ISC SSCP Practice Test Questions and Exam Dumps Part12 Q221-240

View Full ISC SSCP Exam Dumps and Practice Test Dumps.

 

Question 221

Which security concept ensures that an individual cannot later deny performing an action when reliable evidence links the action to that individual?

  1. Availability
  2. Nonrepudiation
  3. Redundancy
  4. Obfuscation

Correct Answer: 2

Explanation

Nonrepudiation provides assurance that an action or transaction can be reliably associated with its originator, making it difficult for that individual to later deny having performed it. Digital signatures, authenticated records, secure audit trails, and controlled identity mechanisms can contribute to nonrepudiation. The strength of nonrepudiation depends on trustworthy authentication, protected records, appropriate cryptographic controls, and reliable processes. Availability focuses on access to resources, while redundancy improves resilience and obfuscation makes information less understandable. Organizations should select nonrepudiation mechanisms according to the legal, business, and technical requirements of the activity being protected.

Question 222

A security administrator discovers that several servers use different security configurations for the same business function. Which practice can improve consistency?

  1. Establish and enforce a standardized configuration baseline
  2. Allow each administrator to select settings independently
  3. Remove configuration documentation
  4. Disable configuration monitoring

Correct Answer: 1

Explanation

A standardized configuration baseline defines approved settings that systems performing similar functions should follow. Establishing and enforcing such baselines improves consistency, simplifies security assessments, and reduces the chance that one system will contain weaker protections than comparable systems. Configuration management tools can compare systems against the approved baseline and identify deviations. Individual administrators should not independently establish security settings without governance because inconsistent configurations can create gaps. Documentation and monitoring are important for maintaining the baseline over time. Approved exceptions should be formally documented, justified, reviewed, and assigned an expiration or reassessment date when appropriate.

Question 223

An organization needs to determine which business processes would be most severely affected by the loss of a critical application. Which activity should be performed?

  1. Penetration testing
  2. Security awareness training
  3. Business impact analysis
  4. Certificate renewal

Correct Answer: 3

Explanation

A business impact analysis identifies critical business processes, supporting resources, dependencies, and the consequences of disruption. It helps organizations understand which applications and services require prioritized recovery and what level of disruption the business can tolerate. Information gathered through a BIA can support recovery objectives, continuity planning, resource allocation, and risk decisions. Penetration testing evaluates security weaknesses, awareness training addresses human security behavior, and certificate renewal manages digital certificates. A BIA should involve appropriate business and technical stakeholders so that recovery priorities reflect actual operational requirements rather than assumptions made solely by IT personnel.

Question 224

Which method provides a secure way for an administrator to manage a remote server over an untrusted network?

  1. Plain-text terminal access
  2. Unauthenticated file transfer
  3. Secure remote administration protocol
  4. Shared email credentials

Correct Answer: 3

Explanation

A secure remote administration protocol protects administrative sessions by providing appropriate authentication and encrypted communication. Secure Shell is a common example for managing supported systems remotely. Organizations should use strong authentication, restrict administrative access to authorized sources, protect private keys, and monitor privileged sessions where required. Plain-text administration can expose credentials and sensitive commands to interception. Unauthenticated file transfer and shared email credentials do not provide an appropriate mechanism for secure server administration. Remote management services should be minimized, hardened, and exposed only through controlled network paths.

Question 225

A company wants to ensure that a critical security function continues operating if its primary service becomes unavailable. Which design principle should be considered?

  1. Single point of failure
  2. High availability
  3. Unrestricted access
  4. Manual configuration drift

Correct Answer: 2

Explanation

High availability uses resilient architectures to reduce service interruption when components fail. Depending on requirements, this may involve redundant servers, clustered services, failover mechanisms, load distribution, multiple network paths, or geographically separated infrastructure. The appropriate design depends on business requirements and acceptable downtime. A single point of failure creates a dependency that can interrupt the service when one component fails. Unrestricted access does not improve availability and may create security exposure. Organizations should test failover mechanisms periodically because redundancy that has not been tested may not operate correctly during an actual outage.

Question 226

Which control is most appropriate for ensuring that visitors entering a restricted facility are accompanied by authorized personnel?

  1. Visitor escort procedures
  2. Data encryption
  3. Network segmentation
  4. Password history

Correct Answer: 1

Explanation

Visitor escort procedures help prevent unauthorized individuals from moving through restricted areas without appropriate supervision. Visitors can be required to register, display temporary identification, remain with an authorized employee, and return visitor credentials when leaving. These procedures are especially important in data centers, server rooms, laboratories, and other sensitive facilities. Encryption and network segmentation protect digital resources, while password history helps prevent reuse of previous passwords. Physical visitor controls should be supported by access authorization, identification, monitoring, and procedures for handling visitors who require access to sensitive equipment or information.

Question 227

A security analyst wants to identify whether a file transferred through an email attachment matches a known malicious sample. Which attribute can be compared efficiently?

  1. File color
  2. Cryptographic hash
  3. Screen resolution
  4. Printer queue length

Correct Answer: 2

Explanation

A cryptographic hash can provide a compact representation of file contents that analysts can compare with known indicators. If a file’s calculated hash matches a trusted malicious-file indicator, it can provide useful evidence that the same content is present. Hashes should be treated as one investigative indicator rather than definitive proof in every situation because modified malware may produce a different hash. Analysts may combine hashes with filenames, behavioral indicators, network activity, and endpoint telemetry. File appearance, screen resolution, and printer queue information do not provide an equivalent method for identifying known malicious file content.

Question 228

An organization wants to ensure that security-sensitive applications are developed according to approved security requirements. Which practice supports this objective?

  1. Ignoring security until deployment
  2. Allowing developers to bypass testing
  3. Integrating security requirements throughout the development lifecycle
  4. Removing code review

Correct Answer: 3

Explanation

Integrating security requirements throughout the development lifecycle helps identify and address security concerns before applications reach production. Security activities may include requirements analysis, secure design, code review, dependency assessment, testing, vulnerability remediation, and deployment controls. Addressing security only after deployment can make weaknesses more expensive and difficult to correct. Allowing developers to bypass testing or removing code review reduces opportunities to detect defects. Security should be integrated into development processes while maintaining appropriate separation of duties and approval requirements. Organizations should tailor development security controls to application risk, data sensitivity, and business requirements.

Question 229

Which control helps prevent unauthorized use of a workstation when an employee leaves the device unattended?

  1. Automatic screen locking
  2. Public network sharing
  3. Unrestricted local access
  4. Disabled authentication

Correct Answer: 1

Explanation

Automatic screen locking reduces the opportunity for an unauthorized person to use an unattended workstation under another employee’s authenticated session. Organizations can configure a suitable inactivity timeout based on risk and operational requirements and require authentication before the session becomes accessible again. This control is particularly important for devices that access sensitive applications or information. Public sharing and unrestricted local access increase exposure, while disabling authentication removes a fundamental security barrier. Automatic locking should complement strong authentication, endpoint security, physical safeguards, and user awareness rather than being treated as a complete workstation security solution.

Question 230

A security team needs to determine whether an external service provider has implemented required security controls. Which activity is most appropriate?

  1. Informal discussion without evidence
  2. Third-party security assessment
  3. Employee password survey
  4. Office equipment inspection

Correct Answer: 2

Explanation

A third-party security assessment evaluates whether an external provider meets defined security requirements. Depending on contractual arrangements, this may involve reviewing independent assurance reports, security questionnaires, audit evidence, certifications, penetration-testing summaries, or other documented evidence. The assessment should focus on requirements relevant to the services and information involved. Informal discussions alone may not provide sufficient assurance, while unrelated employee or office information does not establish the provider’s security posture. Organizations should perform appropriate due diligence before engaging providers and conduct periodic reassessment when services, risks, or contractual requirements change.

Question 231

Which security control can help prevent an attacker from using a stolen password without an additional authentication factor?

  1. Multifactor authentication
  2. File compression
  3. Network broadcasting
  4. Data archiving

Correct Answer: 1

Explanation

Multifactor authentication requires users to provide authentication evidence from multiple factor categories, such as something they know, something they possess, or something they are. If an attacker obtains only a password, the additional factor can prevent successful authentication when properly implemented. MFA does not eliminate all account-compromise risks, particularly when attackers can manipulate users or compromise authentication devices, but it significantly strengthens authentication compared with passwords alone. File compression, network broadcasting, and data archiving do not provide an additional identity-verification factor and therefore do not directly address stolen-password authentication.

Question 232

An organization needs to prevent sensitive information from leaving the environment through unauthorized email attachments. Which technology can assist?

  1. Network time synchronization
  2. Data loss prevention
  3. Disk defragmentation
  4. Hardware inventory

Correct Answer: 2

Explanation

Data loss prevention technology can inspect information and apply organizational policies designed to reduce unauthorized transmission of sensitive data. Depending on the implementation, DLP can examine email content, attachments, endpoint activity, or other communication channels and generate alerts or block selected actions. Effective DLP requires accurate data classification, carefully designed policies, monitoring, and procedures for legitimate exceptions. Time synchronization, disk maintenance, and hardware inventory address different operational requirements. DLP should be implemented as part of a broader data-protection strategy that includes access control, encryption, user awareness, and appropriate handling procedures.

Question 233

A security administrator discovers that a firewall contains an old rule created for an application that has been retired. What should be done?

  1. Keep the rule permanently
  2. Expand the rule to additional systems
  3. Remove the obsolete rule through change management
  4. Disable all firewall logging

Correct Answer: 3

Explanation

An obsolete firewall rule should be removed through the organization’s approved change-management process after confirming that the associated application and dependencies are no longer required. Unused rules increase configuration complexity and may create unnecessary attack paths if they permit traffic that is no longer justified. Administrators should document the change, obtain appropriate approval, verify that no legitimate service depends on the rule, and validate firewall behavior after removal. Expanding obsolete access increases exposure, while disabling logging removes useful visibility. Regular firewall rule reviews help maintain a manageable and secure network configuration.

Question 234

A company wants to identify which employees have access to a specific sensitive database. Which source provides the most direct information?

  1. Current authorization records
  2. Building temperature logs
  3. Printer maintenance records
  4. Software wallpaper settings

Correct Answer: 1

Explanation

Current authorization records provide the most direct information about which users or roles have permission to access a sensitive database. These records may include role assignments, access-control lists, group memberships, and application-specific permissions. Security teams should verify that authorization information reflects current responsibilities because stale permissions can remain after transfers or other personnel changes. Physical and office-management records do not establish digital authorization. Access reviews should also identify privileged permissions, shared accounts, and exceptions so that unnecessary access can be removed. Sensitive database access should be monitored and periodically recertified.

Question 235

A security team wants to identify malicious activity by comparing current network behavior with normal activity. Which technique is useful?

  1. Baseline comparison
  2. Password reuse
  3. File renaming
  4. Manual data deletion

Correct Answer: 1

Explanation

Baseline comparison evaluates current activity against an established pattern of normal behavior. Network baselines can include expected traffic volumes, protocols, destinations, connection frequencies, and communication patterns. Significant deviations can generate investigation opportunities, although unusual activity is not automatically malicious. Legitimate business changes, software updates, backups, or seasonal demand can alter network behavior. Baselines should therefore be reviewed and updated when the environment changes. Password reuse, file renaming, and manual deletion do not provide a systematic method for identifying deviations in network activity. Effective monitoring combines baselines with other security indicators and contextual analysis.

Question 236

Which principle requires an organization to collect and retain only the information necessary for a defined business or security purpose?

  1. Unlimited retention
  2. Data minimization
  3. Universal access
  4. Maximum duplication

Correct Answer: 2

Explanation

Data minimization means collecting, processing, and retaining only the information necessary for a legitimate and defined purpose. Limiting unnecessary information can reduce storage exposure, privacy risks, breach impact, and administrative burden. Organizations should identify why information is required, restrict collection accordingly, and establish appropriate retention and disposal practices. Unlimited retention increases the amount of information that could be exposed during a security incident. Universal access and unnecessary duplication also increase exposure. Data minimization should work alongside classification, access controls, encryption, retention schedules, and secure disposal procedures.

Question 237

A security administrator needs to provide a temporary consultant with access to one application for two weeks. Which approach best follows least-privilege principles?

  1. Permanent administrator access
  2. Shared employee credentials
  3. Time-limited access restricted to the required application
  4. Organization-wide unrestricted access

Correct Answer: 3

Explanation

Time-limited access restricted to the required application follows least-privilege principles by limiting both the scope and duration of the consultant’s permissions. The organization should use an individual account, require appropriate authentication, document the business justification, and automatically or manually revoke access when the engagement ends. Permanent administrator access provides unnecessary privileges, while shared credentials weaken accountability. Organization-wide access exposes unrelated systems and information. Temporary access should be monitored and reviewed, particularly when the consultant handles sensitive information or connects remotely. Formal approval and deprovisioning procedures should support the arrangement.

Question 238

Which action is most appropriate when a security control is temporarily unable to meet its normal requirements because of a documented business constraint?

  1. Ignore the security requirement
  2. Create an undocumented permanent exception
  3. Disable all related monitoring
  4. Apply an approved exception with compensating controls and review

Correct Answer: 4

Explanation

An approved security exception can address a documented situation in which a control cannot currently meet its normal requirements. The exception should identify the business justification, affected systems, responsible risk owner, duration, and applicable compensating controls. A defined expiration or review date helps prevent temporary exceptions from becoming permanent weaknesses. Ignoring requirements or creating undocumented exceptions removes accountability. Disabling monitoring can make the situation harder to manage. Compensating controls should reduce the associated risk as much as reasonably possible until the original requirement can be restored or an alternative solution is formally approved.

Question 239

A company wants to ensure that critical security alerts are investigated according to their potential impact. Which practice supports this objective?

  1. Treat every alert identically
  2. Prioritize alerts using defined severity and risk criteria
  3. Investigate alerts only at the end of the month
  4. Ignore alerts from critical systems

Correct Answer: 2

Explanation

Prioritizing alerts using defined severity and risk criteria helps security teams focus attention on events that could have the greatest effect on important systems, information, or business operations. Criteria may include asset criticality, type of activity, confidence of detection, affected accounts, data sensitivity, and potential business impact. A consistent prioritization process supports timely escalation and efficient use of limited security resources. Treating every alert identically can delay response to serious events, while ignoring critical systems creates significant visibility gaps. Alert-priority rules should be documented, reviewed, and adjusted as threats and environments change.

Question 240

An organization wants to confirm that employees understand how to report suspected security incidents. Which activity provides useful evidence?

  1. Replacing employee identification cards
  2. Increasing network bandwidth
  3. Conducting a security awareness exercise
  4. Removing incident reporting procedures

Correct Answer: 3

Explanation

A security awareness exercise can provide evidence of whether employees understand how to recognize and report suspected security incidents. Exercises may use controlled scenarios, simulated phishing messages, reporting drills, or other activities designed to measure user behavior without causing actual harm. Results can identify gaps in awareness, unclear reporting channels, or additional training needs. Increasing network bandwidth and replacing identification cards address unrelated operational concerns. Removing reporting procedures would reduce the organization’s ability to receive timely information from employees. Exercises should be conducted ethically, documented appropriately, and used to improve awareness and incident-reporting processes.