View Full ISC SSCP Exam Dumps and Practice Test Dumps.
Question 161
Which security principle requires an information system to remain usable by authorized users when needed?
- Confidentiality
- Integrity
- Availability
- Nonrepudiation
Correct Answer: 3
Explanation
Availability ensures that authorized users can access systems, applications, and information when required for legitimate business activities. Organizations support availability through redundancy, fault tolerance, capacity planning, maintenance, recovery procedures, and resilient infrastructure. Availability must be balanced with confidentiality and integrity because excessive restrictions or poorly designed controls can prevent legitimate access. A system can maintain confidentiality and integrity while still failing its users if it becomes unavailable. Security professionals should identify availability requirements during risk and business analysis activities and implement controls appropriate to the operational importance of the affected systems and services.
Question 162
A company needs to prevent sensitive information from being exposed through screenshots taken on managed mobile devices. Which control can address this requirement?
- Disable screen-capture functionality through device management
- Increase wireless transmission power
- Enable unrestricted application installation
- Disable device authentication
Correct Answer: 1
Explanation
Mobile device management can enforce security restrictions such as preventing screenshots in applications that handle sensitive information. The control can help reduce accidental or intentional capture of confidential data and may be combined with application-level protections, encryption, authentication, and data classification. Organizations should identify which applications and information require stronger restrictions because disabling screenshots everywhere may affect legitimate business processes. Increasing wireless power or allowing unrestricted application installation does not protect displayed information. Disabling authentication weakens device security. Mobile controls should be centrally managed, monitored, and periodically reviewed against organizational requirements.
Question 163
An organization wants to make security requirements enforceable when purchasing services from an external provider. Where should those requirements be documented?
- Informal conversation
- Service agreement or contract
- Employee lunch schedule
- Internal social media post
Correct Answer: 2
Explanation
Security requirements for an external provider should be documented in an appropriate service agreement or contract so that responsibilities and expectations are clearly established. Depending on the service, requirements may address data protection, access control, incident notification, audit rights, retention, regulatory obligations, subcontractors, and termination procedures. Documenting requirements formally provides a basis for evaluating provider performance and managing disputes. Informal conversations or internal social media posts do not provide the same level of enforceability or accountability. Contracts should be reviewed before services begin and updated when material changes to the relationship, services, or security requirements occur.
Question 164
A security analyst discovers that a critical application is using a certificate signed by an unknown authority. What should the analyst verify first?
- Whether the certificate chain leads to a trusted authority
- Whether the application has a larger database
- Whether users prefer the application interface
- Whether the server has additional printers
Correct Answer: 1
Explanation
The analyst should first verify whether the certificate chain leads to a trusted certificate authority recognized by the organization or applicable trust store. Certificate validation also involves checking the certificate’s validity period, hostname, signature, revocation status where applicable, and intended usage. An unknown authority may indicate a legitimate private certificate authority that has not been properly distributed, or it may indicate an unauthorized certificate. The analyst should investigate before assuming compromise. Application size, user interface preferences, and unrelated hardware do not establish whether the certificate can be trusted.
Question 165
Which physical security measure can help detect unauthorized movement of equipment through a controlled exit?
- Asset tagging and exit inspection procedures
- Disabling inventory records
- Publishing equipment locations
- Removing visitor controls
Correct Answer: 1
Explanation
Asset tagging combined with exit inspection procedures can help organizations identify equipment being moved without authorization. Tags provide a means of associating physical assets with inventory records, while inspection procedures can require verification before equipment leaves controlled areas. Organizations may supplement these measures with security personnel, electronic monitoring, locked storage, and documented equipment-transfer procedures. Disabling inventory records removes accountability, while publishing asset locations can expose useful information to unauthorized individuals. Removing visitor controls weakens physical security. Physical asset protection should be based on the sensitivity and value of equipment and information involved.
Question 166
A security team is investigating repeated failed access attempts against a privileged account. Which additional information would provide useful context?
- Source addresses, timestamps, and authentication methods
- Office furniture inventory
- Employee meal preferences
- Printer paper consumption
Correct Answer: 1
Explanation
Source addresses, timestamps, and authentication methods can help investigators understand the circumstances surrounding repeated failed attempts against a privileged account. Correlating these details may reveal whether attempts originated from an expected administrative location, an unfamiliar system, or multiple sources. Investigators should also consider successful logins, account lockouts, related alerts, and legitimate maintenance activities. A pattern of failures does not automatically prove an attack because configuration errors or forgotten credentials can produce similar events. Unrelated business information such as furniture, meals, or printer consumption generally provides no meaningful authentication context.
Question 167
A company is classifying information before selecting protection controls. Which characteristic should primarily determine the classification level?
- Potential impact if the information is improperly disclosed, altered, or unavailable
- File name length
- Number of pages in the document
- Employee preference for document format
Correct Answer: 1
Explanation
Information classification should reflect the potential business, legal, regulatory, operational, or security impact associated with unauthorized disclosure, alteration, destruction, or loss of availability. Classification helps organizations apply protection requirements proportionate to the sensitivity and value of information. Highly sensitive data may require stronger access controls, encryption, monitoring, retention restrictions, and handling procedures. File length or document formatting does not determine sensitivity. Classification criteria should be formally defined, consistently applied, and periodically reviewed because the value or sensitivity of information can change as business circumstances evolve.
Question 168
An organization needs to ensure that only approved software can execute on high-security workstations. Which technology is designed for this purpose?
- Application allowlisting
- Open guest access
- Network broadcasting
- Public file sharing
Correct Answer: 1
Explanation
Application allowlisting permits execution only for software that has been explicitly approved according to organizational policy. This can reduce the risk of unauthorized programs, malware, and unapproved utilities executing on high-security workstations. Effective allowlisting requires maintaining trusted application rules and managing legitimate updates so that required software continues to function. Organizations should also consider administrative bypass mechanisms because users with excessive privileges may otherwise circumvent restrictions. Guest access, network broadcasting, and public file sharing do not provide application execution control. Allowlisting is particularly useful where the software environment is stable and well managed.
Question 169
A security administrator wants to identify whether a firewall rule permits traffic that is no longer required by any application. Which activity should be performed?
- Review firewall rules against current traffic and documented requirements
- Delete all firewall rules
- Permit every network service
- Disable firewall logging
Correct Answer: 1
Explanation
Reviewing firewall rules against current traffic patterns and documented application requirements can identify rules that are obsolete, overly broad, or unused. Security teams should understand legitimate dependencies before removing or modifying a rule because an apparently inactive rule may support an infrequent but important process. Rule reviews should examine source, destination, service, business owner, justification, and recent usage where available. Deleting all rules would disrupt legitimate communication and weaken security, while permitting every service increases exposure. Disabling logging also removes valuable evidence for understanding network activity and validating firewall behavior.
Question 170
Which approach helps ensure that employees receive only the security training required for their responsibilities?
- Role-based security awareness and training
- Identical training without regard to duties
- No training for technical staff
- Optional training with no tracking
Correct Answer: 1
Explanation
Role-based security training aligns learning requirements with the responsibilities and risks associated with different job functions. General employees may need awareness of phishing, password security, data handling, and reporting procedures, while administrators may require additional instruction on privileged access, secure configuration, and incident handling. Specialized roles may require further training based on regulatory or operational requirements. Applying identical training to every employee can leave important role-specific risks unaddressed. Organizations should track completion, assess understanding where appropriate, and update training when threats, technologies, or responsibilities change.
Question 171
A company wants to protect backup data from ransomware that could encrypt connected backup repositories. Which architecture provides stronger separation?
- Isolated or offline backup copies
- Permanently writable shared storage
- Shared administrator credentials
- Backups connected without access restrictions
Correct Answer: 1
Explanation
Isolated or offline backup copies can provide stronger protection against ransomware because they reduce the ability of a compromised production environment to directly access and alter those backups. Depending on business requirements, organizations may use offline media, logically isolated repositories, immutable storage, or separate administrative credentials. Backup protection should include encryption, access controls, monitoring, retention, and regular restoration testing. Permanently writable shared repositories may be reachable by compromised accounts or systems. Strong separation does not eliminate ransomware risk, but it can preserve recovery options when production systems and connected backups are affected.
Question 172
A security professional needs to determine whether a workstation’s wireless connection uses an approved corporate network. Which information is most useful?
- Wireless network identifier and authentication details
- Monitor screen size
- Keyboard layout
- Printer manufacturer
Correct Answer: 1
Explanation
The wireless network identifier and authentication details can help determine whether a workstation is connected to an approved corporate network. Security personnel can compare the network identifier, authentication method, encryption configuration, access point information, and related network telemetry with approved wireless standards. An unauthorized or improperly secured wireless connection may expose corporate traffic or provide an alternative path into protected resources. Physical workstation characteristics such as monitor size or keyboard layout do not establish network trust. Wireless configurations should be centrally managed where possible and monitored for unauthorized access points and connection attempts.
Question 173
A security team wants to make sure that a critical system continues operating if one storage device fails. Which design provides this capability?
- Redundant storage configuration
- Single unprotected disk
- Manual file copying once a year
- Disabled backup procedures
Correct Answer: 1
Explanation
A redundant storage configuration can allow a system to continue operating when an individual storage device fails, depending on the specific implementation and failure scenario. Redundant arrays and other storage technologies can provide fault tolerance by maintaining data across multiple devices or maintaining recovery information. However, redundancy is not a replacement for independent backups because certain failures, malware, or user actions can affect multiple copies. Organizations should select storage resilience according to availability requirements and test failure recovery procedures. A single disk and infrequent manual copying provide limited protection against hardware failure and data loss.
Question 174
An organization wants to prevent employees from installing unauthorized browser extensions on managed endpoints. Which control can address this requirement?
- Endpoint configuration policy restricting extension installation
- Public administrator credentials
- Unrestricted software installation
- Disabled endpoint management
Correct Answer: 1
Explanation
An endpoint configuration policy can restrict browser extension installation to approved extensions or block installation entirely on managed systems. This reduces the risk that employees introduce extensions capable of collecting sensitive information, modifying browser behavior, or communicating with untrusted services. Organizations should maintain an approved extension list where business requirements justify specific extensions and periodically review their security. Public administrator credentials and unrestricted installation undermine endpoint controls, while disabling endpoint management removes centralized enforcement. Policies should be tested to ensure legitimate business functions continue while unauthorized browser modifications remain restricted.
Question 175
A security manager needs evidence that employees acknowledged an updated security policy. Which record is most appropriate?
- Policy acknowledgment records
- Network bandwidth statistics
- Hardware purchase orders
- Building maintenance logs
Correct Answer: 1
Explanation
Policy acknowledgment records provide evidence that employees were presented with an updated policy and completed the organization’s required acknowledgment process. Depending on the implementation, records may include the employee identity, policy version, acknowledgment date, and applicable training information. Such records can support compliance monitoring and demonstrate that policy communication processes were performed. Organizations should protect these records from unauthorized modification and retain them according to applicable requirements. Network statistics, purchase orders, and building maintenance logs do not establish whether employees received and acknowledged the updated security policy.
Question 176
A security analyst identifies a suspicious process running on an endpoint. Before terminating it, what consideration is particularly important during an investigation?
- Preserve relevant evidence when feasible
- Immediately delete all related files
- Reinstall the operating system without documentation
- Disable every security control
Correct Answer: 1
Explanation
Preserving relevant evidence before taking disruptive actions can help investigators understand what occurred and maintain useful forensic information. Depending on the incident, evidence may include running-process details, network connections, memory contents, files, timestamps, and associated logs. Investigators must balance evidence preservation with containment requirements because a malicious process may continue causing harm. Actions should follow established incident procedures and be documented. Immediately deleting files or reinstalling systems without preserving evidence can eliminate information needed to determine scope and cause. Security controls should not be disabled without a justified investigative or operational reason.
Question 177
A company wants to ensure that sensitive records are retained only for the period required by business and legal requirements. Which practice supports this objective?
- Defined retention and secure disposal schedules
- Permanent retention of every record
- Uncontrolled employee deletion
- No classification of stored information
Correct Answer: 1
Explanation
Defined retention and secure disposal schedules establish how long information should be retained and how it should be securely destroyed when the applicable retention period expires. Retention requirements may depend on legal obligations, contractual commitments, business needs, litigation holds, and the sensitivity of the information. Keeping every record indefinitely can increase storage costs, privacy exposure, and the impact of a potential compromise. Uncontrolled deletion can violate requirements or destroy useful evidence. Effective retention programs should identify record owners, define applicable periods, apply legal holds where necessary, and verify disposal processes.
Question 178
A security administrator wants to detect unauthorized changes to important system files. Which capability is designed for this purpose?
- File integrity monitoring
- Screen brightness control
- Printer queue management
- Desktop wallpaper synchronization
Correct Answer: 1
Explanation
File integrity monitoring can detect changes to selected files, directories, permissions, or other monitored attributes. Baselines can be established for important system components, and subsequent changes can generate alerts for investigation. This capability can help identify unauthorized modification, malware activity, configuration changes, or administrative actions that were not properly documented. Monitoring should be tuned to reduce unnecessary alerts and should distinguish approved changes from unexpected activity. Screen brightness, printer management, and wallpaper synchronization do not provide meaningful mechanisms for identifying unauthorized modifications to critical system files.
Question 179
A company wants to ensure that a security control continues operating correctly after an infrastructure upgrade. Which activity should be performed?
- Post-implementation control validation
- Permanent removal of monitoring
- Automatic acceptance without testing
- Deletion of previous test results
Correct Answer: 1
Explanation
Post-implementation control validation determines whether a security control continues to meet its intended objective after an infrastructure change. An upgrade can alter system behavior, dependencies, permissions, configurations, or integrations and may unintentionally weaken an existing control. Validation should use appropriate test procedures and compare results with defined security requirements. Any deficiencies should be documented and addressed through the organization’s change and risk processes. Automatically assuming that controls remain effective can allow unnoticed weaknesses to persist. Previous test results should be retained where appropriate because they provide useful historical evidence and comparison points.
Question 180
A security team wants to determine whether an organization can restore critical operations after a major facility outage. Which exercise is most appropriate?
- Business continuity or disaster recovery exercise
- Password complexity review
- Software inventory scan
- Routine vulnerability scan
Correct Answer: 1
Explanation
A business continuity or disaster recovery exercise evaluates whether the organization can maintain or restore critical operations after a disruptive event such as a facility outage. Exercises can test communication procedures, alternate facilities, backup availability, system restoration, personnel responsibilities, and recovery priorities. Results should be documented and used to improve plans, procedures, and technical capabilities. A password review or vulnerability scan addresses different security objectives and does not demonstrate operational recovery capability. Organizations should conduct exercises at appropriate intervals and include relevant personnel, dependencies, and recovery requirements to identify weaknesses before a real disruption occurs.