View Full ISC SSCP Exam Dumps and Practice Test Dumps.
Question 41
A security administrator discovers that employees can connect personal USB storage devices to workstations containing sensitive information. Which control would best reduce the associated risk?
- Increase screen brightness
- Extend password expiration periods
- Implement removable media restrictions and monitoring
- Disable all workstation backups
Correct Answer: 3
Explanation
Removable media restrictions and monitoring help reduce the risk of unauthorized data transfer, malware introduction, and loss of sensitive information through portable storage devices. An organization can restrict USB storage access, permit only approved devices, enforce encryption requirements, and monitor file transfers. These controls should be aligned with business needs so that legitimate work is not unnecessarily disrupted. User awareness and endpoint protection can provide additional safeguards. Screen brightness and password expiration do not directly control removable media, while disabling backups could increase the consequences of data loss rather than address the underlying device risk.
Question 42
A company requires employees to prove their identity using both a password and a hardware security key before accessing a sensitive system. Which authentication approach is being used?
- Multifactor authentication
- Single sign-on
- Password synchronization
- Discretionary access control
Correct Answer: 1
Explanation
Multifactor authentication requires evidence from at least two distinct authentication factor categories, such as something a user knows, possesses, or is. A password represents something the user knows, while a hardware security key represents something the user possesses. Combining these factors makes unauthorized access more difficult when one credential is compromised. The organization should also protect key enrollment, replacement, recovery, and revocation procedures. Single sign-on allows users to access multiple services through an authentication session, password synchronization coordinates credentials, and discretionary access control governs resource permissions rather than establishing identity through multiple factors.
Question 43
A security officer must ensure that a departing contractor no longer has access to cloud applications, VPN services, and internal systems. Which process should coordinate these actions?
- Annual security awareness training
- Network capacity planning
- Data retention review
- Identity and access deprovisioning
Correct Answer: 4
Explanation
Identity and access deprovisioning coordinates the removal or disabling of a departing contractor’s accounts, credentials, tokens, and permissions across organizational services. A complete process should cover cloud applications, remote access, internal systems, privileged accounts, and any third-party access arrangements. It should be triggered promptly by an authoritative departure notification and include verification that access has been revoked. Organizations should also recover assigned devices and transfer ownership of relevant business resources. Annual training and capacity planning do not revoke access, while data retention review addresses information lifecycle requirements rather than the contractor’s active permissions.
Question 44
A company wants to detect suspicious activity by correlating authentication events, endpoint alerts, and network records from different systems. Which capability is designed for this purpose?
- File compression
- Security information and event management
- Database normalization
- Software license management
Correct Answer: 2
Explanation
Security information and event management systems collect and correlate security-related events from multiple sources to help identify suspicious activity. By analyzing authentication records, endpoint alerts, network logs, and other telemetry together, analysts can recognize patterns that might be difficult to detect in isolated systems. Effective implementation requires reliable time synchronization, useful log sources, appropriate detection rules, and procedures for investigating alerts. SIEM capabilities support monitoring and incident response but do not automatically establish that every alert represents a confirmed attack. Database normalization, file compression, and license management serve different operational purposes.
Question 45
A security team is evaluating whether a proposed system configuration follows the organization’s approved security settings. Which artifact provides the baseline for comparison?
- Approved security configuration baseline
- Employee vacation calendar
- Marketing campaign schedule
- Office seating chart
Correct Answer: 1
Explanation
An approved security configuration baseline defines the expected secure settings for a particular system type, application, or operating environment. Administrators and assessors can compare actual configurations against this baseline to identify deviations, missing safeguards, or unauthorized changes. Baselines may specify services, permissions, logging, authentication settings, encryption, and other security requirements. They should be version-controlled, reviewed periodically, and updated through an approved change process. Comparing against an informal or outdated reference may produce misleading results. Business calendars and seating charts do not establish technical security requirements or provide a reliable standard for configuration assessment.
Question 46
A company needs to protect sensitive information while it travels between a remote employee’s device and a corporate application over an untrusted network. Which safeguard is most directly applicable?
- Database indexing
- Screen locking alone
- Encryption in transit using a secure protocol
- File naming conventions
Correct Answer: 3
Explanation
Encryption in transit using a secure protocol protects information as it moves between a remote employee’s device and a corporate application. Properly configured protocols help prevent unauthorized parties from reading or modifying data exchanged over untrusted networks. Organizations should use current protocol versions, trusted certificates, secure cipher configurations, and appropriate endpoint validation. A virtual private network may provide an additional protected connection for certain access scenarios, but application-layer encryption remains important. Database indexing improves query performance, screen locking protects unattended devices, and file naming conventions organize information; none directly encrypts network communications.
Question 47
A company wants to establish the order in which critical systems and business functions should be restored after a major outage. Which activity provides the necessary business priorities?
- Penetration testing
- Business impact analysis
- Password complexity review
- Source code formatting
Correct Answer: 2
Explanation
A business impact analysis identifies critical business functions, their dependencies, and the consequences of disruption. Its findings help establish recovery priorities and inform decisions about recovery time objectives, recovery point objectives, staffing, alternate facilities, and technology resources. Business stakeholders should participate because technical teams alone may not understand the full operational or financial impact of service interruption. The results should be reviewed when business processes or dependencies change. Penetration testing examines security weaknesses, password reviews assess authentication practices, and source code formatting concerns software development quality rather than the prioritization of business recovery.
Question 48
A security analyst notices that a workstation is communicating with a command-and-control address identified by threat intelligence. What is the most appropriate immediate response?
- Ignore the communication until the next audit
- Delete all organization-wide network logs
- Publish the workstation’s details publicly
- Follow incident response procedures to investigate and contain the suspected compromise
Correct Answer: 4
Explanation
Communication with a known command-and-control address is a potential indicator of compromise and should be handled through the organization’s incident response procedures. The analyst should validate the alert, preserve relevant evidence, identify the affected device and user, and assess whether containment is necessary. Isolation or blocking actions should follow established authority and business-impact considerations. Investigators should correlate endpoint telemetry, network records, and other available evidence to understand the scope and likely activity. Ignoring the event or deleting logs would impair response, while publicly disclosing device details could create additional security and privacy risks.
Question 49
An organization wants to ensure that employees cannot access confidential records merely because they know the URL of an internal application. Which safeguard should be enforced?
- Server-side authorization checks for every protected request
- Hiding the URL from search engines
- Changing the application’s logo
- Disabling user activity logging
Correct Answer: 1
Explanation
Server-side authorization checks ensure that each request to a protected resource is evaluated against the authenticated user’s permissions. Access should not depend on whether a URL is hidden, difficult to guess, or absent from navigation menus. The application should verify that the user is permitted to view or modify the requested data and should deny unauthorized operations consistently. Authorization should be enforced for both user-interface actions and direct requests to application endpoints. Hiding URLs is not a substitute for access control, while logo changes and disabling activity logging do not prevent unauthorized resource access.
Question 50
A security administrator is selecting a method to securely dispose of retired storage media containing sensitive information. Which consideration is most important?
- Keep the media accessible to all employees
- Use an approved sanitization or destruction method appropriate to the media and data sensitivity
- Change the device’s asset label only
- Place the media in ordinary office recycling without review
Correct Answer: 2
Explanation
Secure disposal requires a sanitization or destruction method appropriate to the storage technology, information sensitivity, and applicable organizational requirements. Depending on the media, approved methods may include cryptographic erasure, validated sanitization, or physical destruction. The organization should verify that the selected process addresses residual data and document the disposition of the asset. Simply changing an asset label does not remove stored information, and ordinary recycling may expose data to unauthorized recovery. Disposal procedures should also account for third-party service providers, chain-of-custody requirements, and evidence that the process was completed as intended.
Question 51
A security team wants to reduce the likelihood that an attacker can use a compromised employee account to obtain administrative privileges. Which control is especially relevant?
- Allow permanent administrator rights for all users
- Share privileged credentials across teams
- Use privileged access management and just-in-time elevation
- Disable account activity monitoring
Correct Answer: 3
Explanation
Privileged access management helps control, monitor, and audit the use of elevated accounts. Just-in-time elevation can grant administrative permissions only when required and for a limited period, reducing the time that powerful access remains available. Supporting measures may include separate administrator identities, approval workflows, credential vaulting, session monitoring, and periodic privilege reviews. These controls reduce the potential impact of compromised ordinary accounts, although they must be implemented with appropriate emergency access procedures. Permanent administrator rights and shared credentials increase exposure, while disabling activity monitoring removes important evidence of privileged actions.
Question 52
A company needs to ensure that a software change does not introduce unapproved security weaknesses into a production application. Which process should govern the change?
- Unrecorded direct modification by any developer
- Formal change management with security review and testing
- Disabling the application’s security controls
- Allowing production changes without authorization
Correct Answer: 2
Explanation
Formal change management provides a controlled process for evaluating, approving, testing, implementing, and documenting changes to production systems. A security review can identify risks such as new access paths, insecure dependencies, altered permissions, or changes to data handling. Testing should verify both expected functionality and relevant security requirements before deployment. The process should include appropriate authorization, rollback planning, implementation records, and post-change validation. Unrecorded or unauthorized changes make it difficult to understand system behavior and investigate incidents. Disabling security controls or bypassing review increases the likelihood that changes will introduce preventable vulnerabilities.
Question 53
A company wants to prevent sensitive information from being sent to unauthorized external destinations through email or web uploads. Which type of control is designed to help enforce this requirement?
- Data loss prevention
- Network time synchronization
- Database indexing
- Hardware inventory labeling
Correct Answer: 1
Explanation
Data loss prevention controls help identify, monitor, and restrict the unauthorized transfer of sensitive information. Depending on the solution, policies may inspect content, classify data, detect sensitive patterns, and apply actions such as blocking, quarantining, alerting, or requiring justification. Controls can be applied to email, endpoints, web traffic, and cloud services. Effective deployment requires accurate data classification, carefully designed policies, and procedures for handling legitimate business exceptions. Time synchronization, database indexing, and hardware labeling support other operational needs but do not directly enforce restrictions on sensitive information leaving approved channels.
Question 54
A security analyst is investigating whether an employee accessed a restricted file outside normal working hours. Which records are most useful?
- Office temperature readings
- Marketing analytics
- Relevant access logs and identity records
- Printer toner inventory
Correct Answer: 3
Explanation
Relevant access logs and identity records can help establish whether a particular employee account accessed a restricted file and when the activity occurred. The analyst should review timestamps, account identifiers, resource names, access outcomes, and available contextual information such as source devices or network addresses. Time synchronization and log integrity are important to support reliable correlation. An account’s activity does not automatically prove which individual operated it, so additional evidence may be necessary. Office temperature, marketing analytics, and printer inventory are not normally relevant to determining access to a protected file.
Question 55
A company wants to ensure that its critical security policies remain aligned with changes in technology, business operations, and regulatory obligations. Which governance activity should it perform?
- Periodic policy review and formal approval
- Permanently freeze all policies
- Remove policy ownership
- Allow undocumented policy changes
Correct Answer: 1
Explanation
Periodic policy review and formal approval help ensure that security requirements remain relevant as the organization, technology environment, and external obligations evolve. Policy owners should assess whether existing rules address current risks, operational practices, and applicable requirements. Changes should follow an established review and approval process, with version control, communication, and employee acknowledgment where appropriate. Permanently freezing policies can leave outdated requirements in place, while removing ownership or allowing undocumented changes weakens accountability. Governance should also establish review intervals and triggers for earlier reassessment after significant incidents, business changes, or regulatory developments.
Question 56
A security team needs to verify that a system’s clock is accurate so that events from different security tools can be correlated reliably. Which service is commonly used for time synchronization?
- FTP
- NTP
- SMTP
- SNMP
Correct Answer: 2
Explanation
Network Time Protocol is commonly used to synchronize system clocks with reliable time sources. Accurate and consistent timestamps are important when correlating authentication events, endpoint alerts, firewall records, application logs, and incident timelines. Significant clock differences can make it difficult to reconstruct event sequences or determine the relationship between activities across systems. Organizations should configure trusted time sources, monitor synchronization status, and protect time services from unauthorized manipulation. FTP transfers files, SMTP transports email, and SNMP supports network management. Although these protocols may be present in an environment, they do not serve as the standard general-purpose time synchronization protocol.
Question 57
A company is evaluating a third-party provider that will process confidential customer information. Which activity should be completed before granting the provider access?
- Share production credentials immediately
- Disable contractual security requirements
- Conduct a third-party security risk assessment
- Permit unrestricted data use
Correct Answer: 3
Explanation
A third-party security risk assessment helps evaluate the provider’s security practices, access controls, data handling, incident response, resilience, and relevant compliance obligations before confidential information is shared. The assessment should be proportionate to the sensitivity of the data and the provider’s role. Contractual requirements, defined responsibilities, access limitations, breach notification expectations, and ongoing oversight can help manage residual risk. Granting immediate unrestricted access or disabling security requirements exposes the organization to unnecessary risk. The provider’s assurances should be evaluated alongside appropriate evidence, and the relationship should be reviewed when services or risks materially change.
Question 58
A security administrator needs to prevent unauthorized users from reading confidential information transmitted through a public wireless network. Which combination provides direct protection for the communication?
- Strong encryption and authenticated secure connections
- Publicly sharing the network password
- Disabling certificate validation
- Sending sensitive information in plain text
Correct Answer: 1
Explanation
Strong encryption and authenticated secure connections help protect confidential information transmitted over public wireless networks. Properly configured secure protocols protect data in transit, while certificate validation helps users and applications verify that they are communicating with the intended service. A secure remote-access solution may provide an additional protected tunnel where required by organizational policy. Publicly sharing passwords, disabling certificate validation, or transmitting sensitive information in plain text weakens protection and may expose data to interception or manipulation. Users should also be trained to recognize suspicious connection prompts and follow approved procedures when accessing corporate resources remotely.
Question 59
A company wants to determine whether its security controls are reducing the risk of unauthorized access over time. Which approach provides useful evidence?
- Review only the organization’s logo
- Stop collecting access records
- Rely solely on informal opinions
- Monitor access-control metrics, review incidents, and reassess effectiveness
Correct Answer: 4
Explanation
Monitoring access-control metrics, reviewing incidents, and reassessing effectiveness provides evidence about whether security controls are achieving their intended purpose. Useful measures may include unauthorized access attempts, privileged access exceptions, stale accounts, access review completion, and remediation of identified deficiencies. Metrics should be interpreted in context because a change in alert volume may reflect altered detection or reporting rather than a direct change in risk. Incident findings and periodic assessments can reveal control gaps that metrics alone may miss. Informal opinions and the absence of records cannot provide a reliable basis for evaluating access-control performance over time.
Question 60
A security team has identified a critical vulnerability on an internet-facing server, but an immediate patch could disrupt an essential service. What should the team do?
- Ignore the vulnerability indefinitely
- Assess the risk, apply suitable compensating controls, and plan validated remediation
- Publish the vulnerability details without authorization
- Disable all security monitoring
Correct Answer: 2
Explanation
The team should assess the vulnerability’s severity, exposure, exploitability, and business impact, then select an appropriate treatment plan. If immediate patching could disrupt an essential service, compensating controls such as restricting network access, disabling vulnerable functionality, or increasing monitoring may reduce exposure while remediation is prepared. The organization should establish ownership, a target remediation timeframe, and appropriate approval for any exception. The patch should be tested and deployed as soon as feasible, followed by verification. Ignoring the vulnerability or disabling monitoring leaves the organization exposed without a documented, risk-informed response.