ISC SSCP Practice Test Questions and Exam Dumps Part16 Q301-320

View Full ISC SSCP Exam Dumps and Practice Test Dumps.

 

Question 301

Which security measure helps ensure that only authorized personnel can enter a server room?

  1. Physical access control
  2. Data compression
  3. Network load balancing
  4. File indexing

Correct Answer: 1

Explanation

Physical access control restricts entry to sensitive areas such as server rooms, network closets, and data centers. Controls may include access badges, biometric readers, security personnel, locks, mantraps, and visitor procedures. These measures help prevent unauthorized individuals from physically accessing systems, removing equipment, connecting unauthorized devices, or interfering with infrastructure. Physical controls should be based on the sensitivity of the facility and supported by monitoring and access records. Data compression, network load balancing, and file indexing serve different technical purposes and do not directly prevent unauthorized physical entry.

Question 302

A security analyst needs to determine whether a suspicious executable has been modified since it was collected as evidence. Which technique is useful?

  1. File renaming
  2. Hash comparison
  3. Data compression
  4. Screen recording

Correct Answer: 2

Explanation

Hash comparison can help verify whether a file’s contents have changed after collection. Investigators can calculate a cryptographic hash when evidence is acquired and later compare it with a newly calculated value. A matching value provides evidence that the content remains consistent with the original captured data, assuming the hashing method and process are appropriately implemented. File renaming and compression do not establish evidence integrity, while screen recording does not provide a cryptographic integrity check. Evidence handling should also include documentation, controlled storage, restricted access, and chain-of-custody records.

Question 303

Which access control model assigns permissions according to predefined organizational roles?

  1. Mandatory access control
  2. Discretionary access control
  3. Role-based access control
  4. Rule-based routing

Correct Answer: 3

Explanation

Role-based access control assigns permissions according to defined roles rather than individually granting every permission to every user. For example, employees in an accounting role may receive access to specific financial applications, while administrators receive different permissions based on their responsibilities. RBAC can simplify access administration and support consistent authorization when roles are well defined. Mandatory access control uses centrally enforced classifications and rules, while discretionary access control allows owners to control access to resources. Rule-based routing concerns network traffic and is not an authorization model for organizational roles.

Question 304

An organization wants to detect unauthorized changes to important system files. Which capability should be implemented?

  1. File integrity monitoring
  2. Network address translation
  3. Data deduplication
  4. Bandwidth shaping

Correct Answer: 1

Explanation

File integrity monitoring detects changes to selected files, directories, or system configurations and can alert security personnel when unexpected modifications occur. It is useful for monitoring critical operating system files, configuration files, application components, and other assets where unauthorized changes may indicate compromise or misuse. Monitoring rules should distinguish authorized changes from suspicious activity and should be integrated with change-management records where possible. Network address translation, data deduplication, and bandwidth shaping provide different network or storage functions and do not directly identify unauthorized file modifications.

Question 305

Which security practice reduces the risk of administrators using excessive privileges for routine tasks?

  1. Shared administrator accounts
  2. Privileged access separation
  3. Permanent full access
  4. Anonymous administration

Correct Answer: 2

Explanation

Privileged access separation limits the use of elevated permissions to tasks that genuinely require them. Administrators can use standard accounts for routine activities and separate privileged accounts or controlled elevation mechanisms for administrative operations. This reduces exposure if a routine workstation session or standard account is compromised. Shared administrator accounts weaken accountability, while permanent full access increases the potential impact of credential compromise or misuse. Anonymous administration prevents reliable attribution. Privileged access should be granted according to least privilege, protected with strong authentication, monitored, and periodically reviewed.

Question 306

A company wants to protect network traffic between two trusted internal systems from unauthorized interception. Which control is appropriate?

  1. Plaintext communication
  2. Secure encrypted communication
  3. Public file sharing
  4. Unauthenticated transfer

Correct Answer: 2

Explanation

Secure encrypted communication protects information while it travels between systems and can provide confidentiality and integrity protections when properly implemented. Even internal networks should not automatically be considered trusted because compromised endpoints, insider threats, misconfigurations, or unauthorized network access can expose communications. Appropriate secure protocols should be selected based on the application’s requirements and configured using supported cryptographic algorithms and certificates or keys. Plaintext communication and unauthenticated transfers can expose sensitive information. Public file sharing can also create unnecessary disclosure risks when used for protected data.

Question 307

Which document defines the actions personnel should follow when responding to a confirmed security incident?

  1. Incident response procedure
  2. Asset purchase record
  3. Network inventory
  4. Software license agreement

Correct Answer: 1

Explanation

An incident response procedure provides documented actions for detecting, analyzing, containing, eradicating, recovering from, and learning from security incidents. It can define roles, escalation paths, communication requirements, evidence-handling expectations, decision criteria, and technical response activities. Having documented procedures helps responders act consistently during stressful situations and reduces uncertainty about responsibilities. Asset inventories and software license records provide useful supporting information but do not define incident-response actions. Incident procedures should be reviewed and exercised periodically because systems, threats, organizational responsibilities, and communication requirements can change.

Question 308

A security team wants to prevent unauthorized users from connecting unmanaged devices to an internal network. Which technology can help enforce this requirement?

  1. Network access control
  2. Data archiving
  3. File compression
  4. Screen locking

Correct Answer: 1

Explanation

Network access control can evaluate devices and users before or during network connection and enforce requirements such as authentication, device compliance, security configuration, or authorization status. An organization can use NAC to restrict unmanaged or noncompliant devices to a remediation network or deny access altogether. This helps reduce the risk associated with unknown endpoints connecting to sensitive environments. Data archiving and file compression concern information management, while screen locking protects unattended workstations. NAC should be integrated with identity systems, endpoint security, network segmentation, and monitoring to provide effective network admission control.

Question 309

Which control helps prevent sensitive information from being exposed through an unattended workstation?

  1. Automatic screen locking
  2. Open file sharing
  3. Shared passwords
  4. Unrestricted remote access

Correct Answer: 1

Explanation

Automatic screen locking reduces the risk that an unauthorized person can access information through a workstation that has been left unattended. After a defined period of inactivity, the system requires the user to authenticate again before access is restored. Organizations should select an appropriate timeout based on risk and operational requirements. Automatic locking does not replace strong authentication or physical security, but it provides an important additional safeguard. Open file sharing, shared passwords, and unrestricted remote access can increase exposure. Users should also be trained to manually lock devices whenever leaving them unattended.

Question 310

A security manager needs to determine how quickly a critical service must be restored after an outage. Which metric should be evaluated?

  1. Recovery point objective
  2. Recovery time objective
  3. Password history
  4. Data classification

Correct Answer: 2

Explanation

The recovery time objective defines the maximum acceptable period within which a service or system should be restored after a disruption. It helps organizations determine recovery strategies, staffing needs, technical architecture, and continuity requirements. RTO differs from the recovery point objective, which addresses the maximum acceptable amount of data loss measured in time. Password history concerns credential reuse, while data classification determines how information should be handled based on sensitivity or impact. RTO values should be established according to business requirements and supported by recovery procedures that are tested regularly.

Question 311

Which control helps ensure that employees cannot access information simply because they know where the files are stored?

  1. Authorization controls
  2. Network broadcasting
  3. Data compression
  4. File naming standards

Correct Answer: 1

Explanation

Authorization controls determine whether an authenticated user is permitted to access a specific resource or perform a particular action. Authentication establishes identity, but authorization determines what that identity is allowed to do. Proper authorization prevents users from accessing sensitive information merely because they know its location or technical path. Permissions should follow least privilege, need-to-know requirements, and organizational roles. Network broadcasting, data compression, and file naming standards do not establish whether an individual has permission to access protected resources. Authorization decisions should also be enforced on the server side rather than relying solely on client applications.

Question 312

A security administrator needs to ensure that security logs cannot be modified easily by the administrators whose activities they record. Which approach is appropriate?

  1. Store logs in a protected centralized system
  2. Give all administrators write access
  3. Keep logs only on local endpoints
  4. Allow unrestricted deletion

Correct Answer: 1

Explanation

A protected centralized logging system can separate security records from the systems and administrators whose activities are being monitored. Access to the centralized repository should be restricted, and appropriate controls should prevent unauthorized modification or deletion. Centralization also improves correlation, investigation, retention, and monitoring across multiple systems. Giving all administrators write access creates a risk that monitored individuals could alter evidence. Keeping logs only on local endpoints can make them vulnerable to compromise, while unrestricted deletion undermines retention and accountability. Log architecture should include secure transmission, time synchronization, access controls, and appropriate retention policies.

Question 313

A company is evaluating a service provider that will process confidential customer information. Which activity should occur before granting the provider access?

  1. Third-party security assessment
  2. Immediate unrestricted access
  3. Removal of contractual requirements
  4. Anonymous account creation

Correct Answer: 1

Explanation

A third-party security assessment helps an organization evaluate whether a service provider has appropriate safeguards for protecting information and supporting agreed security requirements. Assessment activities may review security controls, access management, encryption, incident response, vulnerability management, compliance evidence, and relevant contractual commitments. The depth of assessment should reflect the sensitivity of the information and the risk associated with the service. Immediate unrestricted access increases exposure, while removing contractual requirements weakens accountability. Anonymous accounts make it difficult to attribute activity. Third-party risk management should continue throughout the relationship rather than ending after initial onboarding.

Question 314

Which measure can help identify whether a system is missing required security updates?

  1. Vulnerability and patch assessment
  2. Screen brightness monitoring
  3. Printer inventory
  4. Office temperature measurement

Correct Answer: 1

Explanation

Vulnerability and patch assessment can identify systems that are missing required security updates or running software versions associated with known weaknesses. Effective assessment depends on accurate asset and software inventories and may use authenticated scanning, configuration checks, endpoint management information, or other technical sources. Findings should be prioritized according to severity, exposure, business impact, and available mitigations. Screen brightness, printer inventories, and office temperature measurements do not establish whether security patches are installed. Patch assessment should be performed regularly and followed by remediation verification to confirm that identified weaknesses have been addressed.

Question 315

An organization wants to ensure that a critical security process continues operating if one monitoring component fails. Which design principle is useful?

  1. Redundancy
  2. Data exposure
  3. Single dependency
  4. Unrestricted access

Correct Answer: 1

Explanation

Redundancy provides alternative components or paths so that a critical security capability can continue operating when one component fails. Monitoring infrastructure may use redundant collectors, storage, network paths, or processing systems to reduce the likelihood that a single failure creates a significant visibility gap. Redundancy should be designed according to availability requirements and tested to ensure that failover works as expected. A single dependency creates a potential single point of failure, while unrestricted access and data exposure are unrelated to resilience. Redundant security systems should also receive appropriate maintenance, monitoring, and configuration management.

Question 316

Which process helps determine whether a proposed security exception should remain valid after its expiration date?

  1. Periodic exception review
  2. Permanent approval without review
  3. Automatic privilege expansion
  4. Removal of risk ownership

Correct Answer: 1

Explanation

Periodic exception review determines whether a previously approved deviation from a security requirement is still necessary and acceptable. Security exceptions should have a documented justification, defined scope, responsible risk owner, expiration date, and, where appropriate, compensating controls. At review time, the organization can determine whether the underlying issue has been resolved, whether the exception should be renewed, or whether normal security requirements can be restored. Permanent approval without review allows outdated exceptions to persist. Privilege expansion and removal of ownership weaken governance and accountability.

Question 317

A security team wants to reduce the chance that ransomware can encrypt the only available backup copy. Which strategy is useful?

  1. Isolated backup copies
  2. Shared writable backups
  3. Public backup access
  4. Permanent backup administrator access

Correct Answer: 1

Explanation

Isolated backup copies can reduce the likelihood that ransomware affecting production systems will also compromise backup data. Isolation may involve offline, logically separated, immutable, or otherwise protected copies depending on the organization’s architecture and recovery requirements. Backup access should be tightly controlled, monitored, and protected with strong authentication. Shared writable backups and public access create additional opportunities for unauthorized modification. Permanent administrator access also increases risk if privileged credentials are compromised. Organizations should regularly test restoration procedures and verify backup integrity rather than assuming that the existence of backup files guarantees recoverability.

Question 318

Which activity helps establish whether a security policy is being followed in daily operations?

  1. Compliance monitoring
  2. Password sharing
  3. Unrestricted configuration changes
  4. Removal of audit records

Correct Answer: 1

Explanation

Compliance monitoring evaluates whether systems, processes, and personnel are operating according to established security requirements. Monitoring can use automated configuration checks, audit records, access reviews, control testing, interviews, or other evidence. Findings can identify deviations that require remediation, investigation, or an approved exception. Password sharing and unrestricted changes undermine security requirements, while removal of audit records eliminates evidence that could demonstrate compliance or noncompliance. Compliance monitoring should be proportionate to risk and supported by clear policies, defined responsibilities, documented evidence, and periodic reassessment of the controls being monitored.

Question 319

A security administrator needs to verify that a firewall rule allows only the communication required by an application. What should be reviewed?

  1. Source, destination, protocol, and port requirements
  2. Employee attendance records
  3. Printer maintenance schedules
  4. Office seating arrangements

Correct Answer: 1

Explanation

Reviewing source, destination, protocol, and port requirements helps determine whether a firewall rule permits only the communication necessary for an application’s operation. This supports least privilege at the network level and reduces unnecessary exposure. Administrators should compare rules against documented application requirements, remove obsolete entries, and investigate overly broad permissions. Employee attendance records, printer schedules, and seating arrangements do not establish whether network traffic is appropriately authorized. Firewall rules should be reviewed periodically and after significant application or network changes, with modifications handled through approved change-management procedures.

Question 320

A security team completes an incident investigation and wants to improve future response capabilities. Which activity should follow the investigation?

  1. Lessons-learned review
  2. Deletion of incident records
  3. Removal of monitoring controls
  4. Permanent suspension of response procedures

Correct Answer: 1

Explanation

A lessons-learned review examines what happened during an incident, how effectively the organization responded, which controls worked, and where improvements are needed. The review can identify gaps in detection, communication, procedures, training, technology, recovery, or documentation. Findings should be converted into actionable improvements with appropriate ownership and tracking. Deleting incident records removes valuable organizational knowledge, while removing monitoring or suspending response procedures can increase future risk. Lessons learned should be conducted after significant incidents and exercises and should contribute to updates in security controls, procedures, training, and response plans.