Courseiva
easyMultiple Choice

SSCP Practice Question: The security analyst at a mid-sized retail…

You are the security analyst at a mid-sized retail company with 500 employees. The company recently experienced a ransomware attack that encrypted files on a file server. The infection was traced to a phishing email opened by an employee in accounting. The company has antivirus software, a firewall, and daily backups. After the incident, management wants to improve risk identification to prevent future attacks. Which of the following is the MOST effective first step to improve risk identification?

⚠ Common exam trap

Many candidates confuse reactive detection/response tools (SIEM, DLP, forensic log review) with the proactive risk-identification discipline the question asks for — candidates gravitate to the 'shiny' security product instead of the process step.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a risk assessment that includes threat modeling and vulnerability scanning

A risk assessment with threat modeling and vulnerability scanning is the foundational, proactive step that identifies, quantifies, and prioritizes risks across the environment — including the phishing vector that caused this incident. Threat modeling maps attack paths (e.g., email → endpoint → file server), while vulnerability scanning surfaces unpatched systems and misconfigurations. Together they produce the risk register and treatment plan that all subsequent controls (DLP, SIEM) should be justified against.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement a data loss prevention (DLP) solution to monitor email traffic

    Why it's wrong here

    DLP monitors outbound data movement to prevent exfiltration; it does not identify how the phishing email bypassed controls or which risks enabled the ransomware. It is tempting because email is the infection vector, but DLP suits protecting sensitive data leaving the organisation, not mapping attack pathways for risk identification.

  • ✓

    Conduct a risk assessment that includes threat modeling and vulnerability scanning

    Why this is correct

    A risk assessment combining threat modelling and vulnerability scanning systematically identifies weaknesses across people, process, and technology, satisfying management's goal of improving risk identification after the phishing-led ransomware incident rather than merely reacting to it.

  • ✗

    Deploy a SIEM system to aggregate logs from all systems

    Why it's wrong here

    Aggregating logs detects and correlates events after they occur; it does not enumerate threats, vulnerabilities or likelihoods, which is what risk identification requires. SIEM deployment is the right choice when the goal is real-time detection and incident response across many sources, not the initial risk-identification step after a phishing-driven ransomware incident.

  • ✗

    Review the logs of the compromised file server for forensic details

    Why it's wrong here

    Reviewing one file server's logs reconstructs a single past compromise; it produces no forward-looking inventory of threats, vulnerabilities or business impact across the 500-employee estate. Forensic log review is correct when scoping an active incident or supporting legal action, not when management asks for broader risk identification.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.