ISC SSCP Practice Test Questions and Exam Dumps Part13 Q241-260

View Full ISC SSCP Exam Dumps and Practice Test Dumps.

 

Question 241

Which control helps ensure that employees can access only the resources necessary for their assigned responsibilities?

  1. Data replication
  2. Least privilege
  3. Network broadcasting
  4. Unrestricted delegation

Correct Answer: 2

Explanation

Least privilege requires users, applications, and processes to receive only the permissions necessary to perform authorized responsibilities. Applying this principle limits the potential damage caused by compromised accounts, accidental misuse, or malicious activity. Access should be based on documented business requirements and reviewed periodically because responsibilities can change. Excessive permissions should be removed when they are no longer required. Data replication supports availability, while network broadcasting and unrestricted delegation do not establish appropriate authorization boundaries. Least privilege should be supported by role definitions, access reviews, authentication controls, and monitoring of privileged activity.

Question 242

A security team wants to protect a server from attacks against unnecessary network services. Which action should be taken during hardening?

  1. Enable every available service
  2. Share administrative credentials
  3. Disable unnecessary services and ports
  4. Remove security monitoring

Correct Answer: 3

Explanation

Disabling unnecessary services and ports reduces the server’s attack surface by removing functionality that is not required for its intended purpose. Every active service may introduce vulnerabilities, configuration requirements, or additional opportunities for unauthorized access. Administrators should first identify legitimate application dependencies before disabling a service and should document approved configurations. Enabling every available service increases exposure, while shared credentials reduce accountability. Removing monitoring eliminates useful visibility into system activity. Secure hardening should combine service reduction with patching, strong authentication, access restrictions, logging, and periodic configuration assessments to maintain an appropriate security posture.

Question 243

An organization needs to verify that a user is physically present when accessing a highly restricted facility. Which authentication factor can support this requirement?

  1. Biometric characteristic
  2. Password
  3. Security question
  4. Personal identification number

Correct Answer: 1

Explanation

A biometric characteristic is an inherence factor because it is based on something the individual physically is, such as a fingerprint, facial characteristic, or other measurable biological attribute. Biometrics can provide strong identity verification when implemented appropriately, although organizations must consider privacy, accuracy, enrollment, spoofing resistance, and fallback procedures. Passwords, security questions, and personal identification numbers are knowledge factors because they depend on information the user knows. Physical access systems may combine biometrics with badges or other factors to increase assurance. Biometric controls should be protected and managed according to organizational security and privacy requirements.

Question 244

A company wants to determine whether a newly installed application introduces known security weaknesses before production deployment. Which activity is appropriate?

  1. Delete application logs
  2. Skip testing to accelerate deployment
  3. Grant unrestricted permissions
  4. Perform security testing before deployment

Correct Answer: 4

Explanation

Security testing before deployment can identify vulnerabilities, insecure configurations, excessive permissions, dependency issues, and other weaknesses before an application reaches production. Depending on risk, testing may include vulnerability scanning, code review, configuration assessment, penetration testing, dependency analysis, and functional security testing. Findings should be evaluated and remediated according to established risk criteria before release. Skipping testing increases the likelihood that weaknesses will reach production. Unrestricted permissions increase exposure, while deleting logs removes valuable evidence. Security testing should be integrated into the development and change-management processes rather than performed only after incidents occur.

Question 245

Which document identifies hardware, software, owners, and other characteristics of systems within an organization’s environment?

  1. Incident response plan
  2. Asset inventory
  3. Disaster recovery exercise
  4. Security awareness policy

Correct Answer: 2

Explanation

An asset inventory provides an organized record of systems and resources within an organization’s environment. Depending on the organization’s needs, inventory information can include hardware, software, operating systems, network addresses, owners, locations, business criticality, and lifecycle status. Accurate inventories support vulnerability management, patching, incident response, access reviews, and risk assessment. An incident response plan defines response activities, while a disaster recovery exercise tests recovery capabilities. A security awareness policy addresses employee behavior and training. Asset information should be maintained as systems are acquired, modified, transferred, or retired.

Question 246

A security administrator needs to ensure that a privileged user cannot access systems unrelated to the user’s administrative responsibilities. Which control is most appropriate?

  1. Role-based access restrictions
  2. Public access permissions
  3. Shared administrator credentials
  4. Unrestricted network connectivity

Correct Answer: 1

Explanation

Role-based access restrictions can limit privileged users to systems and functions associated with their defined responsibilities. This supports least privilege and reduces the potential impact of misuse or compromise of administrative credentials. Roles should be carefully defined and should reflect actual business and technical responsibilities rather than granting broad access for convenience. Shared credentials make individual accountability difficult, while public permissions and unrestricted connectivity increase exposure. Organizations should periodically review privileged assignments, remove unnecessary access, and monitor administrative activity. Strong authentication and privileged access management can further strengthen restrictions around sensitive administrative functions.

Question 247

A security team wants to identify whether an attacker is attempting to use a compromised account to access multiple systems. Which activity can provide useful evidence?

  1. Reviewing only employee schedules
  2. Disabling authentication logs
  3. Correlating authentication events across systems
  4. Removing account monitoring

Correct Answer: 3

Explanation

Correlating authentication events across systems can reveal patterns that may indicate compromised-account activity. Analysts can compare timestamps, source addresses, devices, authentication methods, target systems, and successful or failed attempts. A compromised account may generate activity across systems that appears unusual when compared with the user’s normal behavior. Correlation also helps distinguish isolated authentication failures from broader campaigns or lateral movement. Employee schedules may provide contextual information but are not sufficient technical evidence. Disabling authentication logs or removing account monitoring eliminates important visibility and can make investigation substantially more difficult.

Question 248

Which physical control provides evidence of who entered a restricted area and when?

  1. Visitor brochure
  2. Security access log
  3. Office seating chart
  4. Equipment purchase list

Correct Answer: 2

Explanation

A security access log can record information about physical entry events, such as the identity associated with a badge, the location accessed, and the time of entry. These records can support investigations, access reviews, and accountability for restricted facilities. Logs should be protected from unauthorized modification and retained according to organizational requirements. A visitor brochure, seating chart, or equipment purchase list does not provide reliable evidence of actual physical entry activity. Organizations may combine access logs with surveillance, visitor records, and security personnel observations when investigating physical security events.

Question 249

A company needs to ensure that critical security updates are installed on systems within an approved timeframe. Which process supports this objective?

  1. Informal software requests
  2. Permanent exception approval
  3. Patch management
  4. Disabling vulnerability scanning

Correct Answer: 3

Explanation

Patch management establishes processes for identifying required updates, evaluating their risk, testing them where necessary, deploying them, and verifying successful installation. Critical security updates may require accelerated treatment when they address vulnerabilities with significant exposure or active exploitation. Organizations should maintain accurate asset and software inventories so that affected systems can be identified. Informal requests and permanent exceptions do not provide effective control over patch deployment. Disabling vulnerability scanning removes a useful method for identifying systems that remain exposed. Patch processes should include documentation, accountability, testing, rollback considerations, and exception management.

Question 250

An organization wants to ensure that sensitive information remains unreadable if intercepted while traveling across a public network. Which protection is appropriate?

  1. Data compression
  2. Secure encryption in transit
  3. File renaming
  4. Open network sharing

Correct Answer: 2

Explanation

Secure encryption in transit protects information as it moves between systems across networks that may not be trusted. Properly configured secure protocols can provide confidentiality and, depending on the protocol, integrity and authentication protections. Organizations should use supported cryptographic protocols, validate certificates where applicable, and disable obsolete configurations. Compression reduces data size but does not provide confidentiality. File renaming has no meaningful effect on protection, while open network sharing can expose sensitive information. Encryption in transit should complement strong authentication, access controls, endpoint protection, and secure application design.

Question 251

A security administrator is reviewing a user account that has not been used for several months. What action can reduce unnecessary exposure?

  1. Automatically disable inactive accounts according to policy
  2. Grant the account additional privileges
  3. Share the account with another employee
  4. Remove all account monitoring

Correct Answer: 1

Explanation

Automatically disabling inactive accounts according to an approved policy reduces the risk that forgotten credentials will be abused by unauthorized individuals. Organizations should define appropriate inactivity periods and identify legitimate exceptions such as service accounts or approved temporary accounts. Exceptions should be documented and reviewed periodically rather than remaining permanently active. Granting additional privileges increases risk, while sharing accounts weakens accountability. Removing monitoring eliminates useful visibility. Account lifecycle management should include creation, modification, periodic review, suspension, and removal processes so that access remains aligned with current business requirements.

Question 252

Which approach can help protect confidential information stored in a cloud service if unauthorized parties gain access to the underlying storage?

  1. Public sharing
  2. Unrestricted administrative access
  3. Encryption of stored data
  4. Anonymous authentication

Correct Answer: 3

Explanation

Encryption of stored data can protect confidential information by making the underlying content unreadable without the appropriate cryptographic keys. Cloud encryption should be combined with proper key management, access controls, identity security, logging, and configuration management. Organizations should understand which party controls encryption keys and how the cloud provider implements storage protection. Public sharing and anonymous authentication increase exposure, while unrestricted administrative access weakens authorization. Encryption is not a substitute for access control because authorized users and compromised accounts may still be able to access decrypted information through legitimate interfaces.

Question 253

A security team needs to preserve important system logs for a period required by organizational policy. Which control should be established?

  1. Log retention policy
  2. Unlimited administrator deletion
  3. Automatic deletion after one day
  4. Uncontrolled local storage

Correct Answer: 1

Explanation

A log retention policy defines how long relevant security records should be preserved and how they should be protected during that period. Retention requirements may depend on legal obligations, regulatory requirements, investigations, business needs, and available storage. Logs should be protected against unauthorized alteration and deletion, and access should be restricted to authorized personnel. Unlimited administrator deletion can undermine evidence integrity, while very short retention may remove information needed for investigations. Uncontrolled local storage can also create availability and integrity concerns. Retention policies should be reviewed periodically and aligned with organizational requirements.

Question 254

An organization wants to identify whether a system has deviated from its approved security configuration. Which capability is most appropriate?

  1. Configuration compliance monitoring
  2. Employee directory management
  3. Printer maintenance
  4. Data compression

Correct Answer: 1

Explanation

Configuration compliance monitoring compares system settings with approved security baselines and identifies deviations that may require investigation or remediation. It can evaluate settings such as password policies, enabled services, permissions, security features, and other configuration requirements. Automated monitoring can provide consistent coverage across large environments, while periodic manual validation may supplement automated controls. Employee directory management, printer maintenance, and data compression do not directly establish whether a system follows its approved security configuration. Detected deviations should be investigated because they may result from unauthorized changes, administrative errors, software updates, or approved exceptions.

Question 255

A company wants to ensure that an employee cannot use an old password after changing to a new one. Which control supports this requirement?

  1. Password history enforcement
  2. Network segmentation
  3. Data classification
  4. Log compression

Correct Answer: 1

Explanation

Password history enforcement prevents users from reusing recently used passwords when creating a new password. This can reduce the effectiveness of repeated password cycling, where a user changes a password temporarily and then quickly returns to a previous value. Password policies should be designed according to organizational risk and supported by strong authentication practices. Network segmentation separates systems, data classification determines sensitivity, and log compression improves storage efficiency. None of those controls directly prevents password reuse. Organizations should also consider multifactor authentication and secure password-management practices to strengthen identity protection.

Question 256

Which security measure can reduce the risk of unauthorized access to a wireless network by requiring authenticated devices or users?

  1. Open wireless access
  2. Wireless authentication and access control
  3. Shared public credentials
  4. Disabled encryption

Correct Answer: 2

Explanation

Wireless authentication and access control can restrict network access to authorized users or devices. Depending on the environment, organizations may use enterprise authentication, certificates, managed credentials, device validation, and appropriate encryption. These controls reduce the risk associated with open or improperly secured wireless networks. Open access and shared public credentials make unauthorized access easier, while disabling encryption can expose transmitted information. Wireless security should also include configuration management, monitoring for unauthorized access points, segmentation of wireless clients, and periodic review of authentication settings.

Question 257

A security manager wants to identify the potential consequences if a critical business service becomes unavailable. Which measurement is most relevant?

  1. Employee satisfaction score
  2. Office occupancy rate
  3. Business impact assessment results
  4. Printer utilization

Correct Answer: 3

Explanation

Business impact assessment results identify the consequences associated with disruption of critical business services. They can address financial impact, operational interruption, legal or regulatory effects, customer impact, dependencies, and recovery priorities. This information supports decisions about continuity strategies, recovery objectives, resource allocation, and resilience investments. Employee satisfaction, office occupancy, and printer utilization may provide operational information but do not directly establish the consequences of losing a critical business service. Business impact assessments should involve appropriate stakeholders and be reviewed when business processes, dependencies, or service requirements materially change.

Question 258

A security analyst wants to determine whether a suspicious connection originated from an internal workstation or an external source. Which information is most useful?

  1. Source and destination network addresses
  2. Monitor manufacturer
  3. Keyboard language
  4. Office furniture inventory

Correct Answer: 1

Explanation

Source and destination network addresses provide important information for determining where a connection originated and where it was directed. Analysts can correlate these addresses with network topology, asset inventories, firewall records, DNS information, and other telemetry to establish whether activity came from an internal system, external source, or intermediary service. Network addresses alone may not prove who initiated an action, so additional authentication and endpoint evidence may be required. Monitor manufacturers, keyboard settings, and office furniture records do not provide meaningful network-origin information for security investigations.

Question 259

Which process helps ensure that security responsibilities are clearly assigned to individuals or teams?

  1. Responsibility and accountability assignment
  2. Anonymous administration
  3. Shared unrestricted access
  4. Removal of ownership records

Correct Answer: 1

Explanation

Clearly assigning security responsibilities establishes accountability for activities such as access approval, incident response, system administration, risk acceptance, monitoring, and control maintenance. Defined ownership helps ensure that security tasks are not overlooked because everyone assumes someone else is responsible. Organizations can document responsibilities through policies, role descriptions, procedures, control ownership records, and approval workflows. Anonymous administration and shared unrestricted access weaken accountability, while removing ownership records makes it difficult to determine who is responsible for controls. Responsibilities should be reviewed when organizational structures or system ownership changes.

Question 260

A company wants to determine whether a security incident has been fully resolved rather than merely contained. Which activity provides useful confirmation?

  1. Close the ticket immediately after containment
  2. Stop monitoring the affected systems
  3. Perform post-incident validation and monitoring
  4. Delete investigation records

Correct Answer: 3

Explanation

Post-incident validation and continued monitoring can help determine whether malicious activity has been removed and whether affected systems have returned to an acceptable security state. Validation may include reviewing endpoint activity, network connections, account behavior, vulnerabilities, configurations, and security alerts after containment actions are completed. Simply containing an incident does not prove that the underlying cause has been eliminated. Stopping monitoring or deleting investigation records can remove important evidence and visibility. Organizations should document recovery actions, verify corrective measures, and conduct lessons-learned activities to reduce the likelihood or impact of similar incidents.