View Full ISC SSCP Exam Dumps and Practice Test Dumps.
Question 341
Which security control helps prevent unauthorized users from exploiting a stolen password alone?
- Data classification
- Multifactor authentication
- Network segmentation
- File compression
Correct Answer: 2
Explanation
Multifactor authentication requires users to provide two or more different authentication factors, such as something they know, something they have, or something they are. If an attacker obtains a password, an additional factor can prevent the attacker from successfully authenticating unless that factor is also compromised. MFA should be implemented according to the sensitivity of the account and application, with stronger methods used for privileged or high-risk access. Data classification, network segmentation, and file compression serve different security or operational purposes and do not directly provide additional authentication factors.
Question 342
An organization wants to ensure that a critical security process can continue if the primary system becomes unavailable. Which approach is appropriate?
- Single-server dependency
- Shared passwords
- Redundant infrastructure
- Unrestricted access
Correct Answer: 3
Explanation
Redundant infrastructure provides additional systems or components that can support operations when a primary component becomes unavailable. Depending on requirements, redundancy may involve servers, network paths, power supplies, storage, monitoring systems, or other critical infrastructure. The design should consider availability requirements, failure scenarios, dependencies, and recovery procedures. A single-server dependency creates a potential single point of failure, while shared passwords and unrestricted access introduce security risks rather than improving resilience. Redundant systems should be tested periodically to confirm that failover mechanisms work as intended and that personnel understand the required recovery procedures.
Question 343
Which activity helps determine the priority of systems that must be restored after a major disruption?
- Business impact analysis
- Password expiration
- File compression
- Network address translation
Correct Answer: 1
Explanation
Business impact analysis identifies the consequences of disruptions to business processes and helps establish recovery priorities. It can evaluate financial effects, operational dependencies, regulatory concerns, customer impact, and the maximum tolerable disruption for important services. The results help organizations determine which systems and processes require faster recovery and which dependencies must be restored first. Password expiration addresses credential management, file compression affects storage efficiency, and network address translation supports network communication. Business impact analysis should involve relevant stakeholders and be reviewed when business processes, dependencies, or critical service requirements change.
Question 344
A security administrator wants to prevent unauthorized changes to audit records. Which control is most appropriate?
- Public log access
- Unrestricted deletion
- Shared administrator accounts
- Restricted log permissions
Correct Answer: 4
Explanation
Restricted log permissions limit who can access, modify, or delete audit records and help preserve their integrity. Security logs should generally be accessible only to authorized personnel with a legitimate operational or investigative requirement. Additional protections may include centralized collection, write-protected storage, integrity monitoring, retention controls, and separation between administrators and personnel responsible for reviewing their activities. Public access and unrestricted deletion create opportunities for tampering, while shared administrator accounts weaken accountability. Log protection is important because audit records may provide evidence during security investigations, compliance reviews, and operational troubleshooting.
Question 345
Which practice helps ensure that a departing employee’s physical access credentials are no longer valid?
- Disable the access badge
- Increase badge privileges
- Share the badge
- Extend the badge indefinitely
Correct Answer: 1
Explanation
Disabling an employee’s physical access badge as part of the termination process prevents continued entry into controlled facilities. Physical deprovisioning should be coordinated with identity and personnel processes so that access is removed promptly when employment ends. Organizations may also recover keys, tokens, identification cards, and other physical credentials. Increasing privileges or extending a badge indefinitely creates unnecessary exposure, while sharing badges weakens accountability and makes access records less reliable. Effective physical access management should include authorization, periodic review, immediate revocation when required, monitoring of entry records, and procedures for lost or stolen credentials.
Question 346
A company wants to identify whether a workstation has unauthorized software installed. Which activity is useful?
- Software inventory review
- Network cable labeling
- Printer cleaning
- Office temperature monitoring
Correct Answer:1
Explanation
A software inventory review compares installed applications against approved software lists, licensing requirements, and organizational standards. This can help identify unauthorized, outdated, unsupported, or potentially risky software. Accurate software inventories also support vulnerability management because security teams need to know which applications and versions are deployed across the environment. Network cable labeling, printer cleaning, and temperature monitoring do not directly establish whether software installations are authorized. Software inventory information should be maintained throughout the asset lifecycle and updated when applications are installed, removed, upgraded, or replaced.
Question 347
Which security mechanism can help ensure that an application communicating with a remote service is connecting to the intended service?
- File compression
- Certificate validation
- Data replication
- Screen locking
Correct Answer: 2
Explanation
Certificate validation helps a client verify the identity of a remote service when using certificate-based secure communications. The client can evaluate the certificate chain, validity period, trusted issuer, hostname or service identity, and other applicable properties. Proper validation helps reduce the risk of connecting securely to an impostor or malicious intermediary. File compression and data replication serve storage or availability purposes, while screen locking protects unattended devices. Certificate management should include secure issuance, renewal, revocation, and protection of private keys to maintain trust throughout the certificate lifecycle.
Question 348
An organization wants to reduce unauthorized access caused by employees sharing passwords. Which policy should be emphasized?
- Password sharing encouragement
- Shared administrative accounts
- Individual account responsibility
- Public credential storage
Correct Answer: 3
Explanation
Individual account responsibility requires users to authenticate with their own assigned credentials rather than sharing passwords or accounts. This improves accountability because actions can be associated with specific identities and makes auditing and investigation more reliable. Policies should clearly prohibit credential sharing and explain how users should request appropriate access when necessary. Shared administrative accounts make attribution difficult, while public credential storage directly exposes sensitive authentication information. Strong authentication, password-management practices, and multifactor authentication should complement individual account controls to reduce the likelihood and impact of credential compromise.
Question 349
Which process helps ensure that security configurations remain consistent across similar systems?
- Configuration baselines
- Uncontrolled customization
- Anonymous administration
- Random configuration changes
Correct Answer: 1
Explanation
Configuration baselines define approved settings that systems should follow to meet organizational security and operational requirements. Applying consistent baselines across similar systems makes it easier to identify deviations, reduce configuration errors, and maintain predictable security controls. Baselines may address services, authentication settings, permissions, logging, network configurations, and other system characteristics. Uncontrolled customization and random changes can create configuration drift, while anonymous administration weakens accountability. Baselines should be documented, reviewed, updated when requirements change, and supported by automated or manual compliance checks.
Question 350
A security analyst discovers suspicious activity involving a privileged account. What should be preserved before making major changes to the affected system?
- Relevant investigation evidence
- Unrelated marketing documents
- Printer configuration files
- Office seating plans
Correct Answer: 1
Explanation
Relevant investigation evidence should be preserved before major changes are made to an affected system because actions such as rebooting, terminating processes, deleting files, or altering configurations can destroy useful information. Depending on the incident, evidence may include volatile memory, logs, network connections, process information, authentication records, and relevant files. Investigators should follow approved evidence-handling procedures and document collection activities. Preserving evidence supports accurate analysis and accountability. Unrelated business documents, printer files, and office seating plans generally do not provide the technical information needed to investigate privileged account activity.
Question 351
Which control can reduce the risk of unauthorized access when employees connect to corporate systems from remote locations?
- Secure remote access gateway
- Open remote administration
- Anonymous connections
- Public administrative interfaces
Correct Answer: 1
Explanation
A secure remote access gateway can provide a controlled entry point for users connecting to corporate resources from external networks. It may enforce strong authentication, authorization, encryption, device checks, session controls, logging, and other security requirements before allowing access. Open remote administration and public administrative interfaces expose sensitive services unnecessarily, while anonymous connections weaken identity assurance. Remote access should follow least privilege and should provide access only to the systems and resources required for authorized work. Organizations should monitor remote connections and periodically review remote-access configurations for security and business relevance.
Question 352
A company needs to ensure that confidential information is accessible only to employees with an approved business requirement. Which control is appropriate?
- Open permissions
- Access authorization
- Anonymous sharing
- Public distribution
Correct Answer: 2
Explanation
Access authorization determines whether an authenticated individual or system is permitted to access a specific resource. For confidential information, authorization should be based on legitimate business requirements, organizational roles, need-to-know, and least privilege. Access should be denied when a user lacks the necessary authorization even if the user can identify the location of the information. Open permissions, anonymous sharing, and public distribution can expose sensitive content to unauthorized parties. Authorization should be enforced consistently and reviewed periodically because employee responsibilities, application requirements, and information sensitivity can change.
Question 353
Which activity helps an organization verify that employees can perform their assigned incident-response responsibilities?
- Security exercise
- Data duplication
- Password reuse
- Network broadcasting
Correct Answer: 1
Explanation
A security exercise allows personnel to practice incident-response responsibilities in a controlled environment. Exercises can test communication, escalation, technical procedures, decision-making, evidence handling, and coordination between teams. Scenarios may include simulated malware, unauthorized access, data exposure, or service disruption. The results can reveal weaknesses in procedures or training before a real incident occurs. Data duplication, password reuse, and network broadcasting do not validate incident-response capabilities. Organizations should document exercise findings, assign corrective actions, and update response procedures or training when the exercise identifies meaningful gaps.
Question 354
Which control helps ensure that users cannot access a restricted application simply by modifying the client-side interface?
- Client-side trust only
- Server-side authorization
- Open application permissions
- Anonymous access
Correct Answer: 2
Explanation
Server-side authorization ensures that the application independently verifies whether a user is permitted to perform a requested action or access requested data. Relying only on client-side controls can allow an attacker to manipulate requests or bypass interface restrictions. Server-side checks should validate identity, permissions, requested resources, and applicable business rules before processing sensitive operations. Open permissions and anonymous access increase exposure, while client-side trust alone is insufficient for protecting important resources. Secure application design should combine authorization with strong authentication, input validation, logging, session management, and appropriate error handling.
Question 355
A security team wants to detect unexpected changes to a server’s critical configuration files. Which capability should be used?
- File integrity monitoring
- Network compression
- Data replication
- DNS caching
Correct Answer: 1
Explanation
File integrity monitoring tracks selected files and can alert when their contents, permissions, or other monitored attributes change. Critical configuration files are useful monitoring targets because unauthorized modifications may indicate malicious activity, administrative mistakes, or unexpected software behavior. Alerts should be correlated with approved change records to distinguish legitimate maintenance from suspicious changes. Network compression reduces traffic size, data replication supports availability, and DNS caching improves name resolution. File integrity monitoring is most effective when critical files are carefully selected, alerts are reviewed promptly, and authorized changes are documented through configuration-management processes.
Question 356
Which approach can reduce the impact of a compromised user account by limiting access to sensitive network zones?
- Network segmentation
- Shared credentials
- Open routing
- Public network access
Correct Answer: 1
Explanation
Network segmentation separates systems and services into controlled zones and limits communication between them according to defined requirements. If a user account or workstation is compromised, segmentation can prevent or restrict direct access to sensitive environments such as databases, management networks, or critical infrastructure. Firewall rules, access-control policies, and monitoring can enforce the boundaries. Shared credentials, open routing, and public access increase opportunities for unauthorized movement. Segmentation should reflect application dependencies and business requirements and should be reviewed periodically to ensure that permitted communication remains necessary.
Question 357
A company wants to verify that a backup can actually be used to restore a critical service. Which activity should be performed?
- Backup restoration test
- Backup renaming
- Backup deletion
- Backup publication
Correct Answer: 1
Explanation
A backup restoration test verifies that stored backup data can be successfully recovered and used to restore the intended systems or information. Merely creating backups does not demonstrate that they are complete, uncorrupted, accessible, or compatible with recovery procedures. Restoration testing can identify missing files, configuration dependencies, inadequate recovery documentation, or unexpected technical problems. Renaming or publishing backups does not establish recoverability, while deleting backups directly reduces recovery capability. Tests should be performed periodically and should reflect recovery objectives, critical services, dependencies, and appropriate security controls.
Question 358
Which security practice helps ensure that employees understand how to handle information according to its sensitivity?
- Security awareness and data-handling training
- Unrestricted file sharing
- Anonymous storage
- Public document access
Correct Answer: 1
Explanation
Security awareness and data-handling training teaches employees how information should be accessed, stored, transmitted, shared, retained, and disposed of according to its sensitivity. Training should reflect organizational classification policies and address practical situations employees encounter during daily work. It can reduce accidental disclosure caused by inappropriate sharing, insecure storage, or mishandling of sensitive information. Unrestricted file sharing, anonymous storage, and public document access increase exposure rather than controlling information handling. Organizations should reinforce training periodically and evaluate completion, understanding, and behavior to identify areas requiring additional education.
Question 359
Which control can help detect unauthorized access attempts against a sensitive application by recording authentication activity?
- Authentication logging
- File compression
- Data replication
- Printer management
Correct Answer: 1
Explanation
Authentication logging records relevant login activity and can provide evidence about successful and failed access attempts. Security teams can use these records to identify repeated failures, unusual source locations, unexpected login times, privileged authentication activity, and other patterns that may require investigation. Logs should contain useful information while avoiding unnecessary sensitive data and should be protected against unauthorized modification. File compression and data replication address storage or availability requirements, while printer management concerns physical document output. Authentication logs are most useful when combined with reliable timestamps, centralized collection, monitoring, and appropriate retention.
Question 360
A security administrator needs to verify that a user’s permissions match the user’s current job responsibilities. Which activity should be performed?
- Access review
- Data compression
- Network broadcasting
- Printer maintenance
Correct Answer: 1
Explanation
An access review compares a user’s current permissions with documented job responsibilities and approved business requirements. The review can identify excessive privileges, outdated access, inappropriate group memberships, and permissions retained after role changes. Sensitive and privileged access should receive appropriate scrutiny, and identified discrepancies should be corrected through approved authorization processes. Data compression reduces storage requirements, network broadcasting distributes traffic, and printer maintenance addresses physical equipment. Access reviews should occur periodically and after significant role changes, and their results should be documented so that organizations can demonstrate that authorization remains aligned with current responsibilities.