ISC SSCP Practice Test Questions and Exam Dumps Part20 Q381-400

View Full ISC SSCP Exam Dumps and Practice Test Dumps.

 

Question 381

Which control helps prevent unauthorized users from connecting a personal device to a sensitive internal network?

  1. File compression
  2. Data retention
  3. Network access control
  4. Printer management

Correct Answer: 3

Explanation

Network access control can evaluate devices and connection requests before granting access to organizational resources. Depending on the implementation, the control may verify device identity, authentication, security posture, certificates, or compliance with organizational requirements. This helps prevent unmanaged or unauthorized devices from gaining inappropriate network access. File compression and data retention address different operational requirements, while printer management does not control network connectivity. Network access control should be configured according to business requirements and supported by monitoring, exception procedures, and periodic reviews to ensure that authorized devices continue to meet security requirements.

Question 382

Which principle requires access permissions to be limited to what a user needs to perform assigned duties?

  1. Least privilege
  2. Open access
  3. Universal authorization
  4. Shared administration

Correct Answer: 1

Explanation

Least privilege requires users, applications, and systems to receive only the permissions necessary to perform authorized tasks. Limiting privileges reduces the potential impact of compromised accounts, accidental actions, and misuse of administrative capabilities. Access should be based on legitimate business requirements and reviewed when responsibilities change. Open access and universal authorization provide broader permissions than necessary, while shared administration can weaken accountability. Least privilege should apply to ordinary users as well as privileged accounts and service identities. Organizations should periodically review permissions and remove access that is no longer justified.

Question 383

A security analyst needs to determine whether a suspicious file has been modified after it was collected as evidence. Which method is useful?

  1. File renaming
  2. Hash comparison
  3. File compression
  4. Permission expansion

Correct Answer: 2

Explanation

Hash comparison can help determine whether a file has changed after collection. A cryptographic hash is calculated from the evidence and can later be recalculated and compared with the original value. If the values match, the file content has remained consistent with respect to that hash algorithm. Investigators should document collection, storage, handling, and verification procedures to maintain evidence integrity. Renaming or compressing a file does not independently establish that its original contents remain unchanged, and expanding permissions can create additional opportunities for unauthorized modification.

Question 384

Which activity should occur before granting a third-party contractor access to sensitive organizational resources?

  1. Disable all monitoring
  2. Remove authorization requirements
  3. Allow unrestricted access
  4. Verify approved access requirements

Correct Answer: 4

Explanation

Before granting third-party access, the organization should verify the contractor’s approved business requirements and determine exactly which resources are necessary. Access should follow least privilege, use appropriate authentication, and be limited in scope and duration whenever practical. Contractual and security requirements should also be considered, particularly when sensitive information or critical systems are involved. Disabling monitoring or removing authorization requirements weakens oversight, while unrestricted access provides more privileges than necessary. Third-party access should be reviewed periodically and revoked promptly when the engagement ends or the business requirement changes.

Question 385

Which security control helps identify unusual changes to important operating system files?

  1. File integrity monitoring
  2. Network address translation
  3. Data archiving
  4. Password expiration

Correct Answer: 1

Explanation

File integrity monitoring detects changes to selected files and can alert security personnel when important system files are modified unexpectedly. Monitoring may include file contents, permissions, ownership, or other relevant attributes. Unexpected changes can indicate malware, unauthorized administration, configuration errors, or other security events. Alerts should be compared with approved maintenance and change records so legitimate activity can be distinguished from suspicious modifications. Network address translation handles network addressing, data archiving concerns long-term storage, and password expiration manages credential lifecycle requirements. File integrity monitoring should focus on files whose modification would have meaningful security implications.

Question 386

Which approach best protects a workstation if an unauthorized person attempts to use it while the employee is away?

  1. Disable logging
  2. Automatic screen locking
  3. Shared passwords
  4. Open sessions

Correct Answer: 2

Explanation

Automatic screen locking protects an unattended workstation by requiring the user to authenticate again before accessing the active session. This reduces the opportunity for another person to use applications, view sensitive information, or perform actions under the employee’s identity. Screen-lock policies should use reasonable inactivity periods based on organizational risk and operational needs. Shared passwords and open sessions weaken accountability and provide easier opportunities for unauthorized access. Disabling logging removes useful evidence rather than improving security. Automatic locking should complement authentication, endpoint protection, physical security, and user awareness controls.

Question 387

A company wants to ensure that employees cannot bypass required security controls by installing unauthorized applications. Which control is appropriate?

  1. Application allowlisting
  2. Public file sharing
  3. Anonymous administration
  4. Unrestricted installation

Correct Answer: 1

Explanation

Application allowlisting permits only approved software or software components to execute on managed systems. This can reduce the risk of unauthorized or malicious applications being installed and executed by users. Allowlisting rules should be maintained carefully so that required business applications continue to function and legitimate updates are handled appropriately. Public file sharing and anonymous administration do not restrict software execution, while unrestricted installation increases the possibility of unwanted software being introduced. Application allowlisting is particularly useful on systems where software execution must be tightly controlled and where the approved software set can be reasonably defined.

Question 388

Which security property ensures that information has not been altered without authorization?

  1. Availability
  2. Confidentiality
  3. Integrity
  4. Resilience

Correct Answer: 3

Explanation

Integrity ensures that information remains accurate, complete, and protected against unauthorized modification. Security controls supporting integrity can include access controls, cryptographic hashes, digital signatures, file integrity monitoring, change management, and protected logging. Confidentiality focuses on preventing unauthorized disclosure, while availability concerns reliable access to information and services. Resilience concerns the ability to continue or recover operations following disruption. Organizations should identify which information requires strong integrity protection and implement appropriate controls based on risk, business importance, and the consequences of unauthorized modification.

Question 389

A security administrator notices repeated failed logins from an unfamiliar geographic location. What should be done first?

  1. Ignore the events
  2. Disable all accounts
  3. Delete the authentication logs
  4. Investigate the authentication activity

Correct Answer: 4

Explanation

Repeated failed logins from an unfamiliar location may indicate credential attacks, unauthorized access attempts, misconfiguration, or legitimate activity that requires explanation. The appropriate initial response is to investigate the authentication activity using available logs and contextual information. Analysts can examine usernames, timestamps, source addresses, authentication methods, successful logins, and related events to determine whether the activity is suspicious. Automatically disabling all accounts could unnecessarily disrupt legitimate users, while deleting logs would remove valuable evidence. Ignoring the events provides no opportunity to determine whether a security incident is developing.

Question 390

Which practice helps ensure that an organization’s firewall rules continue to reflect current business requirements?

  1. Disable rule reviews
  2. Periodic firewall rule review
  3. Allow every protocol
  4. Create permanent temporary rules

Correct Answer: 2

Explanation

Periodic firewall rule review helps determine whether existing rules remain necessary, correctly configured, and aligned with current business requirements. Reviews can identify obsolete rules, excessive access, duplicate entries, unsupported services, and rules created for temporary purposes that are no longer required. Removing unnecessary rules reduces the attack surface and can make firewall policies easier to understand and manage. Disabling reviews and allowing every protocol increase exposure, while permanent temporary rules can accumulate unnecessary access. Changes to firewall rules should follow approved change-management procedures and be documented for accountability.

Question 391

Which recovery metric specifies the maximum acceptable amount of data that may be lost after a disruption?

  1. Recovery point objective
  2. Recovery time objective
  3. Mean time to repair
  4. Service availability target

Correct Answer: 1

Explanation

The recovery point objective, or RPO, defines the maximum acceptable amount of data loss measured in time. For example, an organization with a one-hour RPO should design backup and replication processes so that it can recover data to a point within approximately one hour of the disruption, subject to the organization’s implementation. RTO instead addresses how quickly a service should be restored. Mean time to repair measures repair performance, while an availability target describes expected service availability. RPO requirements influence backup frequency, replication strategies, and recovery architecture.

Question 392

A security team wants administrators to use separate accounts for ordinary work and privileged tasks. What security objective does this support?

  1. Data compression
  2. Privileged account separation
  3. Network broadcasting
  4. Backup deduplication

Correct Answer: 2

Explanation

Separating ordinary and privileged accounts helps reduce the unnecessary use of elevated permissions and improves accountability for administrative actions. Administrators can use standard accounts for routine activities and privileged accounts only when elevated access is required. This limits the exposure of powerful credentials and makes privileged activity easier to monitor and investigate. Data compression and backup deduplication address storage efficiency, while network broadcasting concerns communication behavior. Privileged account separation should be combined with strong authentication, access approval, logging, and periodic review of administrative permissions.

Question 393

Which control can help identify malicious or suspicious traffic entering or leaving a monitored network?

  1. Intrusion detection system
  2. Printer management
  3. Data classification
  4. File archiving

Correct Answer: 1

Explanation

An intrusion detection system monitors network or system activity for indicators that may correspond to malicious behavior, policy violations, or known attack patterns. Depending on its design, an IDS can analyze network traffic, host activity, signatures, anomalies, or other indicators and generate alerts for investigation. Data classification organizes information according to sensitivity, file archiving manages stored records, and printer management controls document output. IDS alerts should be reviewed in context because detection mechanisms can generate false positives and do not by themselves prove that an incident has occurred.

Question 394

A company is preparing to replace a critical application. Which activity helps ensure security requirements are included before implementation?

  1. Security requirements analysis
  2. Unrestricted deployment
  3. Password sharing
  4. Anonymous testing

Correct Answer: 1

Explanation

Security requirements analysis identifies the security capabilities and constraints that should be incorporated into a system before implementation. Requirements may address authentication, authorization, encryption, logging, privacy, data protection, availability, secure configuration, and regulatory obligations. Identifying these requirements early allows security considerations to influence architecture and design rather than being added after deployment. Unrestricted deployment, password sharing, and anonymous testing can introduce significant security weaknesses. Security requirements should be documented, reviewed by appropriate stakeholders, and validated during development and testing to confirm that the resulting system satisfies the organization’s needs.

Question 395

Which control can reduce the chance that a terminated employee continues using an existing authenticated session?

  1. Data classification
  2. Log compression
  3. Session revocation
  4. Asset labeling

Correct Answer: 3

Explanation

Session revocation invalidates active authentication sessions so that a user can no longer continue accessing resources through an existing session after authorization has been withdrawn. This is particularly important when an employee leaves the organization or when an account is suspected of compromise. Simply disabling future authentication may not terminate sessions that are already active if the application does not revalidate authorization. Data classification, log compression, and asset labeling serve different purposes. Organizations should incorporate session revocation into identity lifecycle procedures and verify that important applications respond appropriately to account deactivation.

Question 396

Which principle requires responsibilities for sensitive security activities to be divided among different individuals?

  1. Separation of duties
  2. Open administration
  3. Shared credentials
  4. Universal access

Correct Answer: 1

Explanation

Separation of duties divides sensitive responsibilities among different individuals or roles so that one person does not have excessive control over a critical process. For example, the person requesting a significant security change may be different from the person approving and implementing it. This reduces opportunities for unauthorized actions and provides an additional layer of oversight. Shared credentials and universal access weaken accountability, while open administration can provide unnecessary privileges. Separation of duties should be designed according to organizational risks and operational requirements without creating unnecessary delays in legitimate business processes.

Question 397

Which control helps ensure that only authorized software packages are obtained from an organization’s internal repository?

  1. Public package access
  2. Repository access control
  3. Anonymous downloads
  4. Unrestricted publishing

Correct Answer: 2

Explanation

Repository access control restricts who can retrieve, publish, modify, or administer software packages within an organizational repository. This helps reduce the risk of unauthorized package changes, malicious software insertion, or use of unapproved components. Strong authentication, role-based permissions, change auditing, and integrity verification can further protect software repositories. Public package access and anonymous downloads weaken control over software distribution, while unrestricted publishing can allow unauthorized users to introduce harmful content. Organizations should maintain approved software sources and monitor repository activity for unexpected changes or suspicious behavior.

Question 398

A security manager wants to ensure that an incident response plan remains usable after organizational responsibilities change. What should occur?

  1. Ignore the plan
  2. Delete previous procedures
  3. Review and update the plan
  4. Remove escalation contacts

Correct Answer: 3

Explanation

Incident response plans should be reviewed and updated when organizational roles, systems, contacts, technologies, or responsibilities change. An outdated plan may contain incorrect escalation paths, obsolete technical procedures, or missing responsibilities, reducing its usefulness during an actual incident. Regular reviews and exercises can identify these weaknesses before a real event occurs. Deleting previous procedures or removing escalation contacts reduces preparedness, while ignoring the plan leaves known changes unaddressed. Updates should be documented, approved through appropriate governance processes, communicated to relevant personnel, and validated through periodic exercises or simulations.

Question 399

Which method helps protect confidential information stored on a lost laptop?

  1. Full-device encryption
  2. Public file sharing
  3. Anonymous login
  4. Open storage permissions

Correct Answer: 1

Explanation

Full-device encryption protects data stored on a laptop by encrypting the contents of the device’s storage. If the laptop is lost or stolen and the encryption is properly implemented with protected authentication mechanisms, unauthorized individuals may be unable to read the stored information directly from the storage media. Public file sharing, anonymous login, and open storage permissions increase exposure rather than protecting confidential data. Encryption should be supported by secure key management, strong authentication, device-management controls, and appropriate recovery procedures to ensure that authorized users can continue accessing protected information.

Question 400

Which activity helps determine whether security controls operated as intended after an important system change?

  1. Ignore the change results
  2. Post-change security validation
  3. Remove monitoring
  4. Disable audit records

Correct Answer: 2

Explanation

Post-change security validation confirms that security controls continue to operate as intended after a system or configuration change. Validation may include testing access controls, authentication, logging, network restrictions, encryption, configuration settings, or other controls affected by the change. This helps identify unintended security weaknesses introduced during implementation. Ignoring results or disabling monitoring removes opportunities to detect problems, while disabling audit records reduces visibility into system activity. Validation should be documented and performed according to change-management procedures, with identified weaknesses corrected before the modified system is considered fully operational.