ISC SSCP Practice Test Questions and Exam Dumps Part4 Q61-80

View Full ISC SSCP Exam Dumps and Practice Test Dumps.

 

Question 61

An organization wants to ensure that employees receive only the network services required for their assigned responsibilities. Which principle should guide this design?

  1. Need to know
  2. Open access
  3. Maximum availability
  4. Universal administration

Correct Answer: 1

Explanation

The need-to-know principle limits access to information and services based on what an individual requires to perform assigned responsibilities. Applying this principle can reduce unnecessary exposure if an account is compromised or misused. Administrators should define access requirements according to job duties and review them as responsibilities change. Need-to-know is related to, but distinct from, least privilege because it focuses particularly on access to information or resources necessary for a specific task. Providing universal access increases the potential impact of compromised credentials and makes unauthorized activity more difficult to control.

Question 62

A security administrator discovers that several systems contain unnecessary services listening on network ports. What action would most directly reduce the attack surface?

  1. Increase disk capacity
  2. Disable or remove unnecessary services
  3. Increase screen timeout values
  4. Add more user accounts

Correct Answer: 2

Explanation

Disabling or removing unnecessary services reduces the number of active components that attackers can potentially target. Every unnecessary service may introduce vulnerabilities, expose network ports, or provide an additional path into a system. Administrators should first determine whether each service has a legitimate business requirement before disabling it. Approved configuration baselines can help identify expected services and detect deviations. Changes should be documented and tested so that required functionality is not unintentionally disrupted. Increasing storage, changing screen timeouts, or creating additional accounts does not directly reduce the network attack surface created by unnecessary services.

Question 63

An organization wants to ensure that employees can access only the files appropriate for their department after moving to a new file-sharing platform. What should administrators establish?

  1. A universal shared account
  2. Department-based authorization rules
  3. Anonymous access for convenience
  4. Identical permissions for every employee

Correct Answer: 2

Explanation

Department-based authorization rules can restrict access to files according to organizational responsibilities and approved business requirements. Administrators should map groups or roles to appropriate resources and avoid granting broader permissions than necessary. Access should be tested using representative accounts to confirm that authorized users can perform required tasks while unauthorized users are denied. Shared or anonymous accounts make accountability and access control more difficult, while identical permissions expose information unnecessarily. The organization should also review group membership periodically and promptly update permissions when employees transfer departments or change responsibilities.

Question 64

A security engineer is designing a server room and wants to reduce unauthorized physical entry. Which control provides the strongest direct barrier?

  1. Visitor log alone
  2. Security awareness posters
  3. Locked access-controlled doors
  4. Network traffic monitoring

Correct Answer: 3

Explanation

Locked access-controlled doors provide a direct physical barrier against unauthorized entry into a server room. Depending on the facility’s risk profile, access may use badges, biometric verification, security personnel, or multiple controls. Physical access should be granted only to authorized personnel, and access records should be reviewed when appropriate. Visitor procedures can supplement physical barriers by requiring identification, authorization, and escorting. Awareness posters and network monitoring do not physically prevent someone from entering the room. Effective physical security should also consider environmental hazards, emergency exits, surveillance, and protection of critical equipment from tampering.

Question 65

A company is creating a process for handling security incidents. Which classification factor is most useful when determining the urgency of an incident?

  1. Office furniture cost
  2. Number of available meeting rooms
  3. Potential business impact and severity
  4. Employee commute distance

Correct Answer: 3

Explanation

Potential business impact and severity are important factors when determining incident urgency and escalation requirements. An event affecting a critical production service, sensitive information, or essential business function may require faster response than a low-impact event. Organizations should define incident categories and escalation thresholds before incidents occur so analysts can respond consistently. Classification may consider affected assets, data sensitivity, scope, persistence, and operational consequences. Personal preferences or unrelated office characteristics should not determine priority. Clear classification criteria help security teams allocate resources appropriately and ensure significant incidents receive timely attention from responsible stakeholders.

Question 66

A company wants to make sure that security requirements are considered before acquiring a new cloud service. Which document should define the expected security obligations?

  1. Security requirements specification
  2. Employee lunch schedule
  3. Office maintenance plan
  4. Marketing brochure

Correct Answer: 1

Explanation

A security requirements specification documents the security expectations that a proposed cloud service must satisfy. Requirements may address authentication, authorization, encryption, logging, data protection, incident notification, availability, privacy, and regulatory obligations. Establishing requirements before acquisition allows the organization to evaluate providers consistently and identify gaps before committing sensitive information or workloads. Contractual terms can later translate appropriate requirements into enforceable obligations. Operational schedules and marketing materials do not establish measurable security expectations. Security requirements should reflect the organization’s risk assessment and the sensitivity of the services and information involved.

Question 67

A security administrator needs to ensure that a backup cannot be altered or deleted by ransomware affecting production systems. Which design provides stronger protection?

  1. Store the only backup on the production server
  2. Maintain isolated or immutable backup copies
  3. Allow every employee to modify backups
  4. Disable backup verification

Correct Answer: 2

Explanation

Isolated or immutable backup copies can help protect recovery data from ransomware and other attacks that compromise production environments. Isolation separates backup infrastructure or credentials from ordinary production access, while immutability can prevent unauthorized modification or deletion for a defined retention period. Organizations should also protect backup management interfaces, use appropriate authentication, monitor administrative activity, and regularly test restoration procedures. Keeping the only backup on a production server exposes it to the same compromise. Broad employee access and disabled verification weaken backup integrity and make it more difficult to determine whether recovery data can be trusted.

Question 68

A security analyst wants to determine whether an employee’s account is being used from two geographically distant locations within an unrealistic period. Which technique is useful?

  1. Data compression
  2. File deduplication
  3. Impossible-travel detection
  4. Disk defragmentation

Correct Answer: 3

Explanation

Impossible-travel detection identifies authentication activity that appears geographically inconsistent with the time between events. For example, an account logging in from distant locations within a period too short for realistic travel may indicate credential compromise, VPN usage, proxy services, or inaccurate location data. Such detections should be investigated rather than automatically treated as confirmed malicious activity because legitimate technical explanations can exist. Security teams can correlate authentication timestamps, source addresses, device information, and other context to determine whether additional action is necessary. Compression, deduplication, and disk defragmentation do not analyze geographic authentication behavior.

Question 69

A company wants to ensure that sensitive data stored on employee laptops remains protected if a device is lost. Which capability is most appropriate?

  1. Full-device encryption with secure key management
  2. Larger desktop monitors
  3. Public file sharing
  4. Disabling device authentication

Correct Answer: 1

Explanation

Full-device encryption protects data stored on a laptop by encrypting the contents of the storage device. If a properly configured encrypted device is lost or stolen, unauthorized individuals may be unable to read the stored information without the necessary authentication or cryptographic keys. Organizations should manage encryption keys securely, enforce appropriate device authentication, monitor encryption status, and establish recovery procedures. Encryption does not protect information after an authorized user unlocks the system, so additional endpoint and access controls remain necessary. Larger monitors, public sharing, and disabled authentication do not provide meaningful protection for lost-device data.

Question 70

An organization is establishing requirements for retaining security logs. Which factor should primarily determine how long important logs are retained?

  1. Monitor size
  2. Employee seniority
  3. Applicable requirements, business needs, and investigative value
  4. Number of office printers

Correct Answer: 3

Explanation

Log retention periods should be based on applicable legal or regulatory requirements, organizational policies, business needs, storage considerations, and the value of logs for security investigations. Some records may need longer retention because they support incident investigation, regulatory obligations, or forensic analysis. Retention policies should define what information is preserved, how it is protected, and when it is securely disposed of. Keeping logs indefinitely may create unnecessary storage and privacy concerns, while deleting them too quickly can eliminate useful evidence. Unrelated factors such as monitor size or employee seniority should not determine retention requirements.

Question 71

A security team wants to identify whether a newly deployed endpoint has been configured according to approved hardening standards. What should the team perform?

  1. Configuration compliance assessment
  2. Employee satisfaction survey
  3. Marketing review
  4. Printer capacity test

Correct Answer: 1

Explanation

A configuration compliance assessment compares a system’s actual settings against approved security requirements or hardening standards. The assessment may examine services, permissions, authentication settings, firewall configuration, logging, software versions, and other controls relevant to the endpoint. Identified deviations should be evaluated to determine whether they represent security risks or approved exceptions. Automated configuration assessment tools can help organizations evaluate large numbers of systems consistently. However, findings should still be reviewed in context because some deviations may be required for legitimate business functions. Employee surveys and printer tests do not assess endpoint security configuration.

Question 72

A company wants to ensure that a security exception granted to a business unit does not remain indefinitely. Which practice is most appropriate?

  1. Remove all exception documentation
  2. Assign an expiration date and periodic review
  3. Make the exception permanent automatically
  4. Allow employees to modify the exception

Correct Answer: 2

Explanation

Security exceptions should have documented justification, appropriate approval, defined scope, an owner, and an expiration or review date. Periodic review ensures that temporary deviations do not become permanent weaknesses simply because nobody revisits them. The organization should reassess whether the original business need still exists and whether a safer alternative is now available. Exceptions should also identify compensating controls where appropriate. Automatically making exceptions permanent removes important governance safeguards, while allowing employees to modify approved exceptions without oversight weakens accountability. Proper exception management helps balance business requirements with established security standards.

Question 73

A company uses a centralized certificate authority to issue certificates for internal services. What is an important responsibility of certificate lifecycle management?

  1. Tracking issuance, renewal, revocation, and expiration
  2. Increasing monitor resolution
  3. Removing certificate ownership records
  4. Sharing private keys publicly

Correct Answer: 1

Explanation

Certificate lifecycle management includes controlling certificate issuance, deployment, renewal, revocation, and expiration. Organizations need accurate records so administrators can identify which certificates belong to which services and replace them before expiration causes service disruption. Private keys must be protected because unauthorized disclosure can undermine the trust provided by certificates. Revocation procedures should be available when keys are compromised or certificates should no longer be trusted. Centralized management can improve visibility and consistency, but it must itself be secured. Monitor resolution and public key disclosure do not replace proper certificate lifecycle processes.

Question 74

A security administrator is reviewing an employee’s access after a role change. The employee still has permissions associated with the previous position. What should happen?

  1. Retain all previous permissions indefinitely
  2. Create another shared account
  3. Remove or modify permissions no longer required
  4. Disable all organizational access permanently

Correct Answer: 3

Explanation

When an employee changes roles, permissions that are no longer required should be removed or adjusted according to the employee’s new responsibilities. This process helps prevent privilege accumulation, where users retain access from previous positions and gradually acquire excessive permissions. Organizations should use role definitions, approval workflows, and periodic access reviews to identify inappropriate access. Removing every form of access would unnecessarily disrupt legitimate work, while retaining old permissions indefinitely increases exposure. Shared accounts also reduce accountability. Role changes should trigger timely access updates and, where appropriate, confirmation from the employee’s manager or resource owner.

Question 75

A company wants to prevent unauthorized modification of firmware on critical devices. Which control would provide relevant protection?

  1. Disable all device monitoring
  2. Use secure boot and firmware integrity mechanisms
  3. Publish administrator credentials
  4. Allow unrestricted firmware updates

Correct Answer: 2

Explanation

Secure boot and firmware integrity mechanisms can help ensure that devices start only trusted software components and that unauthorized firmware modifications are detected or prevented. These controls are particularly valuable for systems where compromise below the operating-system level could undermine conventional security tools. Organizations should also restrict firmware update privileges, protect signing keys, maintain supported firmware versions, and monitor relevant events. Allowing unrestricted firmware updates increases the possibility of unauthorized modification, while disabling monitoring removes useful visibility. Publishing administrator credentials would create an additional security weakness rather than protect device firmware.

Question 76

An organization wants to reduce the risk that a malicious website can exploit outdated browser components on employee endpoints. Which control is most directly applicable?

  1. Application and browser patch management
  2. Increasing email mailbox size
  3. Disabling endpoint logging
  4. Changing employee usernames

Correct Answer: 1

Explanation

Application and browser patch management helps reduce exposure to vulnerabilities in software used to access web content. Browsers and supporting components should be kept within approved supported versions, and security updates should be deployed through a controlled process. Organizations can supplement patching with application controls, web filtering, endpoint protection, and vulnerability monitoring. Patch management should include inventory, prioritization, testing, deployment, and verification rather than simply downloading updates. Increasing mailbox capacity or changing usernames does not address vulnerable browser components, while disabling endpoint logging reduces visibility into potentially exploited systems.

Question 77

A security team wants to determine whether a newly introduced control is operating as intended. Which activity provides direct evidence?

  1. Control effectiveness testing
  2. Office decoration review
  3. Employee parking analysis
  4. Marketing performance measurement

Correct Answer: 1

Explanation

Control effectiveness testing evaluates whether a security control is implemented correctly and operates as intended. Depending on the control, testing may involve reviewing configuration, examining records, observing procedures, performing technical validation, or sampling relevant transactions. Testing should have defined criteria and produce evidence that can support remediation when deficiencies are identified. A control that exists on paper but is not operating correctly may provide little practical protection. Business activities such as parking analysis or marketing measurement do not demonstrate whether a security control is functioning according to its intended requirements.

Question 78

A company is preparing an emergency communication process for a major cybersecurity disruption. Which requirement is most important?

  1. Rely exclusively on one unavailable communication channel
  2. Define alternative communication methods and responsible contacts
  3. Publish internal emergency credentials
  4. Avoid identifying decision-making responsibilities

Correct Answer: 2

Explanation

An emergency communication process should define responsible contacts, escalation paths, approved communication methods, and alternatives if primary systems are unavailable. During a major cybersecurity disruption, email, collaboration platforms, or internal directories may themselves be affected, so organizations should maintain suitable out-of-band communication options where necessary. Contact information should be kept current and protected from unauthorized disclosure. Roles should clearly identify who communicates with technical teams, leadership, employees, customers, regulators, or other stakeholders. Relying on a single potentially compromised channel or leaving responsibilities undefined can delay coordination and create confusion during a crisis.

Question 79

A security administrator is reviewing wireless access points and discovers that an old insecure wireless protocol is still enabled for compatibility. What should be considered first?

  1. Increase wireless transmit power without assessment
  2. Disable all network monitoring
  3. Assess affected devices and migrate to a stronger supported security protocol
  4. Publish the wireless credentials

Correct Answer: 3

Explanation

An organization should assess which devices depend on the outdated wireless protocol and develop a controlled migration to a stronger supported security protocol. Continuing to use an insecure protocol can expose wireless communications to attacks that stronger modern protections are designed to mitigate. The transition should account for business dependencies, device compatibility, authentication methods, configuration changes, and testing. Where immediate replacement is impossible, compensating controls may reduce exposure temporarily. Increasing signal power does not improve protocol security, while publishing credentials or disabling monitoring can create additional risks rather than address the underlying weakness.

Question 80

A company wants to verify that employees understand how to report suspected security incidents. Which method provides practical evidence of awareness?

  1. Remove all reporting instructions
  2. Conduct a controlled awareness exercise and measure reporting behavior
  3. Disable the reporting channel
  4. Assume employees understand without evaluation

Correct Answer: 2

Explanation

A controlled awareness exercise can provide practical evidence of whether employees recognize suspicious activity and know how to report it. Organizations can measure participation, reporting rates, response times, and common misunderstandings without exposing employees to unnecessary harm or revealing sensitive information. Results can identify areas where training or communication should be improved. Exercises should be designed carefully, with appropriate authorization and privacy considerations. Simply distributing instructions does not demonstrate that employees understand them, while removing reporting channels or assuming awareness without testing eliminates opportunities to identify gaps in organizational readiness.