ISC SSCP Practice Test Questions and Exam Dumps Part14 Q261-280

View Full ISC SSCP Exam Dumps and Practice Test Dumps.

 

Question 261

Which security principle requires two different individuals to complete sensitive activities?

  1. Data masking
  2. Separation of duties
  3. Network redundancy
  4. Data aggregation

Correct Answer: 2

Explanation

Separation of duties divides sensitive responsibilities among multiple individuals so that one person cannot independently complete an entire high-risk process. For example, one employee may request access while another approves it. This reduces opportunities for fraud, unauthorized changes, and abuse of authority. The control is particularly useful for financial systems, privileged administration, security exceptions, and other sensitive operations. Data masking protects sensitive values, network redundancy supports availability, and data aggregation combines information. Separation of duties should be documented clearly and reviewed periodically to ensure responsibilities remain appropriately divided.

Question 262

A security administrator discovers that a server is running an obsolete application that is no longer required. What should be done first?

  1. Increase its privileges
  2. Expose it to the internet
  3. Remove the unnecessary application
  4. Disable security logging

Correct Answer: 3

Explanation

Removing an unnecessary obsolete application reduces the server’s attack surface and eliminates potential vulnerabilities associated with software that no longer serves a business purpose. Before removal, administrators should confirm that the application is not required by another service or business process. Approved change procedures should be followed when production systems are affected. Increasing privileges or exposing the server to the internet would increase risk, while disabling logging reduces visibility. Secure system maintenance involves regularly reviewing installed software, removing unnecessary components, applying appropriate updates, and maintaining configurations that reflect current operational requirements.

Question 263

Which security control helps prevent an unauthorized person from following an authorized employee through a controlled entrance?

  1. Anti-tailgating control
  2. Data encryption
  3. Password expiration
  4. File integrity monitoring

Correct Answer: 1

Explanation

Anti-tailgating controls help prevent unauthorized individuals from entering a restricted area by following an authorized person through a secured entrance. Examples can include security personnel, turnstiles, mantraps, access-control vestibules, or procedures requiring each person to authenticate independently. These measures strengthen physical access controls and reduce the risk that possession of an authorized person’s access credentials indirectly provides entry to another individual. Data encryption protects information, password expiration addresses authentication credentials, and file integrity monitoring detects changes to files. Physical security controls should be selected according to facility risk and operational requirements.

Question 264

A company wants to ensure that an employee’s access changes promptly after moving to a different department. Which process is most relevant?

  1. Network bandwidth management
  2. Data backup scheduling
  3. Identity lifecycle management
  4. Printer configuration

Correct Answer: 3

Explanation

Identity lifecycle management handles changes to user access throughout employment, including onboarding, transfers, role changes, and termination. When an employee moves to another department, previous permissions may no longer be appropriate and new permissions may be required. A documented lifecycle process helps ensure that access changes are authorized, timely, and traceable. Network bandwidth, backup scheduling, and printer configuration do not directly manage user authorization. Organizations should integrate identity lifecycle processes with human resources notifications, role definitions, access approval workflows, and periodic reviews to reduce the risk of excessive or outdated privileges.

Question 265

A security analyst receives an alert showing repeated failed authentication attempts followed by a successful login from the same source. What should the analyst examine next?

  1. The building’s lighting system
  2. Authentication and source activity
  3. Printer toner levels
  4. Employee vacation balances

Correct Answer: 2

Explanation

Authentication and source activity can help determine whether repeated failures followed by a successful login represent legitimate behavior or a potential account compromise. The analyst should review timestamps, source addresses, affected accounts, authentication methods, device information, and subsequent activity. Additional evidence may reveal password guessing, credential stuffing, or a legitimate user who initially entered incorrect credentials. Unrelated operational information does not help establish the security context of the event. Investigation should preserve relevant logs and correlate authentication records with endpoint, network, and identity information before drawing conclusions about the incident.

Question 266

Which control provides assurance that a backup has not been altered since it was created?

  1. Compression
  2. Hash verification
  3. File renaming
  4. Disk defragmentation

Correct Answer: 2

Explanation

Hash verification can help determine whether backup content has changed by comparing a newly calculated cryptographic hash with a trusted reference value. If the values match, the data is consistent with the content used to generate the reference hash, subject to the properties and security of the hashing method. Hashing does not itself provide confidentiality, so encryption may also be necessary for sensitive backups. Compression, file renaming, and disk defragmentation do not establish content integrity. Backup verification should be incorporated into broader backup management, including restoration testing, access protection, retention, and secure storage.

Question 267

A company is preparing to allow a vendor to access an internal system for a limited maintenance task. Which control best supports this arrangement?

  1. Permanent administrator access
  2. Time-limited authorized access
  3. Shared employee credentials
  4. Anonymous remote access

Correct Answer: 2

Explanation

Time-limited authorized access allows a vendor to perform an approved task while reducing the period during which external access remains available. The access should follow documented approval, least-privilege requirements, strong authentication, monitoring, and automatic or manual removal after the maintenance activity is completed. Permanent administrator access creates unnecessary long-term exposure, while shared employee credentials weaken accountability and make investigations more difficult. Anonymous remote access is inappropriate for sensitive administrative activities. Third-party access should also be governed by contractual requirements and reviewed to ensure that permissions remain appropriate throughout the relationship.

Question 268

Which method can protect sensitive data displayed on a screen from being viewed by unauthorized individuals nearby?

  1. Screen privacy controls
  2. Network load balancing
  3. Database replication
  4. DNS caching

Correct Answer: 1

Explanation

Screen privacy controls can reduce the risk of unauthorized individuals viewing sensitive information displayed on a workstation or mobile device. Depending on the environment, controls may include privacy filters, automatic screen locking, appropriate workstation positioning, restricted viewing areas, and user awareness procedures. These measures are particularly relevant in public areas, shared offices, healthcare environments, financial operations, and other locations where unauthorized observation is possible. Network load balancing distributes traffic, database replication supports availability, and DNS caching improves name-resolution performance. Screen protection should complement broader physical and information-handling controls.

Question 269

A security team needs to identify which users have permissions that exceed their current job responsibilities. Which activity is most appropriate?

  1. Access rights review
  2. Network cable replacement
  3. Storage compression
  4. Printer maintenance

Correct Answer: 1

Explanation

An access rights review compares assigned permissions with current business responsibilities to identify excessive, outdated, or unauthorized access. Reviews should consider role changes, terminated accounts, temporary permissions, privileged access, and separation-of-duties requirements. Identified discrepancies should be corrected through an approved authorization process and documented for accountability. Network cable replacement, storage compression, and printer maintenance do not assess whether user permissions remain appropriate. Periodic access reviews are especially important for privileged accounts and sensitive systems because excessive access can increase the impact of compromised credentials or inappropriate activity.

Question 270

Which security measure can help ensure that only approved software executes on an endpoint?

  1. Application allowlisting
  2. Open file sharing
  3. Anonymous authentication
  4. Unrestricted scripting

Correct Answer: 1

Explanation

Application allowlisting permits execution only of software that has been explicitly approved according to organizational policy. This can reduce the risk of unauthorized applications, malicious executables, and unapproved tools running on managed endpoints. Effective allowlisting requires maintaining trusted application definitions and handling legitimate software changes through controlled processes. Open file sharing and anonymous authentication increase exposure, while unrestricted scripting can provide attackers with additional execution opportunities. Allowlisting should complement endpoint protection, patch management, least privilege, monitoring, and application control policies rather than being treated as the sole endpoint security mechanism.

Question 271

An organization wants to ensure that administrators use individually identifiable accounts when performing privileged tasks. Why is this important?

  1. It improves screen brightness
  2. It supports accountability
  3. It increases storage capacity
  4. It reduces network latency

Correct Answer: 2

Explanation

Individually identifiable privileged accounts support accountability by allowing administrative actions to be associated with a specific person. This improves monitoring, auditing, incident investigation, and enforcement of administrative responsibilities. Shared administrator credentials make it difficult to determine who performed a particular action and can weaken both deterrence and investigation. Individual accounts should be combined with strong authentication, least privilege, privileged access management, logging, and appropriate session monitoring. Screen brightness, storage capacity, and network latency are unrelated to identity accountability. Organizations should avoid using shared privileged credentials except where technically necessary and properly controlled.

Question 272

A company needs to determine whether an employee’s workstation is communicating with a known malicious domain. Which security capability is useful?

  1. Threat intelligence and DNS monitoring
  2. Printer management
  3. Disk formatting
  4. Employee scheduling

Correct Answer: 1

Explanation

Threat intelligence combined with DNS monitoring can help identify communications between internal systems and domains associated with known malicious infrastructure. Security teams can compare DNS requests against trusted threat intelligence sources and investigate suspicious resolutions or connection patterns. Detection should be supplemented with endpoint and network telemetry because threat intelligence may be incomplete, outdated, or inaccurate for some indicators. Printer management, disk formatting, and employee scheduling do not provide equivalent visibility into malicious domain communication. Organizations should establish procedures for validating alerts, investigating affected systems, and responding appropriately when suspicious communications are identified.

Question 273

Which practice helps prevent unauthorized modification of security policies?

  1. Allowing anyone to edit policies
  2. Controlled policy approval and version management
  3. Removing policy ownership
  4. Storing policies without access restrictions

Correct Answer: 2

Explanation

Controlled policy approval and version management help ensure that security policies are reviewed, authorized, documented, and protected against unauthorized modification. A defined approval process establishes accountability for policy ownership and confirms that changes have appropriate business and security justification. Version management also allows organizations to identify what changed and maintain historical records when necessary. Allowing unrestricted editing or storing policies without access controls weakens governance. Removing policy ownership creates uncertainty about responsibility. Policies should be reviewed periodically and updated when business processes, technology, regulations, or organizational risks materially change.

Question 274

A security administrator wants to reduce the likelihood that a compromised workstation can directly communicate with sensitive database servers. Which architecture is appropriate?

  1. Flat network design
  2. Network segmentation
  3. Unrestricted routing
  4. Public addressing for all systems

Correct Answer: 2

Explanation

Network segmentation separates systems into controlled security zones and limits communication between them according to defined requirements. A workstation used by general employees can therefore be prevented from directly communicating with sensitive database servers unless an approved application or administrative path is required. Segmentation can reduce lateral movement opportunities and limit the potential impact of compromised endpoints. A flat network, unrestricted routing, and broad public addressing can increase exposure. Effective segmentation should be supported by firewalls, access-control rules, monitoring, documented communication requirements, and periodic review to ensure that permitted connections remain necessary.

Question 275

A company wants to confirm that an employee’s access was removed after termination. Which evidence is most useful?

  1. Updated access and identity records
  2. Office temperature readings
  3. Printer usage statistics
  4. Marketing reports

Correct Answer: 1

Explanation

Updated access and identity records can demonstrate that accounts, credentials, group memberships, and other permissions were disabled or removed after an employee’s termination. Organizations should establish procedures that connect personnel status changes with identity-management workflows so that deprovisioning occurs promptly. Evidence may include timestamps, account status changes, revoked sessions, removed group memberships, and confirmation from responsible administrators. Office temperature, printer usage, and marketing reports do not directly verify authorization removal. Deprovisioning should also consider remote sessions, application-specific accounts, physical access badges, cloud services, and privileged credentials.

Question 276

Which recovery objective specifies the maximum acceptable amount of data loss measured in time?

  1. Recovery point objective
  2. Recovery testing frequency
  3. Recovery staffing level
  4. Recovery budget

Correct Answer: 1

Explanation

The recovery point objective, or RPO, defines the maximum amount of data loss an organization is prepared to tolerate, expressed as a period of time. For example, an organization with a one-hour RPO would generally require recovery capabilities that limit data loss to approximately one hour of transactions or changes. RPO influences backup frequency, replication strategies, and recovery architecture. It differs from the recovery time objective, which addresses how quickly a service should be restored. Recovery staffing, testing frequency, and budget support recovery planning but do not define the acceptable period of data loss.

Question 277

A security team is investigating an incident and needs to preserve evidence in a condition suitable for later review. Which practice is important?

  1. Evidence handling and chain of custody
  2. Random evidence deletion
  3. Unrestricted evidence access
  4. Unrecorded evidence transfer

Correct Answer: 1

Explanation

Evidence handling and chain of custody help demonstrate how evidence was collected, transferred, stored, accessed, and preserved throughout an investigation. Proper documentation can support evidence integrity and establish accountability for individuals who handled the material. Investigators should follow approved procedures, restrict access, record relevant actions, and use appropriate storage protections. Random deletion, unrestricted access, and unrecorded transfers can undermine confidence in evidence integrity and make later review more difficult. Evidence procedures should address both digital and physical material and should be aligned with organizational, legal, and investigative requirements.

Question 278

A system administrator plans to make a significant security-related configuration change to a production server. What should normally occur before implementation?

  1. Informal verbal approval only
  2. Approved change review
  3. Removal of backups
  4. Disabling monitoring

Correct Answer: 2

Explanation

An approved change review helps evaluate the security and operational consequences of significant modifications before they are introduced into production. The process can document the requested change, business justification, affected systems, implementation steps, testing requirements, rollback procedures, approvals, and maintenance timing. Significant changes should not rely solely on informal verbal approval because that may provide inadequate accountability or risk assessment. Removing backups or disabling monitoring increases risk during the change. Change management helps organizations maintain configuration integrity while ensuring that necessary modifications can be implemented in a controlled and traceable manner.

Question 279

Which activity helps determine whether security controls continue to operate as intended after implementation?

  1. Control effectiveness assessment
  2. Password sharing
  3. Unrestricted configuration changes
  4. Removal of audit records

Correct Answer: 1

Explanation

A control effectiveness assessment evaluates whether a security control is operating as designed and achieving its intended objective. Testing may include reviewing configurations, examining logs, observing processes, sampling transactions, interviewing responsible personnel, or performing technical validation. Regular assessment can identify controls that have become ineffective because of technology changes, process modifications, new threats, or implementation errors. Password sharing and unrestricted configuration changes weaken security, while removing audit records eliminates useful evidence. Control assessments should be documented, findings should be addressed according to risk, and remediation should be verified.

Question 280

A security manager wants to ensure employees know how to report suspected phishing messages. Which measure is most appropriate?

  1. Remove reporting procedures
  2. Establish a defined phishing-reporting process
  3. Encourage employees to forward messages publicly
  4. Disable email security monitoring

Correct Answer: 2

Explanation

A defined phishing-reporting process gives employees a clear and consistent method for reporting suspicious messages to the security team. The process may use a reporting button, dedicated mailbox, ticketing workflow, or another approved mechanism. Clear reporting procedures help security personnel collect indicators, investigate campaigns, protect other users, and provide timely feedback. Employees should also receive awareness training explaining how to recognize suspicious messages and avoid interacting with potentially malicious content. Publicly forwarding suspicious messages can expose additional users, while removing reporting procedures or disabling monitoring reduces the organization’s ability to detect and respond to phishing activity.