ISC SSCP Practice Test Questions and Exam Dumps Part19 Q361-380

View Full ISC SSCP Exam Dumps and Practice Test Dumps.

 

Question 361

Which document identifies identified risks, their owners, and planned responses within an organization?

  1. Risk register
  2. Network diagram
  3. Asset label
  4. Incident ticket

Correct Answer: 1

Explanation

A risk register provides a structured record of identified risks and commonly includes information such as risk descriptions, affected assets or processes, owners, likelihood, impact, treatment decisions, and status. It helps security and business teams track risks throughout their lifecycle and provides visibility into whether mitigation activities are progressing. A network diagram describes connectivity, an asset label identifies equipment, and an incident ticket records a specific operational or security event. Risk registers should be reviewed and updated when new threats, vulnerabilities, business changes, or control weaknesses alter the organization’s risk environment.

Question 362

A security team discovers that an application stores more customer information than is necessary for its business function. Which principle should guide remediation?

  1. Data duplication
  2. Data minimization
  3. Open access
  4. Unlimited retention

Correct Answer: 2

Explanation

Data minimization means collecting, processing, and retaining only the information necessary for a legitimate business purpose. Reducing unnecessary data can decrease the potential impact of unauthorized disclosure, simplify protection requirements, and reduce unnecessary storage and retention obligations. An organization should first determine what information the application genuinely requires and then remove or avoid collecting information that does not serve a defined purpose. Data duplication and unlimited retention can increase exposure, while open access creates additional confidentiality risks. Data minimization should be incorporated into system design, application requirements, and information-handling procedures.

Question 363

Who should normally be accountable for accepting a business risk when a security issue cannot be completely eliminated?

  1. Help-desk technician
  2. Database operator
  3. Authorized risk owner
  4. End user

Correct Answer: 3

Explanation

An authorized risk owner is accountable for understanding and accepting a business risk when an issue cannot be completely eliminated or when management chooses to retain the risk. Risk acceptance should be based on documented analysis of potential impact, likelihood, existing controls, and available treatment options. Technical personnel may identify or mitigate the issue, but they do not automatically have authority to accept organizational risk. Formal approval and documentation help establish accountability and demonstrate that the decision was made at an appropriate management level rather than informally by an individual administrator.

Question 364

Which technique can help protect sensitive data when an application must use the data but does not require the original value?

  1. Data masking
  2. Open sharing
  3. Credential reuse
  4. Port forwarding

Correct Answer: 1

Explanation

Data masking replaces or obscures sensitive values so that users or systems can work with representative information without receiving the original confidential data. For example, selected characters of an account number may be hidden when displaying information to authorized personnel who do not need the complete value. Masking can reduce unnecessary exposure in applications, reports, testing environments, and user interfaces. Open sharing increases exposure, credential reuse weakens authentication security, and port forwarding addresses network connectivity rather than data confidentiality. Masking should be designed carefully so that protected values cannot be easily reconstructed.

Question 365

A company wants to identify the person responsible for each critical information asset. Which practice is most appropriate?

  1. Asset ownership assignment
  2. Anonymous administration
  3. Public registration
  4. Shared responsibility without assignment

Correct Answer: 1

Explanation

Asset ownership assignment identifies an accountable individual or organizational role responsible for managing a particular information asset. Owners can help determine appropriate classification, access requirements, retention rules, security controls, and acceptable use. Clear ownership also improves accountability when an asset requires risk decisions, control reviews, or remediation. Anonymous administration and shared responsibility without defined accountability can create uncertainty about who must make decisions or address security problems. Asset ownership should remain current as personnel, organizational responsibilities, systems, and business processes change.

Question 366

An organization wants to prevent users from installing unapproved browser extensions on managed workstations. Which control is most appropriate?

  1. Public DNS
  2. Endpoint application control
  3. Network time synchronization
  4. Backup rotation

Correct Answer: 2

Explanation

Endpoint application control can restrict which software components, including browser extensions where supported, may be installed or executed on managed workstations. This reduces the possibility that users introduce extensions containing malicious code, excessive permissions, tracking functionality, or other unwanted behavior. Controls should be based on approved software requirements and should include procedures for requesting legitimate exceptions. Public DNS provides name-resolution services, time synchronization supports consistent timestamps, and backup rotation supports recovery. Endpoint controls should be centrally managed and periodically reviewed to ensure their rules remain appropriate.

Question 367

Which metric measures the percentage of security controls that meet their defined requirements during an assessment?

  1. Asset turnover
  2. Control compliance rate
  3. Network latency
  4. Storage capacity

Correct Answer: 2

Explanation

A control compliance rate can indicate the proportion of assessed controls that satisfy established requirements. This type of metric helps security teams identify areas where controls are operating as expected and where remediation may be required. The organization should define what constitutes compliance before measuring the metric so that results are consistent and meaningful. Asset turnover measures changes in equipment, network latency measures communication delay, and storage capacity concerns available data space. Security metrics should be interpreted within their context and should support informed decisions rather than being treated as isolated measures of overall security.

Question 368

A company needs to ensure that sensitive records are removed after their approved retention period. What should guide this process?

  1. Random deletion
  2. Informal employee preference
  3. Documented retention schedule
  4. Permanent storage

Correct Answer: 3

Explanation

A documented retention schedule defines how long specific categories of information should be retained and when they should be securely disposed of, subject to legal, regulatory, contractual, and business requirements. Applying a defined schedule helps prevent both premature destruction and unnecessary retention of sensitive records. Random deletion may destroy information that is still required, while permanent storage can increase exposure and storage obligations. Employee preference alone does not provide sufficient governance. Retention schedules should identify responsible parties, approved disposal methods, exceptions such as legal holds, and requirements for documenting completed disposal activities.

Question 369

Which control is designed to prevent sensitive information from being exposed through application error messages?

  1. Detailed public stack traces
  2. Secure error handling
  3. Anonymous debugging
  4. Unrestricted diagnostic output

Correct Answer: 2

Explanation

Secure error handling prevents applications from exposing sensitive technical details through messages presented to users. Production applications should generally avoid revealing credentials, database information, internal paths, stack traces, configuration details, or other information that could assist an attacker. Detailed diagnostic information can instead be recorded in protected logs accessible to authorized personnel when needed for troubleshooting. Public stack traces and unrestricted diagnostic output may reveal useful information about internal systems. Secure error handling should be incorporated during application development and testing, with logging designed to preserve useful investigative information without unnecessarily exposing sensitive data.

Question 370

A security administrator needs to determine whether a new system introduces unacceptable exposure before deployment. Which activity should be performed?

  1. Security risk assessment
  2. Printer maintenance
  3. Cable labeling
  4. Password sharing

Correct Answer: 1

Explanation

A security risk assessment evaluates potential threats, vulnerabilities, impacts, and existing or planned controls associated with a system. Conducting the assessment before deployment allows security concerns to be identified while design changes are still practical and less costly. The assessment can consider architecture, access controls, data sensitivity, dependencies, regulatory requirements, and likely threat scenarios. Printer maintenance and cable labeling support operational tasks, while password sharing weakens accountability and authentication security. Security assessments should involve appropriate technical and business stakeholders and should lead to documented decisions about risk treatment and required controls.

Question 371

Which practice helps prevent unauthorized personnel from following an employee through a controlled entrance?

  1. Open-door policy
  2. Shared access badges
  3. Mantrap or controlled-entry system
  4. Unmonitored entrance

Correct Answer: 3

Explanation

A mantrap or similar controlled-entry system can help prevent tailgating by requiring an individual to pass through a controlled area before another person can enter. Depending on the design, authentication may be required at one or both doors, and the system can restrict simultaneous entry. Shared badges and open or unmonitored entrances weaken individual accountability and make unauthorized physical access easier. Physical access controls should be selected according to facility risk, operational requirements, emergency procedures, and applicable safety considerations. Access records and monitoring can further support investigation of unauthorized entry attempts.

Question 372

Which network security control can limit the number of connection attempts accepted by an internet-facing service?

  1. Rate limiting
  2. File compression
  3. Data classification
  4. Asset tagging

Correct Answer: 1

Explanation

Rate limiting restricts how frequently requests or connection attempts can be processed from a user, client, source, or other defined context during a specified period. It can help reduce the impact of excessive requests, automated abuse, certain denial-of-service conditions, and repeated authentication attempts. Rate limits should be designed carefully so that legitimate users are not unnecessarily blocked. File compression reduces data size, data classification categorizes information according to sensitivity or impact, and asset tagging supports inventory management. Rate limiting works best when combined with monitoring, appropriate thresholds, and additional protective controls.

Question 373

An organization wants to prevent a compromised web server from directly communicating with every internal network segment. Which architecture is appropriate?

  1. Flat network
  2. Network segmentation with controlled paths
  3. Universal routing
  4. Unrestricted internal connectivity

Correct Answer: 2

Explanation

Network segmentation with controlled communication paths limits which internal systems a compromised server can reach. A web server can be placed in an appropriate network zone and permitted to communicate only with required services, such as a designated application or database tier. This reduces opportunities for lateral movement if the server is compromised. Flat networks and unrestricted connectivity provide broader access and can increase the potential scope of an intrusion. Segmentation should be supported by firewall or access-control rules, documented communication requirements, monitoring, and periodic review to ensure that unnecessary connections are removed.

Question 374

Which method can help determine whether a user should continue receiving access after moving to another department?

  1. Access recertification
  2. Data compression
  3. DNS caching
  4. Log formatting

Correct Answer: 1

Explanation

Access recertification requires authorized personnel to periodically confirm that users still require their assigned permissions. When an employee changes departments or responsibilities, recertification can reveal access that no longer matches the person’s current duties. Unnecessary permissions can then be removed through approved processes. This supports least privilege and reduces the risk created by accumulated access rights. Data compression affects storage efficiency, DNS caching supports name resolution, and log formatting concerns the presentation of recorded events. Access recertification should cover sensitive privileges and should maintain evidence that reviews were completed and identified issues were addressed.

Question 375

Which approach provides a secure way to store application secrets without embedding them directly in source code?

  1. Public text files
  2. Source-code comments
  3. Secrets management system
  4. Shared spreadsheet

Correct Answer: 3

Explanation

A secrets management system provides controlled storage and retrieval for sensitive values such as API keys, passwords, tokens, and certificates. Applications can retrieve required secrets through authenticated mechanisms rather than storing them directly in source code or configuration files that may be widely accessible. Centralized secrets management can also support access control, auditing, rotation, and lifecycle management. Public text files, source-code comments, and shared spreadsheets can expose credentials through repositories, backups, collaboration systems, or unauthorized access. Secret storage should follow least privilege and should provide appropriate monitoring and rotation capabilities.

Question 376

Which action helps maintain reliable timestamps across security devices when investigating an incident?

  1. Disable system clocks
  2. Use synchronized time sources
  3. Change clocks manually after incidents
  4. Allow unrestricted clock changes

Correct Answer: 2

Explanation

Synchronized time sources help security devices, servers, applications, and monitoring systems maintain consistent timestamps. Accurate and consistent time is important when reconstructing the sequence of events across multiple systems during an investigation. Without synchronization, events may appear out of order or have misleading timestamps, making correlation more difficult. Manual changes after an incident can undermine confidence in records, while unrestricted clock changes can allow inaccurate or manipulated timestamps. Organizations should use approved time sources, monitor synchronization status, protect time-service configurations, and investigate significant clock deviations.

Question 377

A security team wants to ensure that a cloud provider’s responsibilities for protecting customer data are clearly documented. Which document should be reviewed?

  1. Service agreement and security terms
  2. Office seating plan
  3. Printer maintenance record
  4. Employee vacation schedule

Correct Answer: 1

Explanation

The service agreement and associated security terms can document responsibilities between an organization and its cloud provider. Depending on the service, these terms may address data protection, access management, incident notification, availability, security controls, audit rights, retention, and other contractual obligations. Clearly defined responsibilities help reduce uncertainty about which party must implement or operate particular controls. Office seating plans, printer maintenance records, and vacation schedules do not establish cloud security responsibilities. Organizations should review provider agreements before adoption and periodically reassess them when services, requirements, regulations, or contractual terms change.

Question 378

Which security control can help ensure that only approved devices connect to an organization’s internal network?

  1. Network access control
  2. Public file sharing
  3. Anonymous authentication
  4. Open wireless access

Correct Answer: 1

Explanation

Network access control can evaluate connection requests and enforce requirements before allowing devices to access organizational network resources. Depending on the implementation, checks may include device identity, authentication status, security posture, certificate information, or compliance with defined endpoint requirements. This can help prevent unmanaged or unauthorized devices from obtaining unrestricted internal access. Public file sharing and anonymous authentication weaken access restrictions, while open wireless access allows broader connectivity. Network access control should be integrated with identity, endpoint, and network-security processes and should provide appropriate handling for approved exceptions and remediation.

Question 379

Which activity can help identify whether a security control remains appropriate after a major business process changes?

  1. Control reassessment
  2. Password publication
  3. Unrestricted access
  4. Random configuration

Correct Answer: 1

Explanation

Control reassessment evaluates whether an existing security control continues to address the risks and requirements associated with a changed environment. A major business process change can introduce new systems, data flows, users, dependencies, threats, or compliance obligations, potentially making an existing control insufficient or unnecessary. Reassessment allows security teams and business stakeholders to identify these changes and determine whether controls should be modified, replaced, or supplemented. Password publication and unrestricted access create security weaknesses, while random configuration changes do not provide structured assurance. Reassessment should be documented and performed according to organizational risk-management procedures.

Question 380

Which security practice helps ensure that sensitive credentials are not exposed in application source repositories?

  1. Store credentials in source files
  2. Commit secrets for convenience
  3. Use secret scanning and protected storage
  4. Publish configuration files publicly

Correct Answer: 3

Explanation

Secret scanning can identify credentials or other sensitive values accidentally placed in source repositories, while protected secret storage keeps operational credentials outside ordinary application source code. Combining these practices reduces the likelihood that passwords, API keys, tokens, or private keys will be exposed through repository history or developer workflows. Credentials should not be committed merely for convenience because removing them later may not eliminate copies from historical revisions. Publicly publishing configuration files creates additional exposure. Secure development processes should include secret-handling guidance, automated scanning, appropriate access controls, and credential rotation when exposure is suspected.