Courseiva

SSCP Security Operations and Administration Practice Question

Which of the following is the PRIMARY purpose of implementing a clean desk policy?

⚠ Common exam trap

A common mix-up: candidates confuse a clean desk policy with general workplace organization or fire safety, overlooking its core role as a physical security control to protect confidential data from unauthorized access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To reduce the risk of data breaches

A clean desk policy is a physical security control designed to prevent unauthorized access to sensitive information by ensuring that documents, devices, and media are securely stored when not in use. By reducing the visibility of confidential data, it directly mitigates the risk of data breaches from shoulder surfing, theft, or accidental exposure. This aligns with the principle of least exposure and supports compliance with data protection frameworks like GDPR or HIPAA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To lower office cleaning costs

    Why it's wrong here

    A clean desk policy protects information assets by removing sensitive documents and credentials from unattended workspaces, reducing unauthorised viewing or theft; cost reduction is incidental. It is tempting because tidier desks do reduce cleaning effort, and would be correct if the objective were facilities management rather than information security.

  • ✗

    To comply with fire safety regulations

    Why it's wrong here

    A clean desk policy protects information assets by removing sensitive documents and media from unattended workspaces; fire safety is governed by building codes and fire wardens, not data-handling rules. It is tempting because cleared desks do reduce combustible clutter, but that is a coincidental side effect, not the policy's primary purpose.

  • ✓

    To reduce the risk of data breaches

    Why this is correct

    Unattended documents, unlocked screens and exposed media let anyone with physical access copy or photograph sensitive data. A clean desk policy removes that opportunistic exposure, directly lowering the likelihood of a data breach rather than merely improving tidiness or audit compliance.

  • ✗

    To improve employee productivity

    Why it's wrong here

    A clean desk policy restricts sensitive documents and media left unattended, reducing unauthorised viewing or theft; productivity is not its objective. It is tempting because tidier desks can appear to aid efficiency, but that is a side effect, not the security control's primary purpose.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.