{"id":24910,"date":"2026-09-30T09:26:13","date_gmt":"2026-09-30T09:26:13","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=24910"},"modified":"2026-09-30T09:26:13","modified_gmt":"2026-09-30T09:26:13","slug":"isc-sscp-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-sscp-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"ISC SSCP Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sscp-exam-dumps\"><b>ISC SSCP Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 141<\/b><\/h3>\n<p><b>A security administrator needs to ensure that an administrator cannot modify audit records after performing a sensitive action. Which control is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store audit records in a separately controlled system<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Give administrators unrestricted log permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow users to edit their own audit records<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable audit collection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Storing audit records in a separately controlled system can reduce the ability of administrators on a monitored system to alter evidence of their own activities. Centralized logging, restricted write permissions, protected storage, and appropriate monitoring can help preserve the integrity of audit records. Organizations should define who can access logs and under what circumstances, while maintaining reliable timestamps and retention requirements. Allowing users or administrators to modify their own audit records undermines accountability. Disabling logging removes valuable evidence. Separating log management from the systems being monitored provides an additional layer of protection against unauthorized alteration.<\/span><\/p>\n<h3><b>Question 142<\/b><\/h3>\n<p><b>A company is designing a security architecture for internet-facing applications. Which component can provide a controlled intermediary between external clients and internal application servers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy or application gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee workstation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup tape<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A proxy or application gateway can act as an intermediary between external clients and protected application servers. It can enforce security policies, inspect requests, restrict allowed methods, terminate secure connections, and provide additional monitoring before traffic reaches internal systems. Depending on the architecture, such gateways may also support authentication, rate limiting, and application-layer filtering. Directly exposing internal application servers can increase their attack surface. A database server, workstation, or backup tape does not provide the same intermediary security function. The gateway should itself be hardened, monitored, and maintained according to organizational security requirements.<\/span><\/p>\n<h3><b>Question 143<\/b><\/h3>\n<p><b>An organization wants to ensure that employees cannot use unauthorized DNS servers that may redirect corporate traffic to malicious destinations. Which control can help enforce this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable all endpoint authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permit arbitrary DNS configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enforce approved DNS resolver settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove network monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Enforcing approved DNS resolver settings can help ensure that corporate devices use trusted services for name resolution. Organizations may configure managed endpoints to use approved internal or security-enabled resolvers and restrict unauthorized changes through endpoint management policies. Monitoring DNS activity can further help identify suspicious domains, tunneling, or attempts to bypass approved resolvers. Allowing arbitrary DNS configuration can expose users to malicious or manipulated responses. Disabling authentication or removing network monitoring does not address DNS trust. DNS security should be considered alongside endpoint controls, network filtering, and appropriate threat detection capabilities.<\/span><\/p>\n<h3><b>Question 144<\/b><\/h3>\n<p><b>A security team needs to determine whether a suspicious executable was altered after it was collected for analysis. Which technique is useful?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compare cryptographic hash values<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rename the executable<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compress the executable<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Change its file extension<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Comparing cryptographic hash values can help determine whether an executable&#8217;s contents have changed between two points in time. Investigators can calculate a hash when evidence is collected and compare it with a later calculation to identify modification. The original hash should be protected so that an attacker cannot alter both the evidence and its reference value. Hash comparison supports evidence integrity but does not by itself establish whether a file is malicious. Renaming, compressing, or changing the extension does not provide a reliable method for proving that the underlying evidence remains unchanged.<\/span><\/p>\n<h3><b>Question 145<\/b><\/h3>\n<p><b>A company wants to limit the impact of a compromised application server by preventing it from initiating unnecessary connections to other internal systems. Which control is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted internal routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Broad shared administrator access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Host-based or network-based outbound restrictions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publicly exposing internal services<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Host-based or network-based outbound restrictions can limit which destinations and services an application server is permitted to contact. This reduces unnecessary communication paths and can limit lateral movement if the server becomes compromised. Rules should be based on documented application dependencies so legitimate operations continue while unnecessary connections are denied. Network segmentation, firewalls, and host-based controls can work together to enforce these restrictions. Unrestricted routing and broad administrative access increase potential attack paths, while exposing internal services publicly creates additional risk. Restricting outbound communication is an important defense-in-depth measure for critical servers.<\/span><\/p>\n<h3><b>Question 146<\/b><\/h3>\n<p><b>An organization needs to identify who is responsible for approving a security policy exception. Which element should be defined in the exception process?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Random approval selection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A designated risk owner and authorized approver<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Approval by any employee<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">No approval requirement<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A designated risk owner and authorized approver establish accountability for security policy exceptions. The process should identify who accepts the residual risk, why the exception is required, what systems or activities are affected, and how long the exception remains valid. Appropriate management approval ensures that exceptions are consciously accepted rather than created informally. Random or unrestricted approval does not provide reliable accountability. Exceptions should also include compensating controls and review dates where appropriate. Clear ownership allows the organization to track exceptions and determine whether they should eventually be removed or replaced with a compliant solution.<\/span><\/p>\n<h3><b>Question 147<\/b><\/h3>\n<p><b>A security administrator discovers that a critical server has an unnecessary compiler installed, even though the server does not perform software development. What action best follows secure hardening principles?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keep the compiler available for convenience<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove unnecessary software after validating dependencies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Grant all users permission to execute it<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publish the compiler configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Removing unnecessary software can reduce the attack surface of a server when the software has no legitimate operational requirement. Unneeded compilers, utilities, and services may provide additional functionality that attackers could abuse after gaining access. Before removal, administrators should verify that no approved application or operational process depends on the component. Changes should be documented and tested. Keeping unnecessary software solely for convenience increases exposure, while granting broad execution permissions increases potential misuse. Secure hardening focuses on reducing unnecessary functionality while preserving the capabilities required for legitimate business operations.<\/span><\/p>\n<h3><b>Question 148<\/b><\/h3>\n<p><b>A company wants to ensure that security-sensitive configuration changes receive appropriate testing before being applied broadly. Which deployment strategy can reduce operational risk?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Immediate deployment to every system<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pilot deployment followed by controlled rollout<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unapproved manual modification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent suspension of testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A pilot deployment followed by a controlled rollout allows an organization to evaluate a configuration change on a limited group of systems before applying it broadly. The pilot can reveal compatibility issues, unexpected security effects, performance problems, or operational dependencies. Results should be reviewed against predefined acceptance criteria before wider deployment. A staged rollout can also include rollback procedures if problems emerge. Immediate deployment across every system increases the potential impact of an unsuccessful change, while unapproved modifications weaken governance. Suspending testing removes an important opportunity to identify problems before they affect a larger environment.<\/span><\/p>\n<h3><b>Question 149<\/b><\/h3>\n<p><b>A security team wants to prevent unauthorized devices from gaining access to an internal wired network through unused switch ports. Which control is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enable every unused port<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable unused switch ports<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publish switch management credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove physical security controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Disabling unused switch ports prevents unauthorized devices from using inactive network connections to gain access to the internal environment. Organizations can also use port security, network access control, device authentication, and appropriate physical safeguards to strengthen protection. Administrators should maintain documentation of active ports and enable additional ports only when there is an approved business requirement. Leaving unused ports active increases the number of potential entry points. Publishing management credentials or removing physical controls creates additional security risks. Network access controls should be reviewed periodically as office layouts, equipment, and connectivity requirements change.<\/span><\/p>\n<h3><b>Question 150<\/b><\/h3>\n<p><b>A company wants to ensure that a security alert reaches an analyst even when the primary monitoring dashboard is unavailable. Which capability supports this objective?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Independent alert notification mechanisms<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-screen monitoring only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual checking once per month<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabled escalation procedures<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Independent alert notification mechanisms provide an alternative path for delivering important security events when a primary monitoring interface or service becomes unavailable. Depending on the organization&#8217;s architecture, notifications may use separate messaging systems, automated escalation services, or other resilient channels. Critical alerts should have clearly defined ownership and escalation requirements so that notifications receive timely attention. A single dashboard creates a potential point of failure, while infrequent manual checks may delay detection. Disabling escalation procedures removes accountability. Monitoring resilience should be tested periodically to verify that important alerts continue reaching responsible personnel during component failures.<\/span><\/p>\n<h3><b>Question 151<\/b><\/h3>\n<p><b>A security analyst needs to determine whether a user accessed a sensitive application from a device that was previously unknown to the organization. Which record can provide useful evidence?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint and authentication telemetry<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office cleaning schedule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Building utility records<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee cafeteria records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint and authentication telemetry can provide information about the device, account, timestamp, source address, authentication method, and other context associated with an application session. Comparing this information with known managed devices and historical activity can help analysts identify unusual access patterns. An unfamiliar device does not automatically prove malicious activity because legitimate device replacement, travel, or approved personal-device policies may explain the event. Analysts should correlate multiple sources before reaching a conclusion. Office cleaning, utility, and cafeteria records generally do not provide relevant technical evidence about an application&#8217;s authentication or endpoint activity.<\/span><\/p>\n<h3><b>Question 152<\/b><\/h3>\n<p><b>An organization wants to protect privileged credentials used by automated services without requiring administrators to manually enter passwords each time. Which approach is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store passwords in plain-text scripts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use a managed secrets solution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Embed passwords in public documentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Share one credential among all applications<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A managed secrets solution can securely store and provide credentials required by automated services while reducing the need to embed passwords directly in scripts or configuration files. Depending on the platform, secrets can be rotated automatically, access can be restricted by workload identity, and retrieval events can be logged. Applications should receive only the credentials and permissions required for their functions. Plain-text scripts and public documentation can expose credentials to unauthorized users. Sharing one credential across applications also increases the potential impact of compromise and makes it difficult to determine which service used the credential.<\/span><\/p>\n<h3><b>Question 153<\/b><\/h3>\n<p><b>A company is reviewing its incident response process and wants to determine whether containment actions were performed within the expected timeframe. Which information is most useful?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident timestamps and response records<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office seating assignments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer model numbers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee parking information<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Incident timestamps and response records provide evidence for evaluating whether containment actions occurred within defined expectations. Relevant records may include the time an event was detected, escalated, assigned, contained, and resolved. Comparing actual response times with established service levels can help identify bottlenecks and areas for improvement. Analysts should account for incident severity and complexity when interpreting the results because different events may require different response processes. Office seating, printer models, and parking information do not provide meaningful evidence about incident response timing or containment performance.<\/span><\/p>\n<h3><b>Question 154<\/b><\/h3>\n<p><b>A security administrator wants to reduce the risk of unauthorized access through a dormant user account. What should be implemented?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatic disabling of inactive accounts according to policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent activation of every account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared credentials for dormant accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removal of account monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Automatic disabling of inactive accounts can reduce the opportunity for attackers to abuse credentials that are no longer needed. Organizations should establish an inactivity threshold appropriate to their environment and ensure that exceptions for legitimate service or temporary accounts are documented and reviewed. Account lifecycle processes should also include timely creation, modification, and removal of access based on authoritative personnel information. Permanently active dormant accounts increase exposure, while shared credentials weaken accountability. Removing monitoring makes suspicious use of inactive accounts more difficult to detect. Dormant-account controls should complement broader identity governance practices.<\/span><\/p>\n<h3><b>Question 155<\/b><\/h3>\n<p><b>A company needs to ensure that an application server communicates with its database only through the required protocol and port. Which control can enforce this restriction?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network access control rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unlimited routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS registration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared user accounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network access control rules can restrict communication between an application server and its database to approved protocols, ports, and source or destination addresses. This follows a deny-by-default approach in which unnecessary traffic is blocked while required application dependencies are permitted. Restricting communication reduces exposure and can limit the impact of a compromised server. Rules should be documented, tested, monitored, and reviewed when application architecture changes. Unlimited routing creates unnecessary connectivity, while public DNS registration and shared accounts do not directly enforce network communication restrictions between the application and database tiers.<\/span><\/p>\n<h3><b>Question 156<\/b><\/h3>\n<p><b>A security team wants to ensure that employees can report suspected phishing messages without forwarding them to coworkers. Which capability is useful?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A designated phishing-reporting mechanism<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publicly forwarding suspicious messages<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing email security controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling user reporting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A designated phishing-reporting mechanism provides employees with a controlled way to submit suspicious messages to the security team for analysis. The mechanism can preserve relevant email metadata, reduce unnecessary forwarding, and allow analysts to identify campaigns affecting multiple users. Clear instructions should explain how employees can report suspicious messages and what information should be included. Publicly forwarding potentially malicious messages may expose additional users to harmful content. Removing email security controls or disabling reporting reduces defensive capability. Organizations can also use reported-message data to improve filtering, awareness training, and incident response.<\/span><\/p>\n<h3><b>Question 157<\/b><\/h3>\n<p><b>A company wants to ensure that only authorized personnel can modify security policies stored in a centralized repository. Which control is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Repository access control with change auditing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous write access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public modification permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Repository access control with change auditing restricts policy modifications to authorized personnel while providing a record of who changed what and when. Security policies are important governance artifacts, so unauthorized modification could weaken organizational controls or create conflicting requirements. Role-based permissions, individual accounts, version history, approval workflows, and protected backups can strengthen policy integrity. Anonymous or public write access removes accountability, while shared administrator credentials make individual attribution difficult. Policy repositories should also be reviewed periodically to ensure that access permissions remain aligned with current responsibilities.<\/span><\/p>\n<h3><b>Question 158<\/b><\/h3>\n<p><b>A security administrator wants to determine whether a server&#8217;s security configuration changed unexpectedly overnight. Which capability can provide the most direct indication?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration change monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee attendance tracking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer utilization reports<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office temperature monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration change monitoring can detect or report modifications to important system settings, services, permissions, security controls, and other defined configuration elements. Alerts can help administrators identify unauthorized changes and correlate them with approved maintenance activity or change requests. The monitoring system should protect its records from unauthorized modification and maintain reliable timestamps. Unexpected changes should be investigated because they may result from administrative error, unauthorized activity, malware, or legitimate but undocumented work. Employee attendance, printer utilization, and office temperature data generally cannot directly establish whether a server&#8217;s security configuration changed.<\/span><\/p>\n<h3><b>Question 159<\/b><\/h3>\n<p><b>A company is determining whether a security control should be automated or remain manual. Which factor should influence the decision most directly?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk, control requirements, consistency, and operational feasibility<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee preference alone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office decoration style<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Number of meeting rooms<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The decision to automate a security control should consider the associated risk, control requirements, desired consistency, frequency of the task, complexity, cost, and operational feasibility. Automation can improve repeatability and reduce human error for suitable activities, but poorly designed automation can propagate mistakes quickly. Manual procedures may remain appropriate where judgment or contextual review is essential. Organizations should evaluate the control objective rather than assuming automation is always preferable. Employee preference or unrelated office characteristics should not determine the security architecture. Testing and monitoring are important when automated controls are introduced.<\/span><\/p>\n<h3><b>Question 160<\/b><\/h3>\n<p><b>A security manager wants to determine whether security findings identified during an assessment have actually been corrected. Which activity provides the strongest confirmation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remediation verification testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deleting the original findings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assuming remediation after assigning an owner<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Closing findings without evidence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Remediation verification testing confirms that previously identified security weaknesses have actually been corrected and that the implemented solution works as intended. Verification may involve rescanning a vulnerable system, reviewing configuration, performing controlled testing, or examining evidence of the implemented corrective action. Merely assigning an owner or marking a finding closed does not demonstrate that the underlying issue has been resolved. Original findings should be retained for accountability and comparison. Effective remediation management should track ownership, deadlines, status, evidence, and verification results so that unresolved weaknesses do not disappear from security reporting.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC SSCP Exam Dumps and Practice Test Dumps. &nbsp; Question 141 A security administrator needs to ensure that an administrator cannot modify audit records after performing a sensitive action. Which control is most appropriate? Store audit records in a separately controlled system Give administrators unrestricted log permissions Allow users to edit their own [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24910"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=24910"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24910\/revisions"}],"predecessor-version":[{"id":24911,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24910\/revisions\/24911"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=24910"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=24910"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=24910"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}