View Full ISC SSCP Exam Dumps and Practice Test Dumps.
Question 101
An organization wants to prevent sensitive files from being copied to unauthorized external storage devices. Which endpoint control is most appropriate?
- Increase monitor resolution
- Restrict and monitor removable storage access
- Disable system time synchronization
- Increase local disk capacity
Correct Answer: 2
Explanation
Restricting and monitoring removable storage access can prevent unauthorized copying of sensitive information to external devices. Endpoint controls may allow only approved encrypted devices, block specific storage classes, or generate alerts when prohibited transfer attempts occur. Organizations should define exceptions for legitimate business requirements and monitor policy violations for investigation. Technical restrictions should be supported by data classification and user awareness. Increasing storage capacity or monitor resolution does not control data movement, while disabling time synchronization can make security investigations more difficult by creating inconsistent timestamps across systems.
Question 102
A security administrator wants to ensure that an employee cannot use an old access badge after transferring to another facility. Which action should be performed?
- Increase the badge’s expiration period
- Duplicate the badge
- Update physical access permissions
- Share the badge with the new facility
Correct Answer: 3
Explanation
Physical access permissions should be updated when an employee changes facilities so that the badge grants only the access required for the employee’s new responsibilities. Access-control systems should support timely modification or revocation of permissions based on authoritative personnel changes. Organizations should periodically review badge assignments and investigate unusual access attempts. Extending the expiration period or duplicating an existing badge can increase unauthorized access risk. Physical access management should also include procedures for lost badges, terminated employees, visitors, contractors, and emergency access to maintain accountability across the facility.
Question 103
A company is implementing a new security appliance and wants to verify that its default credentials have been removed. What should the administrator do?
- Keep vendor credentials unchanged
- Publish the default password internally
- Disable all administrative logging
- Change or disable default accounts and credentials
Correct Answer: 4
Explanation
Default accounts and credentials are widely known and can provide attackers with an easy path into newly deployed systems. Administrators should change default passwords, disable unnecessary default accounts, and configure unique administrative credentials before placing the appliance into production. Where supported, administrators should also enable strong authentication and restrict management access to authorized networks or systems. Security configuration checklists can help identify other insecure defaults. Publishing default credentials or leaving them unchanged increases exposure, while disabling administrative logging removes valuable accountability and makes unauthorized configuration changes harder to investigate.
Question 104
A security team wants to ensure that an application does not trust user-supplied data when constructing database queries. Which secure development practice is most relevant?
- Input validation and parameterized queries
- Larger database storage
- Disabling application logging
- Sharing database administrator credentials
Correct Answer: 1
Explanation
Input validation and parameterized queries help prevent untrusted user input from being interpreted as executable database commands. Parameterized queries separate application data from SQL instructions, reducing the likelihood of injection attacks. Input validation can further restrict data to expected formats, ranges, or character sets according to the application’s requirements. Developers should also apply appropriate database permissions, error handling, and secure coding practices. Increasing storage capacity does not address injection vulnerabilities, while disabling logs or sharing administrator credentials can create additional security and accountability problems.
Question 105
A security administrator needs to confirm that a backup file has not been modified since it was created. Which mechanism can help verify its integrity?
- File compression
- Cryptographic hash comparison
- Screen locking
- Network address translation
Correct Answer: 2
Explanation
A cryptographic hash can be calculated for a backup file when it is created and recalculated later to determine whether the file’s contents have changed. If the expected and newly calculated hash values match, the organization gains evidence that the file contents have remained unchanged, assuming the original hash was protected from unauthorized modification. Hashes are useful for integrity verification but do not provide confidentiality. Organizations should also protect backup storage, restrict access to verification records, and periodically perform restoration testing. Compression, screen locking, and network address translation serve different technical purposes.
Question 106
A company wants to reduce the risk that employees will connect corporate laptops to unsafe wireless networks while traveling. Which control is most appropriate?
- Allow unrestricted wireless connections
- Disable all endpoint security
- Enforce approved wireless connection policies
- Publish corporate network credentials
Correct Answer: 3
Explanation
Approved wireless connection policies can restrict corporate devices from connecting to networks that fail organizational security requirements. Endpoint management can enforce trusted network settings, require secure configurations, warn users about unsafe connections, and direct traffic through approved protected channels where appropriate. User training should explain the risks of unfamiliar wireless networks and provide clear procedures for remote connectivity. Allowing unrestricted connections increases exposure to malicious or insecure networks, while disabling endpoint protection removes additional safeguards. Publishing corporate credentials can create another avenue for unauthorized access and should be avoided.
Question 107
An organization wants to determine whether a security control remains effective after a major infrastructure change. What should be performed?
- Post-change control validation
- Delete the previous configuration records
- Disable monitoring temporarily
- Assume the control remains effective
Correct Answer: 1
Explanation
Post-change control validation determines whether security safeguards continue to operate as intended after infrastructure modifications. Changes to network architecture, operating systems, applications, identities, or cloud services can unintentionally weaken existing controls. Validation may include configuration checks, functional testing, log review, access testing, and comparison against approved requirements. Previous records should be retained because they provide useful evidence for understanding what changed. Disabling monitoring can hide problems, while assuming effectiveness without testing leaves potential control failures undiscovered. Security validation should be incorporated into change processes for significant infrastructure modifications.
Question 108
A security team is designing access to a highly sensitive application. Users should be allowed to perform only specific approved actions, such as viewing records but not deleting them. Which mechanism directly supports this requirement?
- Role or attribute-based authorization
- Increased network bandwidth
- File compression
- Screen brightness control
Correct Answer: 1
Explanation
Role-based or attribute-based authorization can restrict users to specific operations according to their assigned responsibilities or defined attributes. For example, one role may permit viewing records while another authorized role may perform approved administrative actions. Authorization should be enforced on the server rather than relying solely on interface restrictions. Access rules should be tested to confirm that unauthorized operations are denied and that permissions match business requirements. Network bandwidth and display settings do not control application actions, while file compression affects storage or transmission efficiency rather than authorization decisions.
Question 109
A company wants to ensure that security-relevant applications generate records that can support future investigations. Which requirement is most important?
- Disable event generation
- Define appropriate security logging requirements
- Remove timestamps from events
- Allow applications to overwrite all historical records immediately
Correct Answer: 2
Explanation
Security logging requirements should define which events applications need to record, the information each event should contain, retention expectations, protection requirements, and appropriate access to the records. Useful events may include authentication activity, authorization failures, administrative changes, security exceptions, and significant data access. Accurate timestamps and consistent event formats improve correlation across systems. Logs should be protected from unauthorized alteration and retained according to organizational requirements. Disabling event generation or removing timestamps can significantly reduce investigative value, while immediately overwriting historical records may eliminate evidence needed for incident analysis.
Question 110
A security administrator wants to prevent a compromised endpoint from communicating with known malicious destinations. Which control can provide this capability?
- Egress filtering and threat-intelligence-based blocking
- Increased printer capacity
- Password sharing
- Removal of endpoint monitoring
Correct Answer: 1
Explanation
Egress filtering can restrict outbound connections based on approved destinations, protocols, ports, or other security policies. When combined with reliable threat intelligence, organizations may block communication with known malicious infrastructure. This can limit command-and-control traffic and reduce the ability of compromised systems to communicate externally. Blocking decisions should be carefully managed because threat-intelligence data can change and legitimate services may share infrastructure. Organizations should monitor blocked connections and investigate significant events. Printer capacity and password sharing do not address malicious outbound communication, while removing endpoint monitoring reduces visibility into compromised devices.
Question 111
A company wants to make sure that a sensitive application can continue operating if its primary database server fails. Which architectural capability supports this objective?
- Single-server dependency
- High availability through redundancy
- Unrestricted user permissions
- Disabled database monitoring
Correct Answer: 2
Explanation
High availability through redundancy can allow an application to continue operating when a primary database component fails. Depending on the architecture, organizations may use replicated databases, clustered systems, failover mechanisms, redundant network paths, or geographically separate infrastructure. The design should consider data consistency, recovery objectives, failure detection, and testing requirements. Redundancy is effective only when failover mechanisms are properly configured and periodically tested. A single-server dependency creates a potential single point of failure, while unrestricted permissions and disabled monitoring do not improve service resilience or protect database availability.
Question 112
A security officer is reviewing an agreement with a service provider that stores organizational data. Which contractual requirement can help ensure that security incidents are reported promptly?
- Defined incident notification obligations
- Unlimited data access for the provider
- Removal of audit rights
- Permanent retention of all information
Correct Answer: 1
Explanation
Defined incident notification obligations establish when and how a service provider must inform the organization about security incidents affecting contracted services or information. Contracts may specify notification timelines, communication channels, available incident details, cooperation requirements, evidence preservation, and responsibilities for regulatory reporting where applicable. Clear contractual language helps prevent delays caused by uncertainty about responsibilities. Unlimited provider access can increase exposure, while removing audit rights reduces oversight. Permanent data retention may also conflict with organizational requirements. Third-party security obligations should be proportionate to the services provided and the sensitivity of the information involved.
Question 113
A security administrator wants to ensure that only approved software packages can be installed on managed Linux servers. Which approach is most appropriate?
- Permit installation from any source
- Use controlled repositories and package management policies
- Disable package verification
- Share the root password with developers
Correct Answer: 2
Explanation
Controlled repositories and package management policies help administrators ensure that software installed on managed servers comes from approved and trusted sources. Organizations can restrict repositories, verify package signatures where supported, define approved versions, and monitor installation activity. This reduces the likelihood of introducing malicious or unauthorized software. Developers and administrators should receive appropriate privileges without sharing root credentials. Allowing installation from arbitrary sources increases supply-chain and malware risks, while disabling package verification removes an important integrity check. Package management should also support timely updates and removal of software that is no longer required.
Question 114
A security team wants to determine whether an employee’s account should retain access to a sensitive financial application. Which review is most appropriate?
- Periodic access recertification
- Monitor replacement
- Network cable testing
- Printer configuration review
Correct Answer: 1
Explanation
Periodic access recertification requires appropriate managers or resource owners to confirm that users still need their assigned access. This process can identify outdated permissions resulting from role changes, transfers, or changes in business responsibilities. Sensitive applications should receive particular attention because inappropriate access may expose confidential or regulated information. Recertification should be documented, completed at defined intervals, and followed by timely removal of unnecessary permissions. Hardware-related reviews such as monitor, network cable, or printer checks do not determine whether an employee remains authorized to access a financial application.
Question 115
A company is preparing to deploy an endpoint security agent across thousands of systems. What should administrators establish before broad deployment?
- A tested deployment and rollback procedure
- Unrestricted installation without validation
- A policy prohibiting system monitoring
- Shared administrator passwords
Correct Answer: 1
Explanation
A tested deployment and rollback procedure helps organizations introduce endpoint security software while controlling operational and security risks. Administrators should evaluate compatibility, performance, required privileges, network dependencies, logging, and possible conflicts with existing software. A pilot deployment can identify issues before the agent is installed across the entire environment. Rollback procedures provide a controlled response if unexpected problems affect business operations. Unrestricted deployment without validation may cause widespread disruption, while disabling monitoring or sharing administrator passwords creates additional weaknesses. Large-scale security deployments should be planned, tested, documented, and monitored.
Question 116
A security analyst identifies an endpoint that may be actively compromised. Which containment action can limit the system’s ability to affect other network resources?
- Increase its network privileges
- Isolate the endpoint from the network
- Publish its credentials
- Disable all evidence collection
Correct Answer: 2
Explanation
Isolating a potentially compromised endpoint from the network can limit its ability to communicate with other systems, spread malware, or access additional resources. Isolation should follow established incident response procedures and account for business requirements, especially when the affected device supports critical operations. Where feasible, responders should preserve relevant evidence before making changes that could destroy useful information. Increasing privileges or publishing credentials would worsen the situation, while disabling evidence collection can hinder investigation. Network isolation is a containment measure rather than a complete remediation strategy, so the system should subsequently be analyzed and securely restored.
Question 117
A company wants to ensure that confidential information is not accidentally exposed through screenshots or screen-sharing sessions. Which approach can help reduce this risk?
- Apply data handling policies and appropriate endpoint or application restrictions
- Disable all user authentication
- Publish confidential information internally
- Remove security awareness training
Correct Answer: 1
Explanation
Data handling policies combined with appropriate endpoint or application restrictions can reduce accidental exposure through screenshots and screen-sharing. Depending on the environment, organizations may restrict screen capture for sensitive applications, control remote-session capabilities, apply information protection labels, and educate users about approved handling procedures. Technical controls should be carefully evaluated because legitimate workflows may require screen sharing or capture. Removing authentication or publishing confidential information would increase exposure, while eliminating awareness training removes an important preventive layer. Organizations should identify particularly sensitive workflows and apply controls proportionate to their information protection requirements.
Question 118
A security administrator is investigating a suspicious administrator action and needs to determine whether the event was generated by a legitimate management tool. Which information is particularly useful?
- Event source, timestamp, account, and originating system
- Office furniture inventory
- Employee clothing preferences
- Building paint schedule
Correct Answer: 1
Explanation
Event source, timestamp, account, and originating system provide useful context when determining whether an administrator action came from an expected management tool. Analysts can correlate these details with change records, authorized maintenance windows, endpoint information, and network activity. Reliable timestamps and consistent system identifiers improve investigation accuracy. The presence of an administrator account does not automatically establish that an action was authorized. Security teams should preserve relevant records and avoid altering evidence unnecessarily during investigation. Unrelated information such as furniture inventory or building maintenance does not provide meaningful evidence about the legitimacy of an administrative action.
Question 119
A company wants to reduce the risk that employees will unknowingly execute malicious attachments received through email. Which combination provides useful protection?
- Email filtering, attachment analysis, and user awareness
- Larger mailbox quotas only
- Disabled endpoint protection
- Automatic execution of every attachment
Correct Answer: 1
Explanation
Email filtering, attachment analysis, and user awareness provide complementary protection against malicious attachments. Filtering can identify known malicious content, attachment analysis can examine suspicious files or behavior, and awareness training can help users recognize unexpected or deceptive messages. Endpoint protection provides an additional layer if a malicious file reaches a device. No single control is guaranteed to stop every threat, so layered defenses are important. Larger mailbox quotas do not improve attachment security, while disabling endpoint protection or automatically executing attachments significantly increases the likelihood and potential impact of successful malware delivery.
Question 120
An organization wants to confirm that an employee who left the company no longer has active credentials in a SaaS application. Which evidence is most useful?
- Current account status and authentication records from the SaaS platform
- Employee’s old desk location
- Office supply inventory
- Marketing department schedule
Correct Answer: 1
Explanation
Current account status and authentication records from the SaaS platform can provide evidence that the former employee’s account has been disabled and has not continued authenticating. Administrators should verify account status, active sessions, tokens, delegated access, and other authentication mechanisms where applicable. Offboarding should cover direct accounts as well as access through groups, service integrations, and federated identity systems. Physical desk location and office supply records do not demonstrate whether SaaS credentials remain active. Verification is important because simply submitting a deprovisioning request does not always prove that all forms of access have been successfully removed.