View Full ISC SSCP Exam Dumps and Practice Test Dumps.
Question 81
A security administrator needs to protect a database account used by an application so that developers cannot directly retrieve its credentials. Which control is most appropriate?
- Shared spreadsheet containing passwords
- Publicly accessible configuration files
- Privileged credential vaulting
- Permanent password disclosure to developers
Correct Answer: 3
Explanation
Privileged credential vaulting provides centralized protection and controlled management of sensitive credentials used by applications and administrators. A secure vault can restrict who or what may retrieve credentials, record access activity, rotate secrets, and reduce the need to expose passwords directly to personnel. Application identities should receive only the permissions required for their functions. Storing credentials in spreadsheets or publicly accessible configuration files creates unnecessary exposure and makes credential management difficult. Proper vaulting should also include strong authentication, access monitoring, secure integration, and procedures for responding when credentials are suspected of being compromised.
Question 82
A company wants to identify security weaknesses before deploying a new web application to production. Which activity is most appropriate during the development process?
- Security testing before production release
- Removing application logs
- Granting developers unrestricted production access
- Disabling input validation
Correct Answer: 1
Explanation
Security testing before production release can identify vulnerabilities while they are still relatively easy to correct. Depending on the application, testing may include code review, dependency analysis, vulnerability scanning, security-focused functional testing, and controlled penetration testing. Integrating security activities into the development lifecycle helps identify weaknesses before they become production incidents. Developers should work with defined security requirements and controlled deployment procedures rather than receiving unrestricted production privileges. Removing logs or disabling input validation would reduce security visibility and protection. Findings should be documented, prioritized, remediated, and verified before release when appropriate.
Question 83
An organization wants to ensure that employees cannot install unauthorized software on corporate workstations. Which control would directly support this objective?
- Unrestricted local administrator rights
- Application allowlisting
- Public software repositories
- Disabled endpoint monitoring
Correct Answer: 2
Explanation
Application allowlisting permits only approved applications or software components to execute on managed systems. This can reduce the risk associated with unauthorized software, malicious programs, and unapproved tools. Allowlisting rules should be maintained carefully because legitimate applications may change versions or dependencies. Organizations should define an exception process for business-required software and monitor blocked execution attempts for suspicious patterns. Giving every employee local administrator privileges weakens control over software installation, while public repositories and disabled monitoring do not prevent unauthorized applications. Endpoint security should combine application controls with patching, malware protection, and appropriate user permissions.
Question 84
A security analyst receives an alert indicating that a privileged account has suddenly accessed a large number of sensitive files. What should the analyst do first?
- Delete the alert
- Ignore the activity because the account is privileged
- Immediately publish the account information
- Validate and investigate the activity according to incident procedures
Correct Answer: 4
Explanation
Unexpected activity involving a privileged account should be validated and investigated according to established incident procedures. The analyst should determine whether the access was authorized, examine relevant authentication and file-access records, identify the source device, and assess whether the behavior indicates compromise or misuse. Privileged accounts require particular attention because their actions can affect many resources. Analysts should preserve relevant evidence and escalate according to defined criteria. Deleting the alert or ignoring the activity removes important visibility, while publicly disclosing account information could create additional security and privacy concerns.
Question 85
A company wants to protect an encryption key used to secure highly sensitive information. Which practice is most appropriate?
- Store the key in a public document
- Share the key through ordinary email
- Use controlled key storage with restricted access
- Print the key and distribute copies widely
Correct Answer: 3
Explanation
Controlled key storage with restricted access helps protect cryptographic keys from unauthorized disclosure or modification. Organizations should establish key-management procedures covering generation, storage, distribution, rotation, backup, recovery, revocation, and destruction. Access to keys should be limited to authorized identities and protected through appropriate technical and administrative controls. Key material should not be placed in public documents or casually distributed through email. The protection of encrypted information depends heavily on protecting the associated keys, so organizations should also monitor key access and maintain procedures for responding to suspected compromise.
Question 86
A network administrator wants to prevent users from connecting directly to internal systems from an untrusted external network. Which architecture provides an appropriate controlled entry point?
- Direct unrestricted access
- Segmented remote-access gateway
- Public database exposure
- Shared administrator workstation
Correct Answer: 2
Explanation
A segmented remote-access gateway provides a controlled entry point between untrusted external networks and protected internal resources. Remote users can be authenticated and authorized before permitted traffic reaches internal systems. Additional controls may include multifactor authentication, device compliance checks, session monitoring, network segmentation, and restricted application access. Direct unrestricted access exposes internal systems unnecessarily, while publicly exposing databases creates significant risk. A shared administrator workstation also weakens accountability. Remote-access architecture should be designed according to business requirements and should limit users to the resources necessary for their approved activities.
Question 87
A security team discovers that several endpoints are running unsupported operating systems that no longer receive vendor security updates. What should be the preferred long-term treatment?
- Continue using them without controls
- Replace or upgrade them to supported platforms
- Disable all security software
- Connect them directly to the public internet
Correct Answer: 2
Explanation
Replacing or upgrading unsupported operating systems is the preferred long-term treatment because unsupported platforms may no longer receive security patches or vendor assistance. Continued use increases exposure to vulnerabilities that cannot be remediated through normal update processes. If immediate replacement is not possible, organizations may isolate affected systems, restrict access, increase monitoring, and document temporary risk acceptance or compensating controls. These measures do not eliminate the underlying lifecycle problem. Connecting unsupported systems directly to the internet or disabling security software would increase exposure. Asset lifecycle management should identify unsupported systems before they become significant security risks.
Question 88
A company needs to ensure that a user cannot approve their own request for elevated access. Which control should be implemented?
- Self-approval workflow
- Shared administrator account
- Independent approval workflow
- Anonymous access
Correct Answer: 3
Explanation
An independent approval workflow requires elevated-access requests to be reviewed and approved by an authorized person other than the requester. This helps reduce the risk of unauthorized privilege escalation and provides accountability for sensitive access decisions. The workflow should document the requester, requested permissions, business justification, approver, approval time, and duration where appropriate. Shared administrator accounts make individual accountability more difficult, while self-approval removes an important control over privilege assignment. Anonymous access is inappropriate for privileged authorization. Organizations should also periodically review approved elevated access to confirm that it remains necessary.
Question 89
A company is investigating a suspected malware infection and needs to preserve the affected system’s volatile information. Which evidence should be collected first when technically feasible?
- Volatile memory information
- Archived paper documents
- Old marketing brochures
- Office furniture inventory
Correct Answer: 1
Explanation
Volatile memory can contain information that disappears when a system is powered off or restarted. Depending on the investigation, memory may contain running processes, network connections, loaded modules, authentication material, and other transient information. When technically feasible and authorized, investigators should consider collecting volatile evidence before actions that could destroy it. Evidence collection should follow established procedures and preserve integrity and documentation. Investigators should balance evidence preservation with the need to contain an active threat. Paper documents, marketing materials, and furniture inventories are not normally the most time-sensitive evidence in a live malware investigation.
Question 90
An organization wants to ensure that security monitoring continues if one log collection server fails. Which design characteristic is most useful?
- Single point of failure
- Redundant monitoring infrastructure
- Unrestricted administrator sharing
- Disabled alerting
Correct Answer: 2
Explanation
Redundant monitoring infrastructure can maintain security visibility when an individual logging or monitoring component fails. Organizations may use multiple collectors, resilient storage, replicated services, or alternative forwarding paths depending on their architecture. Redundancy should be tested to confirm that failures are detected and that events continue reaching appropriate systems. A single monitoring server creates a potential single point of failure, while disabled alerting eliminates important detection capabilities. Shared administrative access can also weaken accountability. Monitoring resilience should be considered part of overall security architecture because loss of visibility during an incident can significantly complicate detection and investigation.
Question 91
A security administrator is reviewing an organization’s firewall rules and finds several rules that are no longer associated with any business requirement. What should the administrator do?
- Keep every rule permanently
- Remove or disable obsolete rules after validation
- Publish the firewall configuration
- Allow all traffic instead
Correct Answer: 2
Explanation
Obsolete firewall rules should be reviewed, validated, and removed or disabled when they no longer support an approved business requirement. Unnecessary rules can increase the attack surface, complicate troubleshooting, and make it harder to understand the effective security policy. Changes should follow the organization’s change-management process and be tested to ensure that required connectivity is not disrupted. Administrators should maintain documentation explaining important rules and their intended purpose. Keeping obsolete rules indefinitely increases complexity, while allowing all traffic removes meaningful network restrictions. Firewall rule reviews should occur periodically and after major architectural changes.
Question 92
A company wants to reduce the risk of data exposure when employees print confidential documents. Which control is particularly useful?
- Secure print release requiring user authentication
- Publicly accessible printers
- Automatic printing of every document
- Removal of printer access records
Correct Answer: 1
Explanation
Secure print release requires an authorized user to authenticate at the printer before a document is physically released. This reduces the likelihood that confidential documents will remain unattended in printer output trays. Depending on organizational requirements, additional controls may include printer access restrictions, encryption of print jobs, audit records, secure disposal of printed material, and policies limiting unnecessary printing. Publicly accessible printers and automatic printing can increase exposure, while removing printer access records reduces accountability. Physical security should be considered alongside technical controls because printed information remains exposed even when the originating digital system is well protected.
Question 93
A security team wants to identify unusual outbound network traffic from a workstation that normally communicates only with approved business services. Which approach is useful?
- Establish normal traffic patterns and investigate significant deviations
- Permit all outbound destinations permanently
- Disable network monitoring
- Delete historical traffic records
Correct Answer: 1
Explanation
Establishing normal network traffic patterns can help security teams identify significant deviations that may indicate malware, unauthorized applications, data exfiltration, or compromised accounts. Baselines should consider the workstation’s role, normal destinations, expected protocols, and business operating periods. Deviations should be investigated rather than automatically classified as malicious because legitimate software updates, travel, or new business services can change traffic patterns. Maintaining historical records supports comparison and investigation. Permitting unrestricted outbound traffic removes useful control, while disabling monitoring or deleting historical records eliminates valuable evidence needed to understand suspicious network behavior.
Question 94
A company needs to ensure that security responsibilities for a hosted application are clearly divided between the cloud provider and the customer. What should be documented?
- Shared responsibility assignments
- Employee holiday dates
- Office cleaning schedules
- Unrelated marketing objectives
Correct Answer: 1
Explanation
Shared responsibility assignments document which security responsibilities belong to the cloud provider and which remain with the customer. Depending on the service model, responsibilities may include infrastructure security, operating-system management, identity configuration, application security, data protection, and monitoring. Clearly documenting these responsibilities helps prevent security gaps caused by assumptions that another party is handling a control. Contracts and service agreements should reflect relevant responsibilities and reporting expectations. Business schedules and marketing objectives do not define cloud security ownership. Organizations should periodically reassess responsibility boundaries when services, architectures, or providers change.
Question 95
A security administrator notices repeated authentication failures followed by a successful login from an unfamiliar device. Which additional information would be most useful for investigation?
- Source address, device details, timestamps, and authentication context
- Employee cafeteria menu
- Office lighting schedule
- Printer paper consumption
Correct Answer: 1
Explanation
Source address, device details, timestamps, and authentication context can help determine whether the successful login was legitimate or potentially related to credential abuse. Analysts should compare the activity with the user’s normal behavior, approved devices, geographic context, authentication method, and other relevant security events. The repeated failures may indicate password guessing, user error, or another condition, so additional evidence is necessary before reaching a conclusion. Correlation with endpoint and network records can reveal whether the unfamiliar device has other suspicious activity. Unrelated operational information such as cafeteria menus or printer consumption does not assist meaningfully with authentication investigation.
Question 96
A company wants to make sure that critical security procedures remain usable during an emergency. Which activity provides the most practical validation?
- Ignore the procedures until an actual crisis
- Conduct periodic exercises and update procedures based on findings
- Store procedures without testing them
- Remove emergency contact information
Correct Answer: 2
Explanation
Periodic exercises provide practical validation that critical security procedures can be understood and performed under realistic conditions. Exercises can identify missing steps, unclear responsibilities, outdated contact information, unavailable resources, and dependencies that were not recognized during planning. Findings should be documented and used to improve procedures, training, and technical capabilities. Testing should be proportionate to the organization’s risk and should avoid unnecessary operational disruption. Simply storing procedures does not demonstrate usability, while waiting for an actual emergency creates avoidable uncertainty. Removing contact information would further reduce the organization’s ability to coordinate effectively.
Question 97
An organization wants to ensure that employees cannot reuse a recently compromised password when selecting a new one. Which authentication control addresses this requirement?
- Password history enforcement
- Screen resolution management
- Network load balancing
- File compression
Correct Answer: 1
Explanation
Password history enforcement prevents users from immediately reusing previously used passwords when changing credentials. This can reduce the risk that a compromised or previously exposed password will be selected again. Organizations should combine password policies with appropriate authentication protections, secure password storage, multifactor authentication, and monitoring for compromised credentials. Password history alone does not protect an account if an attacker already possesses the current valid credential. Screen resolution, load balancing, and file compression serve unrelated technical purposes. Authentication policies should also account for secure recovery processes so that password resets do not introduce weaker verification methods.
Question 98
A security manager wants to measure how quickly the organization responds after detecting security incidents. Which metric is most relevant?
- Mean time to respond
- Number of office chairs
- Storage device color
- Employee parking capacity
Correct Answer: 1
Explanation
Mean time to respond measures the average time taken to begin responding to identified security incidents. Tracking this metric can help organizations understand operational responsiveness and identify delays in escalation, investigation, containment, or coordination. The precise definition should be documented so that measurements remain consistent across reporting periods. Organizations may also track related metrics such as detection time, containment time, and remediation time. Metrics should be interpreted with context because incident complexity and severity can vary substantially. Unrelated measures such as office furniture or parking capacity provide no meaningful indication of incident response performance.
Question 99
A company discovers that an employee has connected an unauthorized personal cloud-storage account to a corporate workstation. What security concern should receive immediate attention?
- Potential unauthorized transfer of organizational data
- Increased monitor brightness
- Reduced keyboard noise
- Printer maintenance frequency
Correct Answer: 1
Explanation
An unauthorized personal cloud-storage account can create a pathway for organizational information to leave approved corporate systems. The security team should determine what data was accessible or transferred, identify applicable policies, preserve relevant evidence, and take appropriate containment action. Depending on the environment, controls such as endpoint management, cloud access security policies, data loss prevention, and application restrictions can reduce similar risks. The investigation should distinguish between policy violations and confirmed data exposure. Unrelated hardware or office conditions do not address the central security concern, which is potential unauthorized movement or storage of organizational information.
Question 100
An organization is reviewing its security program after a significant incident. Which activity can help identify improvements to prevent similar issues?
- Ignore the incident after systems are restored
- Conduct a lessons-learned review
- Delete incident documentation
- Prohibit discussion of response activities
Correct Answer: 2
Explanation
A lessons-learned review examines what occurred, how the organization responded, which controls worked, and where improvements are needed. The review should identify contributing conditions, communication problems, procedural weaknesses, technology gaps, and opportunities to strengthen preventive and response capabilities. Findings should result in assigned actions with appropriate owners and timelines. The purpose is improvement rather than assigning blame, and sensitive information should be handled according to organizational requirements. Ignoring the incident or deleting documentation prevents the organization from learning from experience. Effective lessons-learned activities can strengthen policies, controls, training, monitoring, and incident response procedures.