Courseiva

SSCP Systems and Application Security Practice Question

Which Windows feature allows an administrator to define security policies such as password complexity and account lockout across multiple systems in a domain?

⚠ Common exam trap

Candidates often confuse local security settings with domain-wide centralized management; candidates often pick Local Security Policy because it sounds similar, but it only affects one machine, not a domain.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Group Policy

Group Policy is the correct answer because it is a centralized management feature in Windows Active Directory that allows administrators to define and enforce security policies—such as password complexity, account lockout thresholds, and audit settings—across multiple systems in a domain. Group Policy Objects (GPOs) are linked to sites, domains, or organizational units (OUs) and are applied to computers and users at logon or startup, ensuring consistent policy enforcement. This centralized approach is essential for enterprise environments where local settings would be impractical to manage individually.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Local Security Policy

    Why it's wrong here

    Local Security Policy applies only to the individual machine where it is configured, so it cannot enforce password complexity or lockout across domain systems. It is tempting because it exposes the same settings, and it would be correct for a standalone workgroup computer outside Active Directory.

  • ✗

    Security Audit Policies

    Why it's wrong here

    Security Audit Policies log events such as logon attempts and privilege use; they do not set password complexity or lockout thresholds. Auditing is tempting because it also lives under Security Settings, and it would be the right choice when the requirement is to record and review activity rather than enforce account restrictions.

  • ✓

    Group Policy

    Why this is correct

    Group Policy centrally defines and enforces domain-wide security settings, including password complexity and account lockout thresholds, by linking Group Policy Objects to sites, domains, or organisational units. This satisfies the stem's requirement for applying consistent policies across multiple systems in a domain, unlike local policy, which applies to a single machine only.

  • ✗

    User Account Control (UAC)

    Why it's wrong here

    UAC controls privilege elevation prompts for individual actions, not domain-wide password complexity or lockout settings. It is tempting because it is a Windows security feature administrators configure, and it would be correct when the requirement is restricting standard users from performing administrative tasks without consent.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.