activity. It writes detailed records to /var/log/audit/audit.log and can be queried with ausearch and aureport, making it the correct tool for examining system call and file access events after a suspected breach.

Exam trap

The trap here is confusing access-control or authentication tools (SELinux, PAM) with auditing tools — candidates pick SELinux because it 'logs security events,' but it does not provide syscall-level audit records.

How to eliminate wrong answers

Option A is wrong because SELinux is a mandatory access control framework that enforces policy on processes and files — it can log AVC denials, but it is not an auditing tool for examining detailed system call and file access records. Option B is wrong because PAM (Pluggable Authentication Modules) handles authentication, authorization, and session management; it does not provide system call or file access auditing. Option D is wrong because iptables is a packet-filtering firewall for network traffic, not a host-based auditing tool for system calls or file access.

44
MCQhard

A security operations center (SOC) is investigating a suspected supply chain attack where a trusted software update was modified to include a backdoor. The update was delivered via the vendor's official update server over HTTPS. Which of the following controls, if implemented by the organization, would have BEST prevented the installation of the backdoored update?

A.TLS certificate pinning for the update server connection.
B.Network segmentation between the update server and critical systems.
C.Code signing verification of the update package before installation.
D.Endpoint detection and response (EDR) with behavioral monitoring.
AnswerC

Code signing verification checks that the update package was signed by the vendor's private key and has not been altered. If the attacker modified the update, the signature would not match, and the installation would be blocked. This directly prevents the backdoored update from being installed, assuming the vendor's private key was not compromised. It is the most effective control for this scenario.

Why this answer

Code signing verification is the key control to ensure the integrity and authenticity of software updates. If the update was modified after signing, the signature check fails, and the installation is blocked. Other controls like network segmentation or TLS pinning do not protect against a compromised update server or a malicious insider at the vendor.

Exam trap

The trap here is assuming that HTTPS and TLS pinning guarantee the integrity of the update content, when they only secure the transport, not the package itself.

45
MCQhard

A company uses Infrastructure as a Service (IaaS) for its production workloads. According to the shared responsibility model, which of the following security tasks is the customer responsible for?

A.Patching the hypervisor
B.Physical security of data centers
C.Securing the network infrastructure
D.Patching the guest operating system
AnswerD

Patching the guest operating system falls to the customer under IaaS, since the provider manages only the hypervisor, physical hosts and network fabric. The customer retains control of everything from the guest OS upward, satisfying the stem's shared responsibility constraint.

Why this answer

In the IaaS shared responsibility model, the customer is responsible for securing the guest operating system, including patching, because the cloud provider manages the hypervisor and physical infrastructure. The customer controls the OS and applications running on the IaaS instances.

Exam trap

The trap is mixing up responsibilities: candidates often think the provider patches the guest OS in IaaS, but the exam tests that the customer owns guest OS patching.

How to eliminate wrong answers

Option A is wrong because patching the hypervisor is the cloud provider's responsibility in IaaS. Option B is wrong because physical security of data centers is always the provider's responsibility. Option C is wrong because securing the network infrastructure (e.g., physical routers, switches) is managed by the provider, although the customer may be responsible for virtual network security.

46
MCQhard

An organization uses VMware ESXi in a production environment. Which of the following is the most effective mitigation against VM escape attacks?

A.Using VM snapshots for quick recovery
B.Implementing network segmentation between VMs
C.Regularly patching the ESXi hypervisor
D.Disabling unnecessary guest tools within VMs
AnswerC

Patching the ESXi hypervisor closes the vulnerabilities that VM escape exploits target, directly satisfying the stem's mitigation requirement. Because escape attacks break the isolation boundary between guest and host, keeping the hypervisor current is more effective than guest-level controls, which cannot protect the host.

Why this answer

VM escape exploits a vulnerability in the hypervisor that lets a guest VM break out and access the host or other VMs. Regularly patching ESXi closes known hypervisor vulnerabilities (e.g., those disclosed in VMware security advisories) before attackers can exploit them, making it the most effective mitigation. Patching directly addresses the root cause — the hypervisor flaw — rather than the symptoms.

Exam trap

The trap is choosing a compensating or detective control (segmentation, snapshots) when the question asks for the most effective mitigation — candidates overlook that only patching removes the hypervisor vulnerability itself.

How to eliminate wrong answers

Option A is wrong because snapshots are a recovery mechanism, not a preventive control — they help you restore after a compromise but do nothing to stop a VM escape. Option B is wrong because network segmentation between VMs limits lateral movement after an escape but does not prevent the escape itself, which occurs at the hypervisor layer. Option D is wrong because disabling unnecessary guest tools reduces the guest attack surface but does not address hypervisor vulnerabilities that enable escape.

47
MCQmedium

A mobile device management (MDM) administrator at a healthcare company needs to ensure that a physician's personally owned smartphone can access patient records through the corporate email application, but the administrator must be able to remotely erase only the corporate email data and its encryption keys if the device is lost, without deleting the physician's personal photos and apps. Which MDM capability should the administrator configure?

A.Enable selective wipe, also called enterprise wipe, which removes only corporate email data and associated keys.
B.Configure a full-device remote wipe that removes all data after a predefined number of failed unlock attempts.
C.Enroll the device in a mobile application management (MAM) policy that blocks copy and paste between apps.
D.Apply a device-level passcode policy that requires a six-digit PIN and disables the camera application.
AnswerA

Selective wipe, or enterprise wipe, is designed for BYOD scenarios where the organization manages only the corporate container. It removes corporate email, attachments, and the encryption keys protecting that data while leaving personal photos and apps intact. This satisfies the requirement to remotely erase only corporate data if the device is lost.

Why this answer

Selective wipe, also known as enterprise wipe, is the MDM feature that removes only corporate data and its encryption keys from a personally owned device. It preserves the user's personal content, making it the correct choice for BYOD scenarios. Full-device wipe, passcode policies, and copy-paste restrictions do not provide the required granular remote erasure of corporate email data.

Exam trap

The trap here is assuming that any remote wipe capability erases only corporate data, when a full-device wipe destroys personal content as well.

48
Multi-Selectmedium

A security engineer is hardening a Linux server. Which TWO actions are recommended to reduce the attack surface? (Select TWO.)

Select 2 answers
A.Remove unnecessary services and daemons
B.Disable unused user accounts
C.Install a web server for management
D.Set umask to 000
E.Enable IPv6 routing
AnswersA, B

Removing unnecessary services and daemons eliminates listening ports and executable code that attackers could exploit, directly shrinking the server's attack surface. This satisfies the hardening constraint by reducing the number of potential entry points requiring patching and monitoring.

Why this answer

Option A is correct because removing unnecessary services and daemons eliminates listening ports, binaries, and potential vulnerabilities that attackers could exploit, directly shrinking the attack surface. Option B is correct because disabling unused user accounts removes dormant credentials and login paths that could be abused for unauthorized access or privilege escalation. Option C is wrong because installing a web server for management adds a new network-facing service and increases, rather than reduces, the attack surface.

Option D is wrong because setting umask to 000 makes newly created files world-readable and world-writable, weakening permissions instead of hardening them. Option E is wrong because enabling IPv6 routing adds network functionality and exposure that is unnecessary on a hardened server and can introduce additional attack vectors.

Exam trap

The trap is that some options sound like security measures (installing a management web server, enabling IPv6) but actually expand the attack surface—candidates must distinguish between adding functionality and reducing exposure.

49
MCQeasy

An organization is hardening a new Windows server for production use. Which of the following is the most effective method to ensure that only approved applications can run?

A.Enable BitLocker drive encryption
B.Enable User Account Control (UAC)
C.Configure AppLocker or Windows Defender Application Control
D.Install Windows Defender Antivirus
AnswerC

AppLocker and Windows Defender Application Control enforce application allowlisting, permitting only explicitly approved executables to run. This directly satisfies the requirement that only approved applications execute, unlike antivirus scanning or firewall rules, which detect or block traffic rather than restrict which programs may launch.

Why this answer

AppLocker and Windows Defender Application Control (WDAC) are the native Windows mechanisms that enforce application allowlisting by permitting only approved executables, scripts, and installers to run. They operate via policy at the kernel/OS level and are the correct control for restricting execution to approved software. This directly satisfies the requirement that only approved applications can run.

Exam trap

SSCP often tests the confusion between antivirus (denylist, detects known bad) and application allowlisting (only approved apps run), tempting candidates to pick Defender Antivirus as if it guaranteed only approved software executes.

How to eliminate wrong answers

Option A is wrong because BitLocker provides full-disk encryption for data-at-rest confidentiality and does not control which applications execute. Option B is wrong because UAC prompts for elevation and limits standard-user privileges but does not maintain an allowlist of approved applications. Option D is wrong because Windows Defender Antivirus detects and blocks known malware by signature and behavior, but it is a denylist approach, not an allowlist that guarantees only approved apps run.

50
MCQhard

A financial services firm must prove that an e-commerce application's source code has not been tampered with between the build pipeline and production deployment. The pipeline already stores build artifacts in an internal repository. Which control BEST provides this assurance?

A.Generate an SBOM in SPDX format and archive it alongside each release.
B.Enable multi-factor authentication for all engineers who have access to the artifact repository.
C.Sign each build artifact with a key held by the CI/CD system and verify the signature before deployment.
D.Require developers to sign Git commits with their personal GPG keys.
AnswerC

Cryptographically signing the artifact in the pipeline and verifying that signature at deploy time binds the exact bytes to a trusted build process. Any tampering after signing invalidates the signature and blocks deployment. This is the mechanism behind sigstore/cosign and similar supply-chain integrity tools, and it directly satisfies the requirement for provable artifact integrity.

Why this answer

Signing build artifacts in the pipeline and validating those signatures before deployment creates a cryptographic chain from the trusted build to production. If any byte changes in transit or at rest, verification fails. SBOMs, commit signing, and MFA improve visibility or access control but do not seal the artifact itself, so they cannot prove non-tampering.

Exam trap

The trap here is conflating provenance metadata such as an SBOM or a signed Git commit with cryptographic integrity of the deployed artifact.

51
MCQmedium

A financial services firm runs a Java-based customer portal on Apache Tomcat. During a code review, the security team discovers that the application deserializes session objects received from an untrusted partner API without validating their contents. An attacker could craft a malicious serialized object that executes arbitrary code on the server when deserialized. Which of the following controls BEST mitigates this risk?

A.Enable TLS 1.3 with mutual authentication between the portal and the partner API.
B.Implement a strict allowlist of permitted classes for deserialization and reject all others.
C.Increase the Java heap size and enable garbage collection tuning on the Tomcat server.
D.Deploy a web application firewall (WAF) with OWASP ModSecurity Core Rule Set in blocking mode.
AnswerB

An allowlist restricts deserialization to only known, safe classes, preventing attacker-controlled gadget chains from being instantiated. Because the partner API only needs to send specific session object types, enumerating those types and rejecting everything else directly blocks the malicious object from being processed. This is the most targeted and effective mitigation for insecure deserialization in this scenario.

Why this answer

Insecure deserialization allows attackers to influence object state and potentially achieve remote code execution. The most direct fix is to constrain which classes can be deserialized using an allowlist, so only expected types from the partner API are accepted. Transport encryption, WAF rules, and JVM tuning do not validate object contents and therefore fail to eliminate the vulnerability.

Exam trap

The trap here is assuming that encrypting the transport channel with mutual TLS secures the payload, when in fact it only protects data in transit and does nothing to validate the deserialized object itself.

52
MCQeasy

A security analyst is hardening a new Windows server. Which configuration would MOST effectively reduce the attack surface by limiting the software that can execute?

A.Enable Windows Defender Antivirus
B.Disable AutoPlay
C.Enable User Account Control (UAC)
D.Configure AppLocker rules
AnswerD

AppLocker enforces allow/deny rules on which executables, scripts and installers may run, directly restricting software execution on the Windows server and shrinking the attack surface. Unlike firewall or patch controls, it addresses the constraint of limiting what can execute.

Why this answer

AppLocker is a Windows application control feature that lets administrators define allow/deny rules based on publisher, path, or file hash, thereby restricting which executables, scripts, and installers can run. This directly limits the software that can execute, which is the most effective way to reduce attack surface against unauthorized or malicious code. Antivirus, AutoPlay, and UAC address other threats but do not control what software is permitted to run.

Exam trap

The trap is confusing detection-based controls (antivirus) or privilege controls (UAC) with execution control—only AppLocker (or similar WDAC) actually restricts what software is allowed to run.

How to eliminate wrong answers

Option A is wrong because Windows Defender Antivirus detects known malware signatures and behaviors but does not prevent arbitrary legitimate-looking executables from running—it is reactive, not a whitelisting control. Option B is wrong because disabling AutoPlay only prevents automatic execution of removable media content; it does not restrict software execution generally. Option C is wrong because UAC prompts for elevation but does not block execution of non-elevated software—a user can still run any executable that doesn't require admin rights.

53
MCQeasy

An organization is hardening its Windows servers. Which built-in Windows feature can be used to enforce application whitelisting, ensuring only approved executables run?

A.BitLocker
B.Windows Defender Antivirus
C.AppLocker
D.User Account Control (UAC)
AnswerC

AppLocker applies policy-based allow lists that restrict which executables, scripts and installers may run, using publisher, path or hash rules. This enforces application whitelisting natively on Windows servers, satisfying the hardening requirement without third-party agents.

Why this answer

AppLocker is a Windows built-in feature introduced in Windows 7 and Server 2008 R2 that allows administrators to create and enforce rules specifying which applications and files users can run. It uses a whitelisting model based on file attributes such as publisher, path, or hash, and can be configured via Group Policy or PowerShell cmdlets. By default, AppLocker blocks any executable not explicitly allowed, thus ensuring only approved executables run.

This directly meets the requirement for application whitelisting on Windows servers.

Exam trap

The trap here is confusing access control features like UAC or antivirus with application whitelisting; candidates may think UAC restricts applications, but it only controls elevation, not execution.

How to eliminate wrong answers

Option A is wrong because BitLocker is a full-disk encryption feature that protects data at rest, not an application control mechanism. Option B is wrong because Windows Defender Antivirus is a signature-based and heuristic malware detection tool; it does not enforce a whitelist of approved executables. Option D is wrong because User Account Control (UAC) manages privilege elevation for users and administrators, prompting for consent when administrative tasks are attempted; it does not restrict which applications can execute based on a whitelist.

54
MCQmedium

A company is deploying a new web application that will be accessible to the public. The security team wants to ensure that session identifiers cannot be predicted or reused by an attacker who captures one over an unencrypted network segment. Which control should be implemented to BEST address this risk?

A.Generate session identifiers using a cryptographically secure random number generator and transmit them only over TLS.
B.Encode session identifiers using Base64 to obscure their contents from casual observation.
C.Bind session identifiers to the client's IP address and user agent string for validation.
D.Store session identifiers in persistent cookies with long expiration times to reduce reauthentication.
AnswerA

Cryptographically secure random session identifiers resist prediction, and transmitting them only over TLS prevents interception on the network. Together these address both predictability and capture risks. This is the standard approach for protecting session tokens in public web applications and aligns with secure session management guidance.

Why this answer

The risk is twofold: an attacker might predict a session identifier or capture one on the network. Using a cryptographically secure random generator makes prediction infeasible, and requiring TLS for transmission prevents interception. Together they directly mitigate the described threat, whereas encoding, long-lived cookies, and client binding do not address the core weaknesses.

Exam trap

The trap here is confusing encoding with encryption, or assuming that binding a token to client attributes makes it safe even when it can still be captured in transit.

55
MCQeasy

Which Windows feature allows an administrator to define security policies such as password complexity and account lockout across multiple systems in a domain?

A.Local Security Policy
B.Security Audit Policies
C.Group Policy
D.User Account Control (UAC)
AnswerC

Group Policy centrally defines and enforces domain-wide security settings, including password complexity and account lockout thresholds, by linking Group Policy Objects to sites, domains, or organisational units. This satisfies the stem's requirement for applying consistent policies across multiple systems in a domain, unlike local policy, which applies to a single machine only.

Why this answer

Group Policy is the correct answer because it is a centralized management feature in Windows Active Directory that allows administrators to define and enforce security policies—such as password complexity, account lockout thresholds, and audit settings—across multiple systems in a domain. Group Policy Objects (GPOs) are linked to sites, domains, or organizational units (OUs) and are applied to computers and users at logon or startup, ensuring consistent policy enforcement. This centralized approach is essential for enterprise environments where local settings would be impractical to manage individually.

Exam trap

The trap here is confusing local security settings with domain-wide centralized management; candidates often pick Local Security Policy because it sounds similar, but it only affects one machine, not a domain.

How to eliminate wrong answers

Option A is wrong because Local Security Policy applies only to a single standalone Windows system and cannot be used to enforce policies across a domain; it is configured via secpol.msc and affects only the local machine. Option B is wrong because Security Audit Policies are a subset of security settings that determine what events are logged, but they do not provide a mechanism for defining and distributing password complexity or account lockout policies across multiple systems; they are typically configured within Group Policy or Local Security Policy. Option D is wrong because User Account Control (UAC) is a security feature that prompts for elevation when administrative tasks are performed, but it does not define or distribute security policies like password complexity or account lockout across a domain.

56
MCQmedium

A security auditor discovers that a Linux server has a user who can execute any command as root via sudo without a password. Which file should be reviewed to verify this configuration?

A./etc/shadow
B./etc/group
C./etc/sudoers
D./etc/passwd
AnswerC

/etc/sudoers defines sudo privileges, including NOPASSWD entries that let a user run commands as root without authentication. Reviewing it confirms the auditor's finding, since the sudoers policy is the authoritative source for this configuration rather than PAM or group membership files.

Why this answer

The /etc/sudoers file is the primary configuration file for the sudo command, defining which users or groups can run which commands on which hosts, and whether a password is required. A user with NOPASSWD: ALL in this file can execute any command as root without a password. Therefore, reviewing /etc/sudoers is the correct action to verify the auditor's finding.

Exam trap

SSCP often tests the distinction between authentication files (/etc/passwd, /etc/shadow) and authorization configuration files (/etc/sudoers), so candidates may incorrectly choose /etc/shadow because it relates to passwords, but the question specifically asks about sudo privileges.

How to eliminate wrong answers

Option A is wrong because /etc/shadow stores encrypted password hashes and password aging information for user accounts, not sudo privileges. Option B is wrong because /etc/group defines group memberships but does not specify sudo command permissions or password requirements. Option D is wrong because /etc/passwd contains basic user account information such as UID, GID, home directory, and default shell, but not sudo configuration.

57
MCQeasy

During a security assessment, you discover that a Windows server has the Telnet service running. Which of the following is the BEST action to harden the server against this finding?

A.Configure a host-based firewall to allow Telnet only from specific IPs
B.Enable encryption on Telnet
C.Remove the Telnet service and use SSH instead
D.Audit Telnet connections in Event Viewer
AnswerC

Telnet transmits credentials and session data in cleartext, so any network observer can capture them. Removing the service eliminates that exposure, while SSH provides encrypted, authenticated remote administration. Disabling or firewalling Telnet leaves the insecure service installed and re-enableable.

Why this answer

The best action is to remove Telnet and use SSH instead because Telnet transmits data, including credentials, in cleartext, making it inherently insecure. SSH provides encrypted communication, eliminating the vulnerability. Removing the service also reduces the attack surface.

Exam trap

SSCP often tests the misconception that restricting or monitoring Telnet makes it secure, when the fundamental flaw is lack of encryption, so replacement with SSH is the only proper hardening.

How to eliminate wrong answers

Option A is wrong because restricting Telnet by IP still leaves it unencrypted and vulnerable to interception; it does not address the core insecurity. Option B is wrong because Telnet does not support encryption natively; enabling encryption would require a different protocol like SSH. Option D is wrong because auditing Telnet connections is a detective measure, not a hardening action; it does not prevent exploitation.

58
MCQhard

A forensic analyst needs to review security events from multiple Windows servers. To ensure that logs are centrally collected and resistant to tampering, which of the following should be implemented?

A.Use Windows Event Forwarding to a central event collector
B.Store logs only on the local server and back them up weekly
C.Configure Event Viewer on each server to overwrite events as needed
D.Enable auditing of account logon events
AnswerA

Windows Event Forwarding uses the WS-Management protocol to push events from source servers to a central collector, where they are stored on a separate host. This centralisation means an attacker compromising one server cannot alter or delete the forwarded copies.

Why this answer

Windows Event Forwarding (WEF) uses the WS-Management/WinRM protocol to push selected event logs from source servers to a central Windows Event Collector (WEC) server. Because events are forwarded in near real time to a separate host, an attacker who compromises a source server cannot easily erase the already-forwarded copies, satisfying the tamper-resistance requirement. It also centralizes review, which is what the forensic analyst needs across multiple servers.

Exam trap

The trap is that candidates equate 'enable auditing' (Option D) with 'centralize and protect logs' — auditing generates events but does nothing to aggregate or harden them, which is the actual requirement.

How to eliminate wrong answers

Option B is wrong because storing logs only locally and backing them up weekly leaves a window in which an attacker can clear or alter the local Security log (event ID 1102) before the backup runs, and weekly backups are not tamper-resistant. Option C is wrong because configuring Event Viewer to overwrite events as needed destroys forensic evidence by design — log retention is reduced, not improved. Option D is wrong because enabling auditing of account logon events only generates the events; it does not collect or protect them centrally, so it addresses generation, not aggregation or integrity.

59
Multi-Selectmedium

During a virtualized environment security assessment, which THREE of the following are considered risks associated with virtual machine snapshots? (Select three.)

Select 3 answers
A.Snapshots may contain unpatched vulnerabilities
B.Sensitive data may persist in snapshots
C.Snapshots cause VM sprawl
D.Snapshots can be used to roll back security configurations
E.Snapshots can be used as an attack vector for VM escape
AnswersA, B, D

Snapshots capture the full VM state, including the guest OS and installed software, at the moment of creation. Restoring one reinstates that captured image, so any patches applied afterwards are lost, reintroducing the unpatched vulnerabilities the snapshot preserved. This directly satisfies the stem's requirement that snapshots constitute a risk.

Why this answer

Option A is correct because a snapshot captures the VM's disk state at a point in time, including the guest OS and installed applications; if that state predates patching, restoring or mounting the snapshot reintroduces unpatched vulnerabilities into the environment. Option B is correct because snapshots preserve the full contents of the virtual disks (and often memory state), so credentials, keys, and other sensitive data that were later deleted or rotated can persist inside snapshot files such as .vmdk delta disks or .avhd files. Option D is correct because rolling back to a snapshot reverts the entire VM state, including security settings, firewall rules, group policies, and patch levels, potentially undoing hardening or remediation performed after the snapshot was taken.

Option C is not a snapshot-specific risk; VM sprawl refers to the uncontrolled proliferation of VMs, not snapshot files, and is a lifecycle/governance issue rather than an inherent snapshot risk. Option E is not correct because VM escape exploits hypervisor or virtualization-layer vulnerabilities, not snapshots themselves; snapshots are a data-exposure and rollback concern, not a mechanism for escaping the VM boundary.

Exam trap

SSCP often tests the distinction between snapshot-specific risks and broader virtualization risks like VM sprawl or VM escape, causing candidates to select plausible but incorrect options.

60
Multi-Selectmedium

A security analyst is hardening a web application that stores user-uploaded images. The application currently writes uploads to a directory served directly by the web server. Which TWO controls BEST reduce the risk of a malicious upload leading to remote code execution? (Choose two.)

Select 2 answers
A.Validate the file's magic bytes and extension against an allowlist of permitted image formats.
B.Log every upload event with the client IP address and user agent for later review.
C.Store uploaded files outside the web root and serve them through a handler that sets Content-Type and Content-Disposition.
D.Increase the PHP upload_max_filesize directive to accommodate large images.
E.Rename each uploaded file to a random UUID while keeping the original extension.
AnswersA, C

Checking magic bytes and enforcing an extension allowlist ensures the file's actual content matches an expected image type, blocking polyglot files and scripts disguised with image extensions. This directly prevents a PHP or JSP payload from being accepted as a JPEG, which is a prerequisite for the upload-to-RCE chain described in the scenario.

Why this answer

Preventing upload-based remote code execution requires both validating that the content is genuinely an allowed image type and ensuring stored files can never be interpreted as executable code. Content inspection and an extension allowlist establish the first barrier, while storing files outside the web root with safe response headers removes the execution path entirely.

Exam trap

The trap here is treating operational hygiene such as filename randomization or logging as sufficient prevention, when the decisive controls are content validation and removing the file from any executable path.

61
MCQeasy

According to the shared responsibility model in cloud computing, which security responsibility belongs to the customer in a SaaS deployment?

A.Physical security of data centers
B.Securing the application code
C.Data classification and access controls
D.Managing the underlying operating system
AnswerC

In SaaS, the provider secures the application, runtime and underlying infrastructure, while the customer retains ownership of its data. Classifying that data and controlling who may access it therefore remain customer responsibilities, since only the customer understands its sensitivity and business access requirements.

Why this answer

In the shared responsibility model, the cloud provider always owns security *of* the cloud (physical facilities, hypervisor, host OS, and for SaaS the application itself), while the customer always owns security *in* the cloud — their data, identities, and access decisions. Data classification and access controls are therefore unambiguously customer responsibilities in every cloud service model, including SaaS. This is the one responsibility that never transfers to the provider.

Exam trap

The trap is that candidates assume SaaS means 'the provider secures everything' and pick an option like application code or OS management, forgetting that data and access control always stay with the customer.

How to eliminate wrong answers

Option A is wrong because physical security of data centers is always the cloud provider's responsibility in every deployment model (IaaS, PaaS, SaaS). Option B is wrong because in SaaS the provider develops, hosts, and maintains the application code — the customer only configures and uses it. Option D is wrong because managing the underlying operating system is the provider's job in SaaS and PaaS; it only becomes the customer's responsibility in IaaS.

62
MCQhard

A security analyst is reviewing a mobile application that stores authentication tokens in a location accessible to other applications on the same device. The development team wants to remediate this finding for both Android and iOS. Which change BEST addresses the vulnerability?

A.Keep tokens in memory only and require reauthentication whenever the application restarts.
B.Store tokens in a shared preferences file with file permissions restricted to the application's user ID.
C.Store tokens in the platform-provided secure storage such as the Android Keystore and iOS Keychain.
D.Encrypt the tokens with a hardcoded symmetric key embedded in the application binary.
AnswerC

Platform secure storage is designed to isolate secrets from other applications and, on supported hardware, to protect them with hardware-backed keys. Moving tokens there prevents other apps from reading them and addresses the finding directly on both platforms. This is the recommended remediation for insecure local storage of credentials or tokens.

Why this answer

The vulnerability is that tokens are readable by other applications. The platform secure storage mechanisms on Android and iOS are purpose-built to isolate secrets, and on capable hardware they can bind keys to the device's secure element. Hardcoded keys, permission-based files, and memory-only approaches either fail under realistic attacks or do not leverage the strongest available protection.

Exam trap

The trap here is accepting application-level encryption with a key embedded in the binary as equivalent to platform secure storage, when the key can be extracted by reverse engineering.

63
Multi-Selecthard

A security analyst is reviewing Linux audit logs with auditd. Which TWO events would be of greatest concern for a server that should not have interactive logins? (Select TWO.)

Select 2 answers
A.Successful root login via SSH
B.System reboot logs
C.Multiple failed su attempts
D.Successful cron job execution
E.File permission changes by a non-root user
AnswersA, C

A successful root SSH login directly violates the no-interactive-logins constraint, since it establishes an authenticated remote shell on the server. Root access also bypasses the least-privilege boundaries that should restrict administrative activity, making this event a high-priority indicator of compromise or misconfiguration.

Why this answer

Option A (Successful root login via SSH) is correct because a server that should not permit interactive logins should never show a successful root SSH session; this indicates either a policy violation or compromised credentials granting direct privileged interactive access. Option C (Multiple failed su attempts) is correct because repeated su failures signal an active attempt to escalate to another account (often root) interactively, which is a strong indicator of brute-force or unauthorized privilege-escalation activity on a host that should have no interactive users. Option B (System reboot logs) is not inherently concerning, as reboots are routine operational events and do not by themselves indicate interactive login or compromise.

Option D (Successful cron job execution) is normal scheduled behavior and does not represent an interactive login. Option E (File permission changes by a non-root user) may be worth reviewing, but a non-root user changing permissions on files they own is not as directly indicative of unauthorized interactive access as a successful root SSH login or repeated su failures.

Exam trap

The trap here is focusing on generic system events (reboots, cron) as security concerns while missing that the question specifically asks about a server that should not have interactive logins, making root SSH and su attempts the clear anomalies.

64
Multi-Selectmedium

A security engineer is hardening a Windows workstation. Which TWO configurations reduce the attack surface by limiting execution of unauthorized code? (Select TWO.)

Select 2 answers
A.Configure AppLocker rules
B.Enable Windows Firewall with Advanced Security
C.Enable BitLocker full-disk encryption
D.Enable Windows Defender Application Control (WDAC)
E.Disable AutoPlay
AnswersA, D

AppLocker enforces allow or deny rules based on publisher signature, file path or hash, so only approved executables, scripts and installers run. This directly limits execution of unauthorised code, satisfying the stem's attack-surface reduction constraint on the Windows workstation.

Why this answer

AppLocker (A) is correct because it uses allow/deny rules based on publisher, path, or file hash to control which executables, scripts, and installers users can run, directly restricting unauthorized code execution. Windows Defender Application Control (D) is also correct because WDAC enforces code integrity policies at the kernel level, allowing only trusted, signed binaries to execute and blocking unauthorized or tampered code. Windows Firewall with Advanced Security (B) filters network traffic by port, protocol, and profile but does not govern local code execution, so it does not meet the requirement.

BitLocker (C) provides full-disk encryption for data-at-rest confidentiality and does not prevent execution of unauthorized programs. Disabling AutoPlay (E) reduces a minor vector for automatic execution from removable media but is not a general code-execution control like AppLocker or WDAC.

Exam trap

SSCP often tests whether candidates can distinguish application control (AppLocker/WDAC) from network controls (firewall) and data protection (BitLocker) — a common mistake is selecting firewall or BitLocker as a way to limit code execution.

65
Multi-Selectmedium

An organization is implementing system hardening. Which of the following actions are recommended by CIS Benchmarks? (Select all that apply.)

Select 3 answers
A.Remove unnecessary services and accounts
B.Enable DHCP for all network interfaces
C.Disable autorun and autoplay features
D.Enable User Account Control (UAC)
E.Disable the host-based firewall
AnswersA, C, D

Removing unnecessary services and accounts shrinks the attack surface by eliminating unused daemons, listening ports and dormant credentials that attackers exploit for lateral movement or privilege escalation. This directly satisfies the CIS Benchmarks' hardening objective of reducing exploitable components to only those required for the system's documented business function.

Why this answer

Option A is correct because CIS Benchmarks emphasize reducing the attack surface by removing or disabling unnecessary services, applications, and accounts that are not required for the system's role. Option C is correct because CIS Benchmarks recommend disabling autorun and autoplay to prevent automatic execution of potentially malicious code from removable media and network drives. Option D is correct because enabling User Account Control (UAC) ensures administrative actions require explicit elevation and helps enforce least privilege on Windows systems.

Option B is incorrect because CIS Benchmarks generally recommend static IP configuration or controlled network settings for servers rather than enabling DHCP on all interfaces, which can introduce unauthorized or unpredictable network configuration. Option E is incorrect because CIS Benchmarks recommend enabling and properly configuring host-based firewalls, not disabling them, to filter inbound and outbound traffic.

Exam trap

SSCP often tests the difference between hardening actions and general system configurations; candidates may confuse enabling DHCP or disabling firewalls as security measures when they are not recommended by CIS Benchmarks.

66
Multi-Selecthard

A cloud operations team is hardening the management plane of its Infrastructure as a Service (IaaS) environment. The team wants to reduce the risk of unauthorized administrative access to the cloud console and APIs. Which TWO of the following controls best address this objective? (Choose two.)

Select 2 answers
A.Configure a content delivery network in front of public web endpoints
B.Enforce multi-factor authentication for all privileged accounts
C.Apply least-privilege identity and access management policies to administrative roles
D.Enable object storage versioning on application data buckets
E.Increase the size of the managed database instance class
AnswersB, C

Multi-factor authentication requires a second factor beyond a password, so a stolen or guessed credential alone cannot grant console or API access. Applying it to privileged accounts directly reduces the risk of unauthorized administrative access, which is the stated objective. This is a foundational control for protecting the management plane of any IaaS environment.

Why this answer

Protecting the cloud management plane requires strong authentication and tight authorization. Multi-factor authentication ensures that a compromised password alone cannot grant administrative access, while least-privilege IAM policies limit what any authenticated identity can do. Together they reduce the likelihood and impact of unauthorized administrative access.

The other choices concern storage durability, database sizing, and content delivery, none of which govern who can reach the console or APIs.

Exam trap

The trap here is treating any cloud hardening action as relevant to management-plane access, when controls like versioning or CDN configuration do not authenticate or authorize administrative identities.

67
MCQhard

A cloud security team is deploying a new web application on an IaaS platform. According to the shared responsibility model, which of the following security tasks is the customer responsible for?

A.Network infrastructure security such as DDoS protection at the provider edge
B.Hypervisor security and vulnerability management
C.Patching the guest operating system and web server software
D.Physical security of the data center hosting the servers
AnswerC

In IaaS, the provider secures the physical hosts, network and hypervisor only. The customer retains control of everything above the hypervisor, so patching the guest OS and web server software falls to them. This satisfies the shared responsibility split for IaaS workloads.

Why this answer

Patching the guest operating system and web server software is correct because in the IaaS shared responsibility model, the customer controls and is responsible for everything from the guest OS upward — including OS patches, middleware, runtime, and application code. The provider secures the physical hosts, hypervisor, and network fabric beneath the virtualization layer.

Exam trap

SSCP often tests where the responsibility boundary sits in IaaS — candidates over-attribute security tasks to the provider, forgetting that the customer owns the guest OS and everything above it.

How to eliminate wrong answers

Option A is wrong because DDoS protection at the provider edge is part of the cloud provider's responsibility for the underlying network infrastructure, not the customer's. Option B is wrong because hypervisor security and vulnerability management are handled by the cloud provider, since the hypervisor sits below the customer's control boundary in IaaS. Option D is wrong because physical security of data centers is always the provider's responsibility in every cloud service model.

68
MCQmedium

A company is deploying a web application in a containerized environment. The security team wants to ensure that if an attacker compromises the application, they cannot escalate privileges to the host or other containers. Which of the following container security measures should be implemented?

A.Run containers as a non-root user and drop unnecessary Linux capabilities.
B.Use a read-only root filesystem for the container.
C.Enable inter-container communication on the default bridge network.
D.Store container images in a private registry with vulnerability scanning.
AnswerA

Running as non-root and dropping capabilities follows the principle of least privilege. If the application is compromised, the attacker has limited permissions and cannot perform privileged operations like mounting filesystems or modifying kernel parameters. This significantly reduces the risk of container escape and lateral movement to the host or other containers.

Why this answer

The most effective runtime control to prevent privilege escalation and container escape is to run containers with least privilege: as a non-root user and with unnecessary Linux capabilities dropped. This limits the impact of a compromise. Other measures like read-only filesystems or private registries add defense in depth but do not directly address privilege escalation.

Exam trap

The trap here is focusing on image security or filesystem restrictions while overlooking the runtime privileges that determine what an attacker can do after compromising the container.

69
MCQmedium

A software vendor ships a Java-based payment service to a customer's data center. The customer's security team requires that the application run with only the minimum privileges necessary and cannot be trusted to restrict itself. Which mechanism should the security team use to enforce these restrictions on the JVM?

A.Java security policy files configured with a SecurityManager
B.Running the JVM as a Windows service under Local System
C.Enabling verbose garbage collection logging
D.Code signing the JAR with a trusted certificate
AnswerA

A Java security policy file lists the exact permissions granted to code, and the SecurityManager enforces them at runtime by checking each sensitive operation against the policy. This gives the security team an external, declarative way to restrict the application to only the privileges it needs, independent of how the application is written.

Why this answer

Java's SecurityManager works with a policy file that enumerates granted permissions, so code is denied anything not explicitly allowed. This lets the security team enforce least privilege from outside the application, which matches the requirement that the application itself not be trusted to limit its own access.

Exam trap

The trap here is assuming that signing an application's code automatically restricts what it can do, when signing addresses authenticity rather than runtime privilege.

70
MCQmedium

A company uses multiple virtual machines on a single hypervisor. To prevent a VM from escaping its virtualized environment and compromising the hypervisor, which of the following should be implemented?

A.Use a separate network for VM management traffic
B.Apply hypervisor security patches and disable unnecessary VM guest tools
C.Deploy a host-based firewall on each VM
D.Enable VM snapshots to restore in case of compromise
AnswerB

Patching the hypervisor closes known privilege-escalation vulnerabilities that permit VM escape, while removing unnecessary guest tools shrinks the guest-to-host attack surface, such as shared folders and clipboard channels. Together these directly satisfy the stem's requirement to stop a VM compromising the hypervisor.

Why this answer

The correct answer is B because VM escape attacks typically exploit vulnerabilities in the hypervisor itself or in the guest tools (like VMware Tools or VirtualBox Guest Additions) that run with elevated privileges. Applying hypervisor security patches closes known vulnerabilities that could allow a VM to break out, while disabling unnecessary guest tools reduces the attack surface that an attacker could leverage to interact with the hypervisor. Together, these measures directly harden the virtualization layer against escape attempts.

Exam trap

The trap here is confusing network segmentation or host-based firewalls with hypervisor-level security; candidates often pick option A or C because they think isolating management traffic or adding a firewall prevents escape, but the question specifically asks about preventing a VM from escaping its virtualized environment, which requires securing the hypervisor and guest tools.

How to eliminate wrong answers

Option A is wrong because a separate network for management traffic only isolates administrative access; it does not prevent a compromised VM from exploiting hypervisor vulnerabilities to escape. Option C is wrong because a host-based firewall on each VM filters network traffic but cannot stop a VM from exploiting a hypervisor bug or misconfigured guest tools to break isolation. Option D is wrong because snapshots are for recovery and rollback, not prevention; they do nothing to stop a VM escape and may even introduce additional attack surface if snapshot files are not secured.

71
MCQeasy

A healthcare provider must ensure that stored patient records remain unreadable if an attacker steals the physical disk from a database server. The server runs a mainstream Linux distribution and the requirement applies to the entire volume, not just individual files. Which control best meets this requirement?

A.Full disk encryption with LUKS on the data volume
B.Enforcing strict file permissions on the data directory
C.Enabling SELinux in enforcing mode on the server
D.Per-file encryption performed by the database engine
AnswerA

LUKS encrypts the block device itself, so every sector written to the volume is ciphertext while at rest. If the disk is removed and mounted elsewhere, the data is unreadable without the passphrase or key file. This satisfies whole-volume confidentiality for a stolen physical disk.

Why this answer

Whole-volume encryption converts all data on the block device into ciphertext at rest and requires a key to mount it. When the disk is stolen, the ciphertext is useless without that key, which directly satisfies the requirement to keep records unreadable after physical theft.

Exam trap

The trap here is confusing access control mechanisms like file permissions or SELinux with data-at-rest encryption, which are different layers solving different threats.

72
MCQmedium

A Linux system administrator needs to restrict network traffic to a server, allowing only HTTP and HTTPS from the internet. Which tool should be used to configure packet filtering rules?

A.PAM
B.SELinux
C.auditd
D.iptables
AnswerD

iptables is the Linux kernel's packet-filtering framework, configuring rules in the filter table to accept TCP ports 80 and 443 and drop other inbound traffic. It directly satisfies the requirement to restrict network traffic at the host level.

Why this answer

iptables is the standard Linux user-space utility for configuring the kernel's Netfilter packet filtering rules, including allowing only HTTP (TCP 80) and HTTPS (TCP 443) from the internet. It operates at the network layer and is the correct tool for host-based firewall configuration on Linux.

Exam trap

SSCP often tests tool-to-function mapping — candidates confuse security frameworks like SELinux or auditing tools like auditd with packet filtering tools.

How to eliminate wrong answers

Option A is wrong because PAM (Pluggable Authentication Modules) handles authentication and session management, not packet filtering. Option B is wrong because SELinux is a mandatory access control framework that confines processes and files, not a network packet filter. Option C is wrong because auditd is the Linux auditing daemon that logs system events for compliance and forensics, not a firewall tool.

73
MCQeasy

A web application is vulnerable to SQL injection. Which security control would be MOST effective at detecting and blocking such attacks at the network perimeter?

A.Intrusion Detection System (IDS)
B.Web Application Firewall (WAF)
C.Application whitelisting
D.Host-based firewall
AnswerB

A Web Application Firewall inspects HTTP traffic at the network perimeter, matching request patterns against signatures for SQL injection and blocking malicious payloads before they reach the application, satisfying the requirement to detect and block attacks at the perimeter.

Why this answer

A Web Application Firewall (WAF) inspects HTTP/HTTPS traffic at the application layer and can detect and block SQL injection patterns using signature-based and anomaly-based rules (e.g., OWASP Core Rule Set). It sits at the network perimeter in front of the web application, making it the most effective control for this requirement.

Exam trap

SSCP often tests the distinction between detection and prevention — candidates may pick IDS because it 'detects' SQL injection, but the question asks for a control that both detects and blocks at the perimeter, which only a WAF does.

How to eliminate wrong answers

Option A is wrong because an IDS only detects and alerts on suspicious traffic — it does not block attacks, and it is not specifically tuned to parse HTTP payloads for SQL injection signatures. Option C is wrong because application whitelisting controls which executables can run on a host, not which HTTP requests reach a web application. Option D is wrong because a host-based firewall filters traffic by IP, port, and protocol — it cannot inspect HTTP payloads for SQL injection strings.

74
MCQhard

A healthcare organization is deploying a containerized patient records application on Kubernetes. The security team wants to prevent a compromised container from accessing the underlying node's filesystem and from escalating privileges. Which Kubernetes control should be configured to restrict the container's capabilities and prevent privilege escalation?

A.Configure a resource quota that limits CPU and memory for the pod.
B.Enable PodSecurityPolicy with the privileged profile applied to the namespace.
C.Set the pod's securityContext to allowPrivilegeEscalation: false and drop all Linux capabilities.
D.Configure a NetworkPolicy that denies all ingress and egress traffic to the pod.
AnswerC

The securityContext fields allowPrivilegeEscalation and capabilities directly control whether a process can gain more privileges than its parent and which Linux capabilities are available. Setting allowPrivilegeEscalation to false blocks setuid and similar escalation paths, while dropping capabilities removes the ability to perform privileged operations such as mounting filesystems or modifying kernel parameters. This precisely mitigates the described risk.

Why this answer

Restricting a container's privileges requires configuring its securityContext to prevent privilege escalation and to drop unnecessary Linux capabilities. These settings directly limit what the container process can do on the host, including mounting filesystems or using privileged system calls. Network policies, privileged pod security profiles, and resource quotas address different concerns and do not prevent host filesystem access or privilege escalation.

Exam trap

The trap here is confusing network isolation or resource limits with process-level privilege restriction, when only securityContext capability and privilege escalation settings control what the container process can do on the host.

75
MCQmedium

A security administrator is deploying a new web application on a Linux server. The application must be isolated from the host and other applications, and it must only be able to read its own configuration files. The administrator decides to use a container. Which of the following should the administrator implement to meet these requirements?

A.Run the container as the root user to ensure it has permission to read the configuration files.
B.Run the container with the --privileged flag to ensure it has all necessary permissions.
C.Disable all Linux capabilities for the container to prevent any file access.
D.Use a read-only root filesystem and mount only the required configuration files as a read-only volume.
AnswerD

A read-only root filesystem prevents the container from modifying its own files, and mounting only the necessary configuration files as read-only volumes enforces least privilege. This meets the requirement that the application can only read its own configuration files while being isolated from the host and other applications.

Why this answer

The requirement is to isolate the application and restrict it to reading only its own configuration files. A read-only root filesystem combined with read-only volume mounts for specific configuration files enforces this least-privilege model. Other options either grant excessive privileges or break functionality by removing all capabilities.

Exam trap

The trap here is assuming that running a container as root or with privileged flags is necessary for it to function, when in fact it increases the attack surface and violates isolation.

Page 1 of 2 · 101 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Sscp Systems App Security questions.