Courseiva

SSCP · topic practice

Systems and Application Security practice questions

This domain covers securing hosts, applications, and virtual/cloud infrastructure. Questions present operational scenarios about hardening servers, managing virtualization risk, applying application controls, and splitting security duties in cloud service models. You must identify the correct tool, file, or responsibility owner rather than recite theory.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Systems and Application Security

What the exam tests

What to know about Systems and Application Security

Be able to match a scenario to the right control: sudoers for Linux privilege checks, AppLocker for Windows whitelisting, customer responsibility for IaaS workloads, and lifecycle governance for VM sprawl. The most important thing is correctly assigning responsibility and choosing the precise tool or file.

Windows AppLocker and Software Restriction Policies for application whitelisting on hardened servers

Linux sudoers file and sudo configuration for privilege escalation review

Cloud shared responsibility: customer duties under IaaS versus provider duties

Virtual machine sprawl controls such as lifecycle management, inventory, and decommissioning

Watch out for

Common Systems and Application Security exam traps

  • ▸Assuming the cloud provider secures guest OS patching, application data, and identity under IaaS when those remain customer duties
  • ▸Confusing AppLocker with antivirus or firewall features instead of application whitelisting enforcement
  • ▸Reviewing /etc/passwd or /etc/shadow for sudo rights instead of the sudoers configuration file

Practice set

Systems and Application Security questions

20 questions · select your answer, then reveal the explanation

A security analyst is reviewing security events on a Linux server and needs to ensure that all authentication attempts, including both successful and failed logins, are logged. Which configuration should be used?

Which of the following is a primary security concern when using VM snapshots in a virtualized environment?

A company is deploying a web application and wants to protect against OWASP Top 10 attacks. Which THREE controls should be implemented? (Select THREE.)

A security engineer is evaluating cloud security tools. Which TWO of the following are primarily used to protect cloud workloads? (Select two.)

A security analyst notices that a Linux server has an unusual number of failed login attempts for the root account. To strengthen authentication security while preserving administrative access, which of the following configurations would be most effective?

A security administrator is configuring Windows Firewall with Advanced Security for a web server. The requirement is to allow inbound HTTPS traffic but block all other inbound traffic. Which of the following rule configurations best meets this requirement?

A security analyst is reviewing application security and identifies risks related to the OWASP Top 10. Which THREE are examples of OWASP Top 10 vulnerabilities? (Select THREE.)

A cloud security team is implementing CSPM (Cloud Security Posture Management) for their IaaS environment. Which THREE issues is CSPM MOST likely to detect? (Select THREE.)

A security analyst is investigating a potential security incident on a Linux server. The analyst suspects that an attacker has gained root access and installed a rootkit. Which of the following commands would be most effective in detecting the presence of a rootkit by comparing system binaries against known good hashes?

A security engineer is implementing controls to protect a web application from session hijacking attacks. Which TWO of the following measures are MOST effective in preventing an attacker from stealing or reusing a valid session token? (Choose two.)

A security analyst is investigating a suspected malware infection on a Windows workstation. The analyst observes that a process named 'svchost.exe' is making outbound connections to an unknown IP address. Which of the following should the analyst do FIRST to determine if this is malicious activity?

A security engineer is configuring a containerized application in a production Kubernetes cluster. The engineer wants to prevent a compromised container from accessing the host's metadata service to retrieve cloud credentials and from mounting sensitive host paths. Which Kubernetes security control should the engineer implement?

A security administrator is implementing application whitelisting on a fleet of Windows 10 workstations. The administrator wants to use AppLocker to allow only signed applications from trusted publishers to run, while blocking all other executables. Which TWO of the following AppLocker rule conditions should the administrator use to achieve this? (Choose two.)

During a security assessment, it is discovered that a Linux server has unnecessary services running, including Telnet and FTP. The server is also missing critical security patches. Which of the following is the MOST effective approach to harden this server according to industry best practices?

An organization wants to prevent unauthorized applications from running on Windows workstations. Which Windows feature should be used to enforce application whitelisting?

A cloud security team is deploying a new web application on an IaaS platform. According to the shared responsibility model, which of the following security tasks is the customer responsible for?

Question 17mediummultiple choice
Study the full virtualization explanation →

A company uses multiple virtual machines on a single hypervisor. To prevent a VM from escaping its virtualized environment and compromising the hypervisor, which of the following should be implemented?

In Linux, which command is used to change file permissions to restrict access so that only the owner can read and write, and the group and others have no access?

An application security team is reviewing code for vulnerabilities. They find that user input is directly concatenated into an SQL query without sanitization. This is an example of which OWASP Top 10 vulnerability?

A cloud security team is using Cloud Security Posture Management (CSPM) to identify misconfigurations. Which of the following scenarios is MOST likely to be detected by CSPM?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Systems and Application Security sessions

Start a Systems and Application Security only practice session

Every question in these sessions is drawn from the Systems and Application Security domain — nothing else.

Related practice questions

Related SSCP topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SSCP exam test about Systems and Application Security?
Be able to match a scenario to the right control: sudoers for Linux privilege checks, AppLocker for Windows whitelisting, customer responsibility for IaaS workloads, and lifecycle governance for VM sprawl. The most important thing is correctly assigning responsibility and choosing the precise tool or file.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Systems and Application Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Systems and Application Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SSCP topics?
Use the topic links above to move to related areas, or go back to the SSCP question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SSCP exam covers. They are not copied from any real exam or dump site.