View Full ISC SSCP Exam Dumps and Practice Test Dumps.
Question 141
A security administrator needs to ensure that an administrator cannot modify audit records after performing a sensitive action. Which control is most appropriate?
- Store audit records in a separately controlled system
- Give administrators unrestricted log permissions
- Allow users to edit their own audit records
- Disable audit collection
Correct Answer: 1
Explanation
Storing audit records in a separately controlled system can reduce the ability of administrators on a monitored system to alter evidence of their own activities. Centralized logging, restricted write permissions, protected storage, and appropriate monitoring can help preserve the integrity of audit records. Organizations should define who can access logs and under what circumstances, while maintaining reliable timestamps and retention requirements. Allowing users or administrators to modify their own audit records undermines accountability. Disabling logging removes valuable evidence. Separating log management from the systems being monitored provides an additional layer of protection against unauthorized alteration.
Question 142
A company is designing a security architecture for internet-facing applications. Which component can provide a controlled intermediary between external clients and internal application servers?
- Database server
- Proxy or application gateway
- Employee workstation
- Backup tape
Correct Answer: 2
Explanation
A proxy or application gateway can act as an intermediary between external clients and protected application servers. It can enforce security policies, inspect requests, restrict allowed methods, terminate secure connections, and provide additional monitoring before traffic reaches internal systems. Depending on the architecture, such gateways may also support authentication, rate limiting, and application-layer filtering. Directly exposing internal application servers can increase their attack surface. A database server, workstation, or backup tape does not provide the same intermediary security function. The gateway should itself be hardened, monitored, and maintained according to organizational security requirements.
Question 143
An organization wants to ensure that employees cannot use unauthorized DNS servers that may redirect corporate traffic to malicious destinations. Which control can help enforce this requirement?
- Disable all endpoint authentication
- Permit arbitrary DNS configuration
- Enforce approved DNS resolver settings
- Remove network monitoring
Correct Answer: 3
Explanation
Enforcing approved DNS resolver settings can help ensure that corporate devices use trusted services for name resolution. Organizations may configure managed endpoints to use approved internal or security-enabled resolvers and restrict unauthorized changes through endpoint management policies. Monitoring DNS activity can further help identify suspicious domains, tunneling, or attempts to bypass approved resolvers. Allowing arbitrary DNS configuration can expose users to malicious or manipulated responses. Disabling authentication or removing network monitoring does not address DNS trust. DNS security should be considered alongside endpoint controls, network filtering, and appropriate threat detection capabilities.
Question 144
A security team needs to determine whether a suspicious executable was altered after it was collected for analysis. Which technique is useful?
- Compare cryptographic hash values
- Rename the executable
- Compress the executable
- Change its file extension
Correct Answer: 1
Explanation
Comparing cryptographic hash values can help determine whether an executable’s contents have changed between two points in time. Investigators can calculate a hash when evidence is collected and compare it with a later calculation to identify modification. The original hash should be protected so that an attacker cannot alter both the evidence and its reference value. Hash comparison supports evidence integrity but does not by itself establish whether a file is malicious. Renaming, compressing, or changing the extension does not provide a reliable method for proving that the underlying evidence remains unchanged.
Question 145
A company wants to limit the impact of a compromised application server by preventing it from initiating unnecessary connections to other internal systems. Which control is most appropriate?
- Unrestricted internal routing
- Broad shared administrator access
- Host-based or network-based outbound restrictions
- Publicly exposing internal services
Correct Answer: 3
Explanation
Host-based or network-based outbound restrictions can limit which destinations and services an application server is permitted to contact. This reduces unnecessary communication paths and can limit lateral movement if the server becomes compromised. Rules should be based on documented application dependencies so legitimate operations continue while unnecessary connections are denied. Network segmentation, firewalls, and host-based controls can work together to enforce these restrictions. Unrestricted routing and broad administrative access increase potential attack paths, while exposing internal services publicly creates additional risk. Restricting outbound communication is an important defense-in-depth measure for critical servers.
Question 146
An organization needs to identify who is responsible for approving a security policy exception. Which element should be defined in the exception process?
- Random approval selection
- A designated risk owner and authorized approver
- Approval by any employee
- No approval requirement
Correct Answer: 2
Explanation
A designated risk owner and authorized approver establish accountability for security policy exceptions. The process should identify who accepts the residual risk, why the exception is required, what systems or activities are affected, and how long the exception remains valid. Appropriate management approval ensures that exceptions are consciously accepted rather than created informally. Random or unrestricted approval does not provide reliable accountability. Exceptions should also include compensating controls and review dates where appropriate. Clear ownership allows the organization to track exceptions and determine whether they should eventually be removed or replaced with a compliant solution.
Question 147
A security administrator discovers that a critical server has an unnecessary compiler installed, even though the server does not perform software development. What action best follows secure hardening principles?
- Keep the compiler available for convenience
- Remove unnecessary software after validating dependencies
- Grant all users permission to execute it
- Publish the compiler configuration
Correct Answer: 2
Explanation
Removing unnecessary software can reduce the attack surface of a server when the software has no legitimate operational requirement. Unneeded compilers, utilities, and services may provide additional functionality that attackers could abuse after gaining access. Before removal, administrators should verify that no approved application or operational process depends on the component. Changes should be documented and tested. Keeping unnecessary software solely for convenience increases exposure, while granting broad execution permissions increases potential misuse. Secure hardening focuses on reducing unnecessary functionality while preserving the capabilities required for legitimate business operations.
Question 148
A company wants to ensure that security-sensitive configuration changes receive appropriate testing before being applied broadly. Which deployment strategy can reduce operational risk?
- Immediate deployment to every system
- Pilot deployment followed by controlled rollout
- Unapproved manual modification
- Permanent suspension of testing
Correct Answer: 2
Explanation
A pilot deployment followed by a controlled rollout allows an organization to evaluate a configuration change on a limited group of systems before applying it broadly. The pilot can reveal compatibility issues, unexpected security effects, performance problems, or operational dependencies. Results should be reviewed against predefined acceptance criteria before wider deployment. A staged rollout can also include rollback procedures if problems emerge. Immediate deployment across every system increases the potential impact of an unsuccessful change, while unapproved modifications weaken governance. Suspending testing removes an important opportunity to identify problems before they affect a larger environment.
Question 149
A security team wants to prevent unauthorized devices from gaining access to an internal wired network through unused switch ports. Which control is appropriate?
- Enable every unused port
- Disable unused switch ports
- Publish switch management credentials
- Remove physical security controls
Correct Answer: 2
Explanation
Disabling unused switch ports prevents unauthorized devices from using inactive network connections to gain access to the internal environment. Organizations can also use port security, network access control, device authentication, and appropriate physical safeguards to strengthen protection. Administrators should maintain documentation of active ports and enable additional ports only when there is an approved business requirement. Leaving unused ports active increases the number of potential entry points. Publishing management credentials or removing physical controls creates additional security risks. Network access controls should be reviewed periodically as office layouts, equipment, and connectivity requirements change.
Question 150
A company wants to ensure that a security alert reaches an analyst even when the primary monitoring dashboard is unavailable. Which capability supports this objective?
- Independent alert notification mechanisms
- Single-screen monitoring only
- Manual checking once per month
- Disabled escalation procedures
Correct Answer: 1
Explanation
Independent alert notification mechanisms provide an alternative path for delivering important security events when a primary monitoring interface or service becomes unavailable. Depending on the organization’s architecture, notifications may use separate messaging systems, automated escalation services, or other resilient channels. Critical alerts should have clearly defined ownership and escalation requirements so that notifications receive timely attention. A single dashboard creates a potential point of failure, while infrequent manual checks may delay detection. Disabling escalation procedures removes accountability. Monitoring resilience should be tested periodically to verify that important alerts continue reaching responsible personnel during component failures.
Question 151
A security analyst needs to determine whether a user accessed a sensitive application from a device that was previously unknown to the organization. Which record can provide useful evidence?
- Endpoint and authentication telemetry
- Office cleaning schedule
- Building utility records
- Employee cafeteria records
Correct Answer: 1
Explanation
Endpoint and authentication telemetry can provide information about the device, account, timestamp, source address, authentication method, and other context associated with an application session. Comparing this information with known managed devices and historical activity can help analysts identify unusual access patterns. An unfamiliar device does not automatically prove malicious activity because legitimate device replacement, travel, or approved personal-device policies may explain the event. Analysts should correlate multiple sources before reaching a conclusion. Office cleaning, utility, and cafeteria records generally do not provide relevant technical evidence about an application’s authentication or endpoint activity.
Question 152
An organization wants to protect privileged credentials used by automated services without requiring administrators to manually enter passwords each time. Which approach is appropriate?
- Store passwords in plain-text scripts
- Use a managed secrets solution
- Embed passwords in public documentation
- Share one credential among all applications
Correct Answer: 2
Explanation
A managed secrets solution can securely store and provide credentials required by automated services while reducing the need to embed passwords directly in scripts or configuration files. Depending on the platform, secrets can be rotated automatically, access can be restricted by workload identity, and retrieval events can be logged. Applications should receive only the credentials and permissions required for their functions. Plain-text scripts and public documentation can expose credentials to unauthorized users. Sharing one credential across applications also increases the potential impact of compromise and makes it difficult to determine which service used the credential.
Question 153
A company is reviewing its incident response process and wants to determine whether containment actions were performed within the expected timeframe. Which information is most useful?
- Incident timestamps and response records
- Office seating assignments
- Printer model numbers
- Employee parking information
Correct Answer: 1
Explanation
Incident timestamps and response records provide evidence for evaluating whether containment actions occurred within defined expectations. Relevant records may include the time an event was detected, escalated, assigned, contained, and resolved. Comparing actual response times with established service levels can help identify bottlenecks and areas for improvement. Analysts should account for incident severity and complexity when interpreting the results because different events may require different response processes. Office seating, printer models, and parking information do not provide meaningful evidence about incident response timing or containment performance.
Question 154
A security administrator wants to reduce the risk of unauthorized access through a dormant user account. What should be implemented?
- Automatic disabling of inactive accounts according to policy
- Permanent activation of every account
- Shared credentials for dormant accounts
- Removal of account monitoring
Correct Answer: 1
Explanation
Automatic disabling of inactive accounts can reduce the opportunity for attackers to abuse credentials that are no longer needed. Organizations should establish an inactivity threshold appropriate to their environment and ensure that exceptions for legitimate service or temporary accounts are documented and reviewed. Account lifecycle processes should also include timely creation, modification, and removal of access based on authoritative personnel information. Permanently active dormant accounts increase exposure, while shared credentials weaken accountability. Removing monitoring makes suspicious use of inactive accounts more difficult to detect. Dormant-account controls should complement broader identity governance practices.
Question 155
A company needs to ensure that an application server communicates with its database only through the required protocol and port. Which control can enforce this restriction?
- Network access control rules
- Unlimited routing
- Public DNS registration
- Shared user accounts
Correct Answer: 1
Explanation
Network access control rules can restrict communication between an application server and its database to approved protocols, ports, and source or destination addresses. This follows a deny-by-default approach in which unnecessary traffic is blocked while required application dependencies are permitted. Restricting communication reduces exposure and can limit the impact of a compromised server. Rules should be documented, tested, monitored, and reviewed when application architecture changes. Unlimited routing creates unnecessary connectivity, while public DNS registration and shared accounts do not directly enforce network communication restrictions between the application and database tiers.
Question 156
A security team wants to ensure that employees can report suspected phishing messages without forwarding them to coworkers. Which capability is useful?
- A designated phishing-reporting mechanism
- Publicly forwarding suspicious messages
- Removing email security controls
- Disabling user reporting
Correct Answer: 1
Explanation
A designated phishing-reporting mechanism provides employees with a controlled way to submit suspicious messages to the security team for analysis. The mechanism can preserve relevant email metadata, reduce unnecessary forwarding, and allow analysts to identify campaigns affecting multiple users. Clear instructions should explain how employees can report suspicious messages and what information should be included. Publicly forwarding potentially malicious messages may expose additional users to harmful content. Removing email security controls or disabling reporting reduces defensive capability. Organizations can also use reported-message data to improve filtering, awareness training, and incident response.
Question 157
A company wants to ensure that only authorized personnel can modify security policies stored in a centralized repository. Which control is most appropriate?
- Repository access control with change auditing
- Anonymous write access
- Shared administrator credentials
- Public modification permissions
Correct Answer: 1
Explanation
Repository access control with change auditing restricts policy modifications to authorized personnel while providing a record of who changed what and when. Security policies are important governance artifacts, so unauthorized modification could weaken organizational controls or create conflicting requirements. Role-based permissions, individual accounts, version history, approval workflows, and protected backups can strengthen policy integrity. Anonymous or public write access removes accountability, while shared administrator credentials make individual attribution difficult. Policy repositories should also be reviewed periodically to ensure that access permissions remain aligned with current responsibilities.
Question 158
A security administrator wants to determine whether a server’s security configuration changed unexpectedly overnight. Which capability can provide the most direct indication?
- Configuration change monitoring
- Employee attendance tracking
- Printer utilization reports
- Office temperature monitoring
Correct Answer: 1
Explanation
Configuration change monitoring can detect or report modifications to important system settings, services, permissions, security controls, and other defined configuration elements. Alerts can help administrators identify unauthorized changes and correlate them with approved maintenance activity or change requests. The monitoring system should protect its records from unauthorized modification and maintain reliable timestamps. Unexpected changes should be investigated because they may result from administrative error, unauthorized activity, malware, or legitimate but undocumented work. Employee attendance, printer utilization, and office temperature data generally cannot directly establish whether a server’s security configuration changed.
Question 159
A company is determining whether a security control should be automated or remain manual. Which factor should influence the decision most directly?
- Risk, control requirements, consistency, and operational feasibility
- Employee preference alone
- Office decoration style
- Number of meeting rooms
Correct Answer: 1
Explanation
The decision to automate a security control should consider the associated risk, control requirements, desired consistency, frequency of the task, complexity, cost, and operational feasibility. Automation can improve repeatability and reduce human error for suitable activities, but poorly designed automation can propagate mistakes quickly. Manual procedures may remain appropriate where judgment or contextual review is essential. Organizations should evaluate the control objective rather than assuming automation is always preferable. Employee preference or unrelated office characteristics should not determine the security architecture. Testing and monitoring are important when automated controls are introduced.
Question 160
A security manager wants to determine whether security findings identified during an assessment have actually been corrected. Which activity provides the strongest confirmation?
- Remediation verification testing
- Deleting the original findings
- Assuming remediation after assigning an owner
- Closing findings without evidence
Correct Answer: 1
Explanation
Remediation verification testing confirms that previously identified security weaknesses have actually been corrected and that the implemented solution works as intended. Verification may involve rescanning a vulnerable system, reviewing configuration, performing controlled testing, or examining evidence of the implemented corrective action. Merely assigning an owner or marking a finding closed does not demonstrate that the underlying issue has been resolved. Original findings should be retained for accountability and comparison. Effective remediation management should track ownership, deadlines, status, evidence, and verification results so that unresolved weaknesses do not disappear from security reporting.