ISC SSCP Practice Test Questions and Exam Dumps Part10 Q181-200

View Full ISC SSCP Exam Dumps and Practice Test Dumps.

 

Question 181

Which control helps ensure that a user cannot approve their own access request?

  1. Data encryption
  2. Separation of duties
  3. Network segmentation
  4. File compression

Correct Answer: 2

Explanation

Separation of duties prevents one individual from controlling multiple conflicting steps of a sensitive process. For access management, this can mean requiring one person to request access while another authorized individual approves it. The objective is to reduce the opportunity for unauthorized access, fraud, or abuse by distributing responsibilities. Organizations should define approval roles according to risk and business requirements. Technical controls can support the process by enforcing workflow and recording approvals. Encryption, segmentation, and compression may provide other security benefits, but they do not directly prevent a user from approving their own access request.

Question 182

A security administrator wants to prevent users from connecting unauthorized personal devices to corporate endpoints. Which control is most appropriate?

  1. Increase screen resolution
  2. Disable password expiration
  3. Restrict peripheral devices through endpoint management
  4. Remove endpoint monitoring

Correct Answer: 3

Explanation

Endpoint management can restrict or control the use of unauthorized peripheral devices such as personal USB storage, mobile devices, or other removable hardware. Policies may allow only approved device classes or specifically authorized devices to connect. This can reduce the risk of malware introduction, unauthorized data transfer, and loss of sensitive information. Organizations should document approved exceptions and monitor policy violations. Increasing screen resolution and disabling password expiration do not address unauthorized peripherals. Removing endpoint monitoring would reduce visibility into device activity. Device-control policies should be tested to ensure that legitimate business equipment continues to function.

Question 183

A company discovers that an employee’s account has privileges no longer required after a transfer to another department. What should occur?

  1. Remove or modify unnecessary privileges
  2. Grant additional administrative access
  3. Preserve all previous privileges indefinitely
  4. Disable all organizational accounts

Correct Answer: 1

Explanation

Unnecessary privileges should be removed or modified when an employee changes roles so that access remains aligned with current responsibilities. This supports least privilege and reduces the risk of misuse if the account is compromised. Organizations should have formal processes that notify access administrators when personnel changes occur and should verify that permissions are updated across relevant systems. Retaining historical privileges indefinitely creates unnecessary exposure. Granting more access without a business requirement increases risk, while disabling every organizational account would disrupt legitimate operations. Access changes should also be documented and periodically reviewed.

Question 184

A security team needs to protect credentials transmitted between an application and an authentication service. Which measure is most appropriate?

  1. Plain-text communication
  2. Unencrypted file transfer
  3. Shared passwords
  4. Encrypted communication using an approved secure protocol

Correct Answer: 4

Explanation

Using an approved secure communication protocol helps protect credentials while they travel between an application and an authentication service. Properly configured encrypted connections can provide confidentiality and help detect unauthorized modification or interception of transmitted information. Organizations should use current, supported protocols and appropriate certificate validation rather than relying on outdated or weak cryptographic configurations. Plain-text communication exposes credentials to interception, while shared passwords increase accountability and credential-management risks. Secure transport should be combined with strong authentication, access controls, logging, and appropriate credential lifecycle management.

Question 185

An organization wants to identify security weaknesses caused by incorrect system settings before they are exploited. Which activity is most suitable?

  1. Configuration assessment
  2. Employee satisfaction survey
  3. Asset decoration review
  4. Printer maintenance

Correct Answer: 1

Explanation

A configuration assessment evaluates systems against approved security baselines or defined configuration requirements. It can identify weaknesses such as unnecessary services, insecure permissions, weak authentication settings, excessive privileges, or unsupported protocols. Assessments may be automated or performed manually depending on the environment. Findings should be prioritized according to risk and addressed through established remediation processes. Configuration assessment differs from general vulnerability scanning because it focuses specifically on system settings and compliance with defined configuration standards. Employee surveys and equipment maintenance do not directly identify security weaknesses caused by incorrect system configurations.

Question 186

A security analyst receives an alert indicating that a privileged account authenticated from an unusual geographic location. What should the analyst do first?

  1. Immediately delete the account
  2. Validate the event using additional authentication and activity data
  3. Publish the alert publicly
  4. Ignore the event without investigation

Correct Answer: 2

Explanation

The analyst should validate the unusual authentication event using additional evidence before determining whether it represents unauthorized activity. Useful information may include source addresses, timestamps, authentication methods, device identifiers, VPN usage, travel records, and related successful or failed authentication events. Geographic anomalies can result from legitimate remote access, VPN gateways, cloud services, or inaccurate location mapping. Immediate account deletion may disrupt legitimate operations and destroy useful investigative context. Ignoring the event removes an opportunity to detect compromise. Correlation with multiple reliable data sources provides a more accurate basis for deciding appropriate containment or escalation.

Question 187

Which practice helps ensure that an organization’s security policies remain aligned with changes in business operations and threats?

  1. Permanent approval without review
  2. Removing policy ownership
  3. Periodic policy review and revision
  4. Allowing employees to modify policies independently

Correct Answer: 3

Explanation

Periodic policy review and revision help ensure that security requirements remain relevant as business processes, technologies, regulations, and threats change. Policies should have designated owners, defined review intervals, appropriate approval authorities, and version control. Changes should be communicated to affected personnel and supported by updated procedures or training when necessary. Permanent approval without review can leave outdated requirements in place. Allowing employees to independently modify policies undermines governance and accountability. Regular review also provides an opportunity to identify conflicting requirements, clarify responsibilities, and verify that policy statements continue supporting organizational security objectives.

Question 188

A company wants to ensure that an employee’s access is automatically removed when the employee leaves the organization. Which integration can best support this process?

  1. Screen-locking software
  2. Centralized identity lifecycle management
  3. Network cable labeling
  4. Printer monitoring

Correct Answer: 2

Explanation

Centralized identity lifecycle management can connect authoritative personnel information with account provisioning and deprovisioning processes. When an employee leaves, the system can trigger disabling or removal of accounts across supported applications and services. Automation can reduce delays and the risk of forgotten accounts, although organizations should still verify that deprovisioning occurred successfully. Manual processes may be necessary for systems that cannot integrate directly. Screen locking, cable labeling, and printer monitoring do not manage user identity lifecycles. Effective offboarding should also address privileged accounts, tokens, remote access, physical credentials, and other forms of organizational access.

Question 189

A security team is preparing to collect evidence from a compromised workstation. Which principle should guide the collection process?

  1. Preserve evidence integrity and document handling
  2. Modify evidence to make analysis easier
  3. Allow unrestricted access to collected evidence
  4. Discard original evidence after copying it

Correct Answer: 1

Explanation

Evidence collection should preserve integrity and document how evidence was identified, collected, transferred, stored, and accessed. Maintaining a documented chain of custody helps demonstrate that evidence was handled appropriately and supports its reliability during investigations or potential legal proceedings. Investigators should use approved procedures and tools and should minimize unnecessary modification of original evidence. Unrestricted access increases the possibility of alteration or loss, while discarding original evidence can eliminate an important reference. Organizations should also protect collected evidence through appropriate access controls, secure storage, and documented retention requirements.

Question 190

A company needs to reduce the risk that an attacker can move from a compromised user workstation to critical servers. Which architecture provides a useful defense?

  1. Flat network design
  2. Shared administrator accounts
  3. Network segmentation with controlled access paths
  4. Unrestricted internal connectivity

Correct Answer: 3

Explanation

Network segmentation separates systems into controlled security zones and limits communication between them according to documented requirements. If a user workstation becomes compromised, segmentation can restrict the attacker’s ability to directly reach critical servers and other sensitive resources. Firewalls, access control lists, identity-aware network controls, and monitoring can enforce communication boundaries. A flat network or unrestricted connectivity provides more opportunities for lateral movement. Shared administrator accounts also weaken accountability. Segmentation should be designed around business dependencies and reviewed whenever applications, network architecture, or security requirements change.

Question 191

An organization wants to verify that backup files can actually be used to restore a critical application. Which activity provides the strongest evidence?

  1. Checking only the backup file size
  2. Performing a documented restoration test
  3. Assuming backups are valid after creation
  4. Increasing backup frequency without testing

Correct Answer: 2

Explanation

A documented restoration test provides direct evidence that backup data can be successfully used to recover the required application or information. The test should verify restoration procedures, data integrity, dependencies, recovery time requirements, and the ability of responsible personnel to perform the process. A backup file existing on storage does not prove that it can be restored successfully. File size alone cannot establish usability, and increasing backup frequency without testing may simply create more unverified copies. Restoration tests should be performed periodically and their results documented so identified failures can be corrected before an actual outage occurs.

Question 192

A security administrator needs to limit access to a database containing highly sensitive records based on a user’s job responsibilities. Which control is appropriate?

  1. Role-based access control
  2. Open database permissions
  3. Shared database credentials
  4. Anonymous access

Correct Answer: 1

Explanation

Role-based access control assigns permissions according to defined job roles and responsibilities. Users receive access appropriate to their assigned roles rather than receiving broad permissions to the entire database. This supports least privilege and simplifies administration when responsibilities change. Database permissions should be reviewed periodically to identify excessive or outdated access. Open permissions, shared credentials, and anonymous access weaken accountability and can expose sensitive records. Role definitions should be based on documented business requirements, and particularly sensitive operations may require additional controls such as approval workflows, multifactor authentication, or separation of duties.

Question 193

A security team wants to detect attempts to exploit known vulnerabilities against internet-facing systems. Which capability can provide useful detection?

  1. Network intrusion detection or prevention
  2. Employee attendance tracking
  3. Document formatting controls
  4. Printer inventory

Correct Answer: 1

Explanation

Network intrusion detection or prevention systems can inspect network traffic for patterns associated with known attacks, exploit attempts, malicious protocols, or suspicious behavior. These systems can provide alerts or, when configured for prevention, potentially block selected traffic. They should complement rather than replace vulnerability management because detection does not remove the underlying weakness. Signature updates, appropriate tuning, and monitoring are important to reduce false positives and maintain useful coverage. Employee attendance, document formatting, and printer inventory do not directly provide visibility into network-based exploitation attempts against internet-facing systems.

Question 194

A company is developing a procedure for handling security incidents involving regulated information. Which element should be clearly defined?

  1. Notification and escalation responsibilities
  2. Employee vacation preferences
  3. Office decoration requirements
  4. Personal device colors

Correct Answer: 1

Explanation

Notification and escalation responsibilities should be clearly defined in procedures for incidents involving regulated information. Depending on applicable requirements, the organization may need to notify specific internal stakeholders, customers, regulators, law enforcement, or other parties within defined timeframes. Procedures should identify who evaluates the incident, who authorizes notifications, what evidence is required, and how communications are documented. Personnel should understand their responsibilities before an incident occurs. Unrelated workplace preferences do not contribute to incident handling. Procedures should be periodically reviewed and exercised to identify gaps before a real incident requires rapid decision-making.

Question 195

Which control can help ensure that administrators use individual identities rather than a shared privileged account?

  1. Shared password vault entry
  2. Individual privileged accounts with centralized management
  3. Anonymous administration
  4. Generic credentials posted for the team

Correct Answer: 2

Explanation

Individual privileged accounts allow administrative actions to be associated with specific people, improving accountability and supporting effective auditing. Centralized privileged access management can enforce stronger authentication, manage credential rotation, restrict privileges, and record administrative activity. Shared accounts make it difficult to determine who performed a particular action and can complicate investigations. Anonymous administration and publicly available credentials further weaken accountability. Organizations should provide administrators with only the privileges required for their responsibilities and should monitor privileged activity. Emergency or break-glass accounts should be tightly controlled and subject to appropriate logging and review.

Question 196

A security administrator wants to identify systems that have not received a required security update. Which information source is most useful?

  1. Patch and asset management records
  2. Employee directory photos
  3. Building access schedules
  4. Office supply records

Correct Answer: 1

Explanation

Patch and asset management records can show which systems are subject to required updates and whether those updates have been successfully installed. Effective records should associate assets with operating systems, software versions, patch status, and relevant ownership information. Security teams can compare installed versions with approved patch requirements and prioritize remediation based on exposure and risk. Asset records also help identify systems that may be missing from the patching process. Employee photos, building schedules, and office supply records do not provide the technical information needed to determine whether systems received required security updates.

Question 197

A company wants to ensure that a security monitoring system continues collecting logs when one collection component fails. Which design principle is useful?

  1. Single-point dependency
  2. Redundant collection architecture
  3. Manual collection once a year
  4. Unmonitored log deletion

Correct Answer: 2

Explanation

A redundant collection architecture can help maintain security visibility when an individual log collection component becomes unavailable. Organizations may use multiple collectors, failover mechanisms, buffering, or distributed collection depending on the environment. The design should ensure that events are not silently lost during component failures and that collected logs remain protected. Redundancy should be tested periodically because a design that has never been exercised may not perform as expected during an actual failure. A single collection dependency creates a potential visibility gap, while manual annual collection and uncontrolled deletion provide inadequate monitoring continuity.

Question 198

A security analyst receives a suspicious email reported by an employee. Which action can help determine whether the message was part of a larger campaign?

  1. Correlate message indicators across email and security logs
  2. Delete all similar messages without analysis
  3. Disable email logging
  4. Forward the message to every employee

Correct Answer: 1

Explanation

Correlating message indicators across email and security logs can help determine whether multiple users received related phishing or malicious messages. Analysts may compare sender information, domains, URLs, attachment characteristics, timestamps, delivery records, and related endpoint activity. This approach can reveal campaign scope and support appropriate containment. Deleting messages without analysis may remove useful evidence, while disabling logging reduces visibility. Forwarding suspicious messages to employees can expose additional people to malicious content. Reported messages should be handled through controlled security procedures, with relevant evidence preserved and affected users notified when necessary.

Question 199

A company needs to ensure that security controls continue meeting their objectives as the environment changes. Which practice supports this requirement?

  1. Ongoing control monitoring and periodic assessment
  2. One-time implementation with no review
  3. Removing control ownership
  4. Ignoring changes in system architecture

Correct Answer: 1

Explanation

Ongoing control monitoring and periodic assessment help determine whether security controls continue operating effectively as systems, threats, business processes, and technologies change. A control that was appropriate when implemented may become ineffective because of architectural changes, new dependencies, altered privileges, or emerging attack techniques. Monitoring can identify deviations while periodic assessments provide a more structured evaluation of effectiveness. Control owners should track findings and corrective actions. One-time implementation without review can allow weaknesses to persist unnoticed. Ignoring architectural changes prevents security teams from recognizing when controls need adjustment or replacement.

Question 200

A security manager wants to determine whether an organization’s incident response plan remains practical after major organizational changes. Which activity is appropriate?

  1. Delete the existing plan
  2. Conduct a tabletop or simulated incident exercise
  3. Stop incident reporting
  4. Assume the previous plan remains valid

Correct Answer: 2

Explanation

A tabletop or simulated incident exercise allows personnel to evaluate whether an incident response plan remains practical after organizational, technological, or procedural changes. Participants can review communication paths, responsibilities, escalation procedures, decision points, dependencies, and expected response actions without causing an actual disruption. Exercise findings can identify outdated contacts, unclear responsibilities, missing procedures, or gaps in technical capabilities. Simply assuming that an older plan remains valid can leave important weaknesses undiscovered. The plan should be updated based on exercise results and then communicated to relevant personnel so that responsibilities remain understood.