View Full ISC SSCP Exam Dumps and Practice Test Dumps.
Question 21
A security administrator needs to ensure that sensitive data remains unreadable if a storage device is stolen. Which security measure directly protects the data at rest?
- Network intrusion detection
- Full-disk encryption
- Security awareness training
- Network load balancing
Correct Answer: 2
Explanation
Full-disk encryption protects data at rest by encrypting information stored on a device’s storage media. If a laptop or other storage device is lost or stolen, encryption can prevent unauthorized individuals from reading its contents without the required authentication or recovery mechanism. Organizations should implement secure key management, enforce strong device authentication, and verify encryption coverage across applicable systems. Network intrusion detection monitors suspicious network activity, awareness training addresses user behavior, and load balancing distributes traffic. Although these controls contribute to broader security, they do not directly provide confidentiality for data stored on a stolen device.
Question 22
A company wants to ensure that critical security updates are applied consistently across its server environment. Which process should it establish?
- Allow each administrator to patch systems without records
- Disable vulnerability scanning
- Use a managed patch process with testing and verification
- Postpone all updates indefinitely
Correct Answer: 3
Explanation
A managed patch process helps ensure that security updates are evaluated, tested, deployed, and verified consistently across an organization’s systems. It should include asset identification, vulnerability prioritization, maintenance planning, change approval where required, deployment tracking, and confirmation that updates were successfully installed. Testing is especially important for critical services where an incompatible update could cause operational disruption. Unrecorded patching makes it difficult to demonstrate coverage or investigate failures, while disabling scanning and indefinitely postponing updates leave known weaknesses unresolved. A documented process supports timely remediation while balancing security requirements with service stability.
Question 23
An organization is designing access controls for a database containing confidential customer records. Which approach best supports controlled access?
- Grant all employees administrator permissions
- Share one account among every department
- Permit access based only on workstation location
- Assign role-based permissions according to job responsibilities
Correct Answer: 4
Explanation
Role-based access control assigns permissions according to defined organizational roles and responsibilities. For a confidential customer database, the organization can create roles for functions such as data entry, customer support, auditing, and database administration, each with only the access required. This approach simplifies permission management and supports consistent access reviews when employees join, leave, or change roles. Granting everyone administrator permissions or sharing a common account weakens accountability and increases exposure. Workstation location may be a useful contextual control, but it should not replace identity-based authorization and carefully defined permissions.
Question 24
A security analyst detects unusual outbound traffic from a workstation that normally communicates only with internal services. What should the analyst examine?
- Relevant network logs, endpoint activity, and destination details
- The workstation’s wallpaper
- The user’s preferred browser theme
- The office printer’s paper settings
Correct Answer: 1
Explanation
Unusual outbound traffic should be investigated by examining relevant network logs, endpoint activity, and destination details. The analyst should establish which process generated the traffic, when it occurred, which external addresses or services were contacted, and whether the activity matches expected business behavior. Correlating network telemetry with endpoint alerts and authentication records may reveal malware activity, unauthorized remote access, or legitimate software behavior. If evidence indicates a threat, the analyst should follow incident response procedures and apply proportionate containment. Cosmetic workstation settings and printer configuration do not provide meaningful evidence about suspicious network communications.
Question 25
A company wants to reduce the likelihood that a single compromised server can provide an attacker with access to every internal system. Which security strategy is most relevant?
- Increase the number of shared accounts
- Apply network segmentation and restrictive communication rules
- Disable system logging
- Use identical administrator credentials everywhere
Correct Answer: 2
Explanation
Network segmentation combined with restrictive communication rules can limit an attacker’s ability to move from one compromised system to other internal resources. Sensitive systems should be placed in appropriate security zones, with traffic permitted only when required for business or technical purposes. Firewalls, access control lists, and monitoring can enforce and verify these boundaries. Shared accounts and identical administrator credentials increase the consequences of credential compromise, while disabling logging removes valuable detection evidence. Segmentation is most effective when supported by identity controls, endpoint protection, continuous monitoring, and periodic review of permitted network paths.
Question 26
An organization needs to determine which information assets require the strongest protection. Which activity should be performed first?
- Replace all network switches
- Disable data retention
- Classify information according to sensitivity and business value
- Give every user unrestricted access
Correct Answer: 3
Explanation
Information classification helps an organization identify which assets require stronger protection based on sensitivity, business value, legal obligations, and potential harm from unauthorized disclosure or alteration. Classification levels should have clear handling requirements, such as access restrictions, encryption, retention, transmission safeguards, and disposal procedures. Asset owners and relevant stakeholders should participate in assigning classifications and reviewing them when information use changes. Replacing network switches does not establish information sensitivity, while disabling retention or granting unrestricted access can increase risk. Classification provides a foundation for selecting proportionate controls and allocating security resources according to business priorities.
Question 27
A security team wants to detect unauthorized changes to important system files. Which control is designed to identify such modifications?
- File integrity monitoring
- Network address translation
- Email filtering
- Load balancing
Correct Answer: 1
Explanation
File integrity monitoring detects changes to selected files, directories, and configuration objects by comparing their current state with an established baseline or by tracking relevant modification events. It can help identify unauthorized alterations to operating system files, security configurations, application components, and other sensitive resources. Alerts should be investigated to distinguish approved administrative changes from suspicious activity. The control is most useful when critical files are properly selected and baselines are maintained. Network address translation, email filtering, and load balancing address different technical functions and do not directly establish whether protected files have been modified.
Question 28
A company is establishing rules for employees who use corporate devices and networks. Which document typically defines acceptable use and prohibited activities?
- Disaster recovery test report
- Acceptable use policy
- Database schema
- Network topology diagram
Correct Answer: 2
Explanation
An acceptable use policy defines how employees and other authorized users may use organizational devices, networks, accounts, and information resources. It commonly addresses permitted activities, prohibited behavior, personal use, software installation, information handling, monitoring, and consequences for violations. The policy should be communicated clearly and supported by employee acknowledgment and appropriate training. A disaster recovery report documents recovery testing, a database schema describes data structures, and a network topology diagram depicts connectivity. These artifacts may support IT governance, but they do not replace a policy that establishes behavioral expectations for using organizational technology.
Question 29
A security administrator needs to ensure that access to a sensitive application is removed promptly when an employee leaves the organization. Which process is essential?
- Keep the account active indefinitely
- Share the departing employee’s password
- Disable or revoke access through the formal offboarding process
- Remove audit records before departure
Correct Answer: 3
Explanation
A formal offboarding process should promptly disable accounts, revoke credentials, remove application permissions, and recover organizational devices when an employee leaves. Timely deprovisioning reduces the risk of former personnel retaining access to confidential information or business systems. The process should coordinate human resources, management, IT, and security teams, with completion records maintained for accountability. Depending on organizational requirements, access may also need to be reviewed for shared resources, service ownership, and delegated permissions. Keeping accounts active or sharing passwords increases risk, while deleting audit records undermines accountability and incident investigation.
Question 30
A company wants to confirm that a security incident was handled according to its documented response procedures. Which evidence is most useful?
- Informal recollections without records
- Deleted incident tickets
- Unrelated system inventory reports
- Incident timeline, response records, and documented actions
Correct Answer: 4
Explanation
An incident timeline, response records, and documented actions provide evidence of how an incident was identified, assessed, contained, eradicated, and recovered from. Records should capture important decisions, timestamps, responsible personnel, communications, evidence handling, and follow-up activities. This information supports post-incident review, accountability, regulatory obligations where applicable, and improvement of response procedures. Informal recollections may be incomplete, while deleted incident tickets remove valuable context. System inventory reports can help identify affected assets but do not, by themselves, demonstrate that the response process was followed or that required actions were completed.
Question 31
A security team wants to reduce the risk of attackers exploiting unnecessary services on servers. What should administrators do?
- Enable every available service
- Disable unnecessary services and restrict required ones
- Share administrator credentials
- Turn off vulnerability management
Correct Answer: 2
Explanation
Disabling unnecessary services and restricting the services that must remain available reduces the attack surface of servers. Every running service may introduce software vulnerabilities, configuration weaknesses, or opportunities for unauthorized access. Administrators should identify required services, remove or disable those that are not needed, apply secure configurations, and monitor exposed interfaces. Changes should be tested to avoid disrupting legitimate business functions. Enabling every service increases exposure, shared administrator credentials weaken accountability, and disabling vulnerability management removes an important source of security information. Service minimization should be part of an ongoing secure configuration process.
Question 32
An organization wants to verify that a web application properly rejects unauthorized requests to restricted resources. Which testing activity is appropriate?
- Check only the website’s visual design
- Review office seating arrangements
- Perform authorized access-control testing
- Disable application logs
Correct Answer: 3
Explanation
Authorized access-control testing evaluates whether an application correctly enforces permissions for users, roles, and protected resources. Testers should verify that unauthenticated users cannot access restricted functions and that authenticated users cannot perform actions beyond their assigned privileges. Testing should follow an approved scope and use controlled accounts representing different permission levels. Results should be documented and any weaknesses remediated and retested. Visual design reviews and seating arrangements do not validate authorization behavior, while disabling logs can reduce the evidence available during testing. Access-control testing is particularly important for applications handling confidential or regulated information.
Question 33
A company needs to ensure that employees can recover access to their accounts without creating an easy path for attackers to take over those accounts. What should be designed?
- A secure identity verification and account recovery process
- A shared password for all employees
- An unrestricted password reset link
- A policy allowing support staff to disclose passwords
Correct Answer: 1
Explanation
A secure identity verification and account recovery process helps users regain access while reducing the risk of account takeover. Recovery procedures should verify the requester’s identity using appropriate evidence, protect recovery channels, limit repeated attempts, and generate audit records. Sensitive recovery actions may require additional verification or notification to the account owner. Shared passwords, unrestricted reset links, and password disclosure by support personnel undermine identity security and accountability. The recovery process should be tested against realistic abuse scenarios and should provide clear guidance to users without exposing secrets or creating weaker authentication paths than the normal login process.
Question 34
A security administrator wants to confirm that only approved software can execute on sensitive workstations. Which control may enforce this requirement?
- Network load balancing
- Application allowlisting
- Data compression
- Screen brightness management
Correct Answer: 2
Explanation
Application allowlisting permits execution of software that meets defined approval criteria while blocking unapproved applications. On sensitive workstations, it can reduce the risk of unauthorized tools, certain malware, and unapproved software being executed. Implementation requires careful planning, application inventory, policy design, exception handling, and testing to avoid blocking legitimate business activities. Allowlisting should be combined with patching, endpoint monitoring, least privilege, and other safeguards because it does not eliminate every attack path. Load balancing and compression address performance or data handling, while screen brightness management is unrelated to software execution control.
Question 35
A company wants to identify which systems and services are affected by a newly disclosed software vulnerability. What information is essential?
- Employee vacation schedules
- Dashboard color preferences
- Asset inventory and software version data
- Office furniture records
Correct Answer: 3
Explanation
An accurate asset inventory and software version data are essential for identifying systems potentially affected by a newly disclosed vulnerability. The organization should know which assets exist, where they are deployed, which software and versions they run, who owns them, and how critical they are to business operations. This information enables security teams to scope exposure, prioritize remediation, and verify patch coverage. Incomplete inventories can leave vulnerable systems undiscovered. Vacation schedules, dashboard preferences, and furniture records do not establish software exposure. Asset management should be maintained continuously and integrated with vulnerability management and change processes.
Question 36
A security team is preparing to investigate a suspected malware infection. Which action helps preserve useful forensic evidence?
- Immediately wipe the affected device
- Follow approved evidence preservation and collection procedures
- Allow users to clean the device themselves
- Delete security alerts
Correct Answer: 2
Explanation
Approved evidence preservation and collection procedures help maintain the integrity and usefulness of information gathered during a suspected malware investigation. Responders should follow organizational protocols for isolating affected systems, collecting relevant logs or forensic images, recording actions, and maintaining chain of custody when required. The appropriate containment method depends on the threat, business impact, and investigative objectives. Wiping the device immediately may destroy evidence, while uncontrolled user cleanup can alter important artifacts. Deleting alerts removes potentially valuable records. Evidence handling should be coordinated with incident response and legal or compliance teams when appropriate.
Question 37
A company wants to reduce unauthorized access to its internal network by devices that do not meet security requirements. Which approach is most relevant?
- Network access control
- Dashboard customization
- File compression
- Database indexing
Correct Answer: 1
Explanation
Network access control can evaluate devices against defined requirements before permitting or limiting their access to organizational networks. Depending on the implementation, checks may include device identity, security posture, endpoint protection status, patch levels, and compliance with organizational policy. Noncompliant devices may be denied access, restricted to remediation resources, or placed in a limited network segment. The organization should define clear enforcement rules and account for exceptions such as approved unmanaged devices. Dashboard customization, compression, and database indexing serve unrelated purposes and do not directly assess whether connecting devices meet security requirements.
Question 38
An organization needs to determine how quickly a critical business service must be restored after an outage. Which metric expresses the targeted maximum restoration time?
- Recovery point objective
- Mean time between failures
- Recovery time objective
- Data classification level
Correct Answer: 3
Explanation
The recovery time objective specifies the targeted maximum time for restoring a business service or system after a disruption. It helps organizations establish recovery priorities, select appropriate technology solutions, and plan the personnel and procedures required to resume operations. The recovery point objective addresses the acceptable amount of data loss measured in time, rather than the restoration deadline. Mean time between failures measures reliability, while data classification describes information sensitivity. Recovery objectives should be established through business impact analysis and validated through exercises to determine whether actual recovery capabilities meet the organization’s requirements.
Question 39
A security manager wants to ensure that employees understand how to handle confidential information when working remotely. Which measure is most appropriate?
- Allow confidential files to be stored on any personal device
- Provide remote-work security guidance and enforce approved safeguards
- Disable all endpoint security controls
- Permit unrestricted sharing of sensitive documents
Correct Answer: 2
Explanation
Remote-work security guidance supported by approved safeguards helps employees protect confidential information outside traditional office environments. Guidance should address secure network access, device protection, authentication, information storage, sharing practices, physical privacy, and incident reporting. Technical safeguards may include managed devices, encryption, multifactor authentication, endpoint protection, and controlled access to corporate resources. Unrestricted use of personal devices or sharing can expose sensitive information, while disabling endpoint controls removes important protections. The organization should communicate expectations clearly, provide practical training, and periodically review whether remote-work arrangements continue to meet its security and business requirements.
Question 40
A security team has completed a risk assessment and selected controls to address identified risks. What should happen next to support ongoing risk management?
- Stop reviewing the risks permanently
- Delete the risk assessment
- Ignore control performance
- Implement the controls, monitor their effectiveness, and reassess risk
Correct Answer: 4
Explanation
After selecting risk treatments, the organization should implement the controls, monitor their effectiveness, and reassess risk as conditions change. Implementation should have clear ownership, timelines, resources, and evidence of completion. Monitoring can reveal control failures, changing threats, new vulnerabilities, or unexpected operational effects. Periodic reassessment helps determine whether residual risk remains within approved tolerance and whether additional treatment is necessary. Permanently stopping reviews or deleting the assessment would weaken governance and accountability. Ongoing risk management is a continuous process that connects security decisions with changing business needs, technology environments, and threat conditions.