easyMultiple Choice
SSCP Practice Question: The security analyst at a mid-sized retail…
You are the security analyst at a mid-sized retail company with 500 employees. The company recently experienced a ransomware attack that encrypted files on a file server. The infection was traced to a phishing email opened by an employee in accounting. The company has antivirus software, a firewall, and daily backups. After the incident, management wants to improve risk identification to prevent future attacks. Which of the following is the MOST effective first step to improve risk identification?
⚠ Common exam trap
Many candidates confuse reactive detection/response tools (SIEM, DLP, forensic log review) with the proactive risk-identification discipline the question asks for — candidates gravitate to the 'shiny' security product instead of the process step.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a risk assessment that includes threat modeling and vulnerability scanning
A risk assessment with threat modeling and vulnerability scanning is the foundational, proactive step that identifies, quantifies, and prioritizes risks across the environment — including the phishing vector that caused this incident. Threat modeling maps attack paths (e.g., email → endpoint → file server), while vulnerability scanning surfaces unpatched systems and misconfigurations. Together they produce the risk register and treatment plan that all subsequent controls (DLP, SIEM) should be justified against.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement a data loss prevention (DLP) solution to monitor email traffic
Why it's wrong here
DLP monitors outbound data movement to prevent exfiltration; it does not identify how the phishing email bypassed controls or which risks enabled the ransomware. It is tempting because email is the infection vector, but DLP suits protecting sensitive data leaving the organisation, not mapping attack pathways for risk identification.
- ✓
Conduct a risk assessment that includes threat modeling and vulnerability scanning
Why this is correct
A risk assessment combining threat modelling and vulnerability scanning systematically identifies weaknesses across people, process, and technology, satisfying management's goal of improving risk identification after the phishing-led ransomware incident rather than merely reacting to it.
- ✗
Deploy a SIEM system to aggregate logs from all systems
Why it's wrong here
Aggregating logs detects and correlates events after they occur; it does not enumerate threats, vulnerabilities or likelihoods, which is what risk identification requires. SIEM deployment is the right choice when the goal is real-time detection and incident response across many sources, not the initial risk-identification step after a phishing-driven ransomware incident.
- ✗
Review the logs of the compromised file server for forensic details
Why it's wrong here
Reviewing one file server's logs reconstructs a single past compromise; it produces no forward-looking inventory of threats, vulnerabilities or business impact across the 500-employee estate. Forensic log review is correct when scoping an active incident or supporting legal action, not when management asks for broader risk identification.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.