ISC SSCP Practice Test Questions and Exam Dumps Part11 Q201-220

View Full ISC SSCP Exam Dumps and Practice Test Dumps.

 

Question 201

Which security mechanism can help ensure that only authorized devices connect to an organization’s internal network?

  1. Network access control
  2. File compression
  3. Data archiving
  4. Screen protection

Correct Answer: 1

Explanation

Network access control can evaluate devices before permitting them to connect to protected network resources. Depending on the implementation, the control may verify device identity, authentication status, security posture, certificates, or compliance with organizational requirements. Noncompliant devices can be denied, isolated, or placed into a restricted network. This approach helps reduce the risk created by unauthorized or unmanaged endpoints. File compression, data archiving, and screen protection address different security or operational requirements. Network access controls should be supported by appropriate authentication, endpoint management, monitoring, and documented exception procedures.

Question 202

An organization wants to ensure that sensitive data stored on laptops remains protected if a device is lost. Which control is most appropriate?

  1. Network segmentation
  2. Full-disk encryption
  3. Email filtering
  4. Application logging

Correct Answer: 2

Explanation

Full-disk encryption protects information stored on a laptop by encrypting the contents of the device’s storage. If the laptop is lost or stolen, an unauthorized person who removes the drive or attempts to access its contents may be unable to read the protected data without the appropriate authentication or cryptographic keys. Encryption should be supported by strong device authentication, secure key management, and appropriate recovery procedures. Network segmentation and email filtering address network and communication risks, while application logging provides visibility into activity. Encryption is especially important for portable devices containing sensitive organizational information.

Question 203

A security team discovers that an application has permissions to access files unrelated to its business function. What principle should guide remediation?

  1. Maximum availability
  2. Open access
  3. Least privilege
  4. Unlimited delegation

Correct Answer: 3

Explanation

The principle of least privilege requires applications, users, and processes to receive only the permissions necessary to perform their authorized functions. Excessive application permissions increase the potential impact of a compromise because an attacker who gains control of the application may inherit those privileges. The security team should identify required resources, remove unnecessary permissions, test the application, and monitor for access failures after the change. Open access and unlimited delegation create unnecessary exposure. Availability remains important, but granting excessive permissions solely to avoid possible application errors is not an appropriate security strategy.

Question 204

Which document formally describes how an organization will respond to different types of security incidents?

  1. Asset inventory
  2. Incident response plan
  3. Network diagram
  4. Configuration baseline

Correct Answer: 2

Explanation

An incident response plan defines how an organization prepares for, identifies, contains, eradicates, and recovers from security incidents. It can describe roles, responsibilities, escalation paths, communication requirements, evidence handling, decision criteria, and coordination with internal or external parties. The plan should be aligned with organizational risks and applicable requirements and should be reviewed and exercised periodically. An asset inventory identifies systems and resources, while a network diagram describes connectivity. A configuration baseline defines expected system settings. These documents support security operations but do not replace the incident response plan.

Question 205

A security administrator needs to determine which assets are affected by a newly disclosed vulnerability. What should be consulted first?

  1. Current asset and software inventory
  2. Employee attendance report
  3. Building maintenance schedule
  4. Office supply inventory

Correct Answer: 1

Explanation

A current asset and software inventory helps security teams identify systems that contain the vulnerable product or affected software version. Accurate inventory information may include asset ownership, operating system, application versions, network location, and business criticality. Once affected assets are identified, administrators can assess exposure and prioritize remediation according to risk. An outdated inventory can result in missed systems and incomplete remediation. Employee attendance, building maintenance, and office supply records do not provide the technical information needed to identify vulnerable assets. Asset inventories should therefore be maintained and validated as part of ongoing security management.

Question 206

A company wants to prevent unauthorized personnel from entering a server room behind an employee who has already opened the door. Which control can address this threat?

  1. Data classification
  2. Network monitoring
  3. Anti-tailgating physical controls
  4. Email encryption

Correct Answer: 3

Explanation

Anti-tailgating physical controls are designed to reduce the possibility that an unauthorized person follows an authorized individual through a secured entrance. Examples can include mantraps, turnstiles, security personnel, badge verification procedures, and other controlled-entry mechanisms. These controls are particularly useful for sensitive areas such as server rooms and data centers. Data classification and email encryption protect information through different mechanisms, while network monitoring provides visibility into digital activity. Physical access controls should be supported by visitor procedures, access logs, surveillance where appropriate, and periodic review of authorized personnel.

Question 207

A security analyst is reviewing an alert and needs to determine whether the activity occurred before or after a related event on another system. Which capability is essential?

  1. File compression
  2. Time synchronization
  3. Password reuse
  4. Data deduplication

Correct Answer: 2

Explanation

Time synchronization helps ensure that security events recorded by different systems can be compared accurately. When servers, endpoints, network devices, and security tools use inconsistent clocks, investigators may struggle to establish the correct sequence of events. A reliable time source and appropriate synchronization configuration improve log correlation, incident investigation, and forensic analysis. Organizations should monitor synchronization status and protect time sources from unauthorized manipulation. File compression and data deduplication improve storage efficiency, while password reuse creates security risks. Accurate timestamps are particularly important when reconstructing complex incidents involving multiple systems.

Question 208

Which control can help prevent unauthorized modification of data while it is being transmitted between two systems?

  1. Secure transport with integrity protection
  2. Public file sharing
  3. Unauthenticated transmission
  4. Plain-text communication

Correct Answer: 1

Explanation

Secure transport protocols can provide confidentiality and integrity protection for information transmitted between systems. Integrity mechanisms help recipients detect unauthorized modification of data while it is in transit, while encryption can prevent unauthorized parties from reading the contents. Proper certificate validation and secure protocol configuration are also important where applicable. Plain-text and unauthenticated communication can expose information to interception or manipulation. Public file sharing does not inherently provide appropriate protection for sensitive communications. Organizations should select supported secure protocols based on the sensitivity of information and the security requirements of the systems involved.

Question 209

A company wants to ensure that employees cannot install software without authorization on managed workstations. Which approach is most suitable?

  1. Disable all security logging
  2. Grant every employee local administrator rights
  3. Enforce application installation restrictions
  4. Allow unrestricted software downloads

Correct Answer: 3

Explanation

Application installation restrictions can prevent users from installing unauthorized software on managed workstations. Organizations may enforce these restrictions through endpoint management, application control, software deployment policies, or removal of unnecessary administrative privileges. Approved software can be distributed through controlled repositories so that users receive validated versions. Granting every employee local administrator rights significantly increases the ability to bypass security controls. Unrestricted downloads increase exposure to malicious or unapproved applications, while disabling logging removes useful visibility. Policies should include an approved process for requesting legitimate software and handling necessary exceptions.

Question 210

An organization wants to determine whether a security incident affected confidential information in addition to system availability. Which activity should be performed?

  1. Change all screen backgrounds
  2. Perform an impact and data exposure assessment
  3. Increase printer capacity
  4. Remove affected systems from inventory

Correct Answer: 2

Explanation

An impact and data exposure assessment helps determine whether confidential information was accessed, disclosed, altered, or otherwise affected during a security incident. Investigators may review access logs, data transfer records, affected accounts, application activity, and the type of information stored on impacted systems. Determining the scope of information exposure supports appropriate incident classification, response, notification, and remediation decisions. System availability alone does not establish whether confidentiality was affected. Unrelated changes such as modifying screen backgrounds or printer capacity provide no useful evidence. Findings should be documented and supported by reliable investigative evidence.

Question 211

Which authentication factor is something a user physically possesses?

  1. Password
  2. Security question
  3. Hardware token
  4. Personal knowledge

Correct Answer: 3

Explanation

A hardware token is an example of a possession-based authentication factor because the user must physically possess the device to authenticate. Other possession factors can include smart cards or approved cryptographic devices. Passwords and security questions are knowledge-based factors because they depend on information the user knows. Multifactor authentication becomes stronger when different factor categories are combined rather than simply using multiple credentials from the same category. Possession factors should be protected against loss, theft, cloning, and unauthorized use. Organizations should also establish procedures for replacing and revoking lost authentication devices.

Question 212

A security team wants to identify whether a user account is being used simultaneously from two distant locations. Which detection capability is useful?

  1. Impossible-travel or anomalous-location detection
  2. Disk defragmentation
  3. Printer monitoring
  4. File compression

Correct Answer: 1

Explanation

Impossible-travel or anomalous-location detection can identify authentication patterns that appear inconsistent with the expected physical movement of a user. For example, successful authentications from distant locations within an unusually short interval may indicate credential compromise or another suspicious condition. However, such alerts require investigation because VPN gateways, mobile networks, cloud services, and inaccurate geolocation can produce legitimate anomalies. Analysts should correlate authentication times, source addresses, device information, and user activity before making a determination. Disk maintenance, printer monitoring, and file compression do not provide useful information about unusual authentication locations.

Question 213

A company needs to ensure that deleted sensitive files cannot be recovered using ordinary undelete software. Which method is appropriate for storage media that will be reused?

  1. Rename the files
  2. Move files to another folder
  3. Apply approved media sanitization procedures
  4. Hide the files

Correct Answer: 3

Explanation

Approved media sanitization procedures can make previously stored sensitive information difficult or infeasible to recover before storage media is reused. The appropriate method depends on the type of media and organizational requirements and may include cryptographic erasure, secure erasure commands, or other approved techniques. Simply renaming, hiding, or moving files does not remove their underlying data and may leave recoverable information on the storage device. Organizations should document sanitization activities and verify that the selected method is appropriate for the media type and sensitivity of the information involved.

Question 214

Which security activity provides evidence that a newly implemented access control actually prevents unauthorized access?

  1. Control effectiveness testing
  2. Increasing storage capacity
  3. Updating office directories
  4. Changing monitor settings

Correct Answer: 1

Explanation

Control effectiveness testing evaluates whether a security control operates as intended and achieves its defined security objective. For an access control, testing may involve attempting authorized and unauthorized actions under controlled conditions and verifying that the expected restrictions are enforced. Results should be documented and compared with established requirements. Testing may also identify configuration weaknesses or unexpected exceptions that require remediation. Increasing storage capacity and changing monitor settings do not demonstrate access-control effectiveness. Organizations should conduct appropriate testing after implementation and periodically thereafter, especially when significant system or configuration changes occur.

Question 215

A security administrator needs to determine whether an employee’s account should retain access to a sensitive application. Which process is appropriate?

  1. Access recertification
  2. Network cable testing
  3. Printer maintenance
  4. File compression

Correct Answer: 1

Explanation

Access recertification requires designated personnel to periodically review user permissions and confirm that access remains appropriate for current responsibilities. The process can identify privileges that are no longer required because of role changes, transfers, project completion, or other circumstances. Sensitive applications may require more frequent reviews and stronger approval requirements. Recertification results should be documented and unnecessary access should be removed promptly. Network cable testing, printer maintenance, and file compression do not address authorization decisions. Effective access governance combines periodic reviews with timely provisioning, modification, and deprovisioning procedures.

Question 216

A company wants to ensure that security logs cannot be easily modified by an attacker who compromises a monitored server. Which architecture provides stronger protection?

  1. Local-only logs with administrator write access
  2. Centralized log collection with restricted access
  3. Logs stored in temporary memory
  4. Logging disabled during incidents

Correct Answer: 2

Explanation

Centralized log collection with restricted access can protect security records from attackers who compromise an individual monitored server. Logs can be transmitted to a separate system where access is limited and changes are monitored. Additional protections may include write restrictions, immutable storage, encryption, retention controls, and independent administrative roles. Local-only logs are more vulnerable if an attacker gains administrative control of the host. Temporary memory provides limited retention, while disabling logging during an incident removes potentially valuable evidence. Centralized logging also improves correlation across multiple systems during security investigations.

Question 217

An organization wants to reduce the likelihood that an employee will reuse a corporate password on external websites. Which control can help address this risk?

  1. Password reuse detection and awareness controls
  2. Disabling account monitoring
  3. Sharing passwords through email
  4. Removing authentication requirements

Correct Answer: 1

Explanation

Password reuse detection and security awareness controls can help reduce the likelihood that employees use corporate credentials on external services. Organizations may use identity protection capabilities to detect compromised credentials, while awareness programs explain the risks associated with password reuse. Password managers and strong authentication methods can further reduce dependence on repeated passwords. Sharing passwords through email creates additional exposure, while removing authentication requirements eliminates an important security barrier. Organizations should also encourage unique passwords and use multifactor authentication where appropriate to reduce the impact of compromised credentials.

Question 218

A security team needs to determine whether a suspected malware infection has spread to other endpoints. Which activity is most useful?

  1. Review correlated endpoint and network indicators
  2. Change workstation wallpaper
  3. Increase printer capacity
  4. Disable endpoint telemetry

Correct Answer: 1

Explanation

Reviewing correlated endpoint and network indicators can help determine whether suspicious activity has appeared on additional systems. Analysts can examine process activity, file hashes, network connections, authentication events, domains, addresses, and timestamps to identify common indicators across endpoints. Correlation helps establish the potential scope of an incident and supports containment decisions. Disabling endpoint telemetry removes important investigative visibility, while unrelated activities such as changing wallpaper or increasing printer capacity provide no meaningful evidence. Analysts should preserve relevant evidence and use reliable indicators before concluding that malware has or has not spread.

Question 219

Which practice helps protect an organization’s security baseline from unauthorized changes?

  1. Formal change approval and configuration management
  2. Unrestricted administrative modification
  3. Shared administrator passwords
  4. Removing configuration documentation

Correct Answer: 1

Explanation

Formal change approval and configuration management help ensure that modifications to approved security baselines are authorized, documented, tested, and traceable. Configuration management establishes expected settings, while change processes identify the reason for a modification, responsible personnel, affected systems, testing requirements, and rollback procedures. Unauthorized changes can weaken security controls or create inconsistent system configurations. Shared administrator passwords and unrestricted modification reduce accountability and make investigations more difficult. Removing configuration documentation also prevents administrators from reliably determining what settings are expected. Baselines should be reviewed when legitimate architectural or business changes occur.

Question 220

A security manager wants to identify whether an organization has enough personnel and resources to respond to major security incidents. Which activity is most useful?

  1. Capacity and readiness assessment
  2. Changing password length
  3. Replacing office furniture
  4. Disabling incident escalation

Correct Answer: 4

Explanation

A capacity and readiness assessment can determine whether an organization has sufficient personnel, skills, technology, procedures, and external support to respond effectively to major security incidents. The assessment can identify staffing gaps, unavailable expertise, inadequate monitoring coverage, communication weaknesses, or insufficient response tooling. Findings can then inform staffing plans, training, contracts, and technical investments. Password configuration may address authentication risk but does not evaluate incident-response capacity. Office furniture is unrelated, while disabling escalation reduces the organization’s ability to coordinate serious incidents. Readiness should be reassessed as organizational structure, threats, and technology change.