{"id":24932,"date":"2026-09-30T09:36:10","date_gmt":"2026-09-30T09:36:10","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=24932"},"modified":"2026-09-30T09:36:10","modified_gmt":"2026-09-30T09:36:10","slug":"isc-sscp-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-sscp-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"ISC SSCP Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sscp-exam-dumps\"><b>ISC SSCP Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 361<\/b><\/h3>\n<p><b>Which document identifies identified risks, their owners, and planned responses within an organization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk register<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network diagram<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset label<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident ticket<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A risk register provides a structured record of identified risks and commonly includes information such as risk descriptions, affected assets or processes, owners, likelihood, impact, treatment decisions, and status. It helps security and business teams track risks throughout their lifecycle and provides visibility into whether mitigation activities are progressing. A network diagram describes connectivity, an asset label identifies equipment, and an incident ticket records a specific operational or security event. Risk registers should be reviewed and updated when new threats, vulnerabilities, business changes, or control weaknesses alter the organization&#8217;s risk environment.<\/span><\/p>\n<h3><b>Question 362<\/b><\/h3>\n<p><b>A security team discovers that an application stores more customer information than is necessary for its business function. Which principle should guide remediation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data duplication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data minimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unlimited retention<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data minimization means collecting, processing, and retaining only the information necessary for a legitimate business purpose. Reducing unnecessary data can decrease the potential impact of unauthorized disclosure, simplify protection requirements, and reduce unnecessary storage and retention obligations. An organization should first determine what information the application genuinely requires and then remove or avoid collecting information that does not serve a defined purpose. Data duplication and unlimited retention can increase exposure, while open access creates additional confidentiality risks. Data minimization should be incorporated into system design, application requirements, and information-handling procedures.<\/span><\/p>\n<h3><b>Question 363<\/b><\/h3>\n<p><b>Who should normally be accountable for accepting a business risk when a security issue cannot be completely eliminated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Help-desk technician<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database operator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authorized risk owner<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">End user<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An authorized risk owner is accountable for understanding and accepting a business risk when an issue cannot be completely eliminated or when management chooses to retain the risk. Risk acceptance should be based on documented analysis of potential impact, likelihood, existing controls, and available treatment options. Technical personnel may identify or mitigate the issue, but they do not automatically have authority to accept organizational risk. Formal approval and documentation help establish accountability and demonstrate that the decision was made at an appropriate management level rather than informally by an individual administrator.<\/span><\/p>\n<h3><b>Question 364<\/b><\/h3>\n<p><b>Which technique can help protect sensitive data when an application must use the data but does not require the original value?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential reuse<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port forwarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data masking replaces or obscures sensitive values so that users or systems can work with representative information without receiving the original confidential data. For example, selected characters of an account number may be hidden when displaying information to authorized personnel who do not need the complete value. Masking can reduce unnecessary exposure in applications, reports, testing environments, and user interfaces. Open sharing increases exposure, credential reuse weakens authentication security, and port forwarding addresses network connectivity rather than data confidentiality. Masking should be designed carefully so that protected values cannot be easily reconstructed.<\/span><\/p>\n<h3><b>Question 365<\/b><\/h3>\n<p><b>A company wants to identify the person responsible for each critical information asset. Which practice is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset ownership assignment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous administration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public registration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared responsibility without assignment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Asset ownership assignment identifies an accountable individual or organizational role responsible for managing a particular information asset. Owners can help determine appropriate classification, access requirements, retention rules, security controls, and acceptable use. Clear ownership also improves accountability when an asset requires risk decisions, control reviews, or remediation. Anonymous administration and shared responsibility without defined accountability can create uncertainty about who must make decisions or address security problems. Asset ownership should remain current as personnel, organizational responsibilities, systems, and business processes change.<\/span><\/p>\n<h3><b>Question 366<\/b><\/h3>\n<p><b>An organization wants to prevent users from installing unapproved browser extensions on managed workstations. Which control is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint application control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network time synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup rotation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint application control can restrict which software components, including browser extensions where supported, may be installed or executed on managed workstations. This reduces the possibility that users introduce extensions containing malicious code, excessive permissions, tracking functionality, or other unwanted behavior. Controls should be based on approved software requirements and should include procedures for requesting legitimate exceptions. Public DNS provides name-resolution services, time synchronization supports consistent timestamps, and backup rotation supports recovery. Endpoint controls should be centrally managed and periodically reviewed to ensure their rules remain appropriate.<\/span><\/p>\n<h3><b>Question 367<\/b><\/h3>\n<p><b>Which metric measures the percentage of security controls that meet their defined requirements during an assessment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset turnover<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control compliance rate<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network latency<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage capacity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A control compliance rate can indicate the proportion of assessed controls that satisfy established requirements. This type of metric helps security teams identify areas where controls are operating as expected and where remediation may be required. The organization should define what constitutes compliance before measuring the metric so that results are consistent and meaningful. Asset turnover measures changes in equipment, network latency measures communication delay, and storage capacity concerns available data space. Security metrics should be interpreted within their context and should support informed decisions rather than being treated as isolated measures of overall security.<\/span><\/p>\n<h3><b>Question 368<\/b><\/h3>\n<p><b>A company needs to ensure that sensitive records are removed after their approved retention period. What should guide this process?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Random deletion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Informal employee preference<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Documented retention schedule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A documented retention schedule defines how long specific categories of information should be retained and when they should be securely disposed of, subject to legal, regulatory, contractual, and business requirements. Applying a defined schedule helps prevent both premature destruction and unnecessary retention of sensitive records. Random deletion may destroy information that is still required, while permanent storage can increase exposure and storage obligations. Employee preference alone does not provide sufficient governance. Retention schedules should identify responsible parties, approved disposal methods, exceptions such as legal holds, and requirements for documenting completed disposal activities.<\/span><\/p>\n<h3><b>Question 369<\/b><\/h3>\n<p><b>Which control is designed to prevent sensitive information from being exposed through application error messages?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detailed public stack traces<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure error handling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous debugging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted diagnostic output<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure error handling prevents applications from exposing sensitive technical details through messages presented to users. Production applications should generally avoid revealing credentials, database information, internal paths, stack traces, configuration details, or other information that could assist an attacker. Detailed diagnostic information can instead be recorded in protected logs accessible to authorized personnel when needed for troubleshooting. Public stack traces and unrestricted diagnostic output may reveal useful information about internal systems. Secure error handling should be incorporated during application development and testing, with logging designed to preserve useful investigative information without unnecessarily exposing sensitive data.<\/span><\/p>\n<h3><b>Question 370<\/b><\/h3>\n<p><b>A security administrator needs to determine whether a new system introduces unacceptable exposure before deployment. Which activity should be performed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security risk assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer maintenance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cable labeling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password sharing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security risk assessment evaluates potential threats, vulnerabilities, impacts, and existing or planned controls associated with a system. Conducting the assessment before deployment allows security concerns to be identified while design changes are still practical and less costly. The assessment can consider architecture, access controls, data sensitivity, dependencies, regulatory requirements, and likely threat scenarios. Printer maintenance and cable labeling support operational tasks, while password sharing weakens accountability and authentication security. Security assessments should involve appropriate technical and business stakeholders and should lead to documented decisions about risk treatment and required controls.<\/span><\/p>\n<h3><b>Question 371<\/b><\/h3>\n<p><b>Which practice helps prevent unauthorized personnel from following an employee through a controlled entrance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open-door policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared access badges<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mantrap or controlled-entry system<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unmonitored entrance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A mantrap or similar controlled-entry system can help prevent tailgating by requiring an individual to pass through a controlled area before another person can enter. Depending on the design, authentication may be required at one or both doors, and the system can restrict simultaneous entry. Shared badges and open or unmonitored entrances weaken individual accountability and make unauthorized physical access easier. Physical access controls should be selected according to facility risk, operational requirements, emergency procedures, and applicable safety considerations. Access records and monitoring can further support investigation of unauthorized entry attempts.<\/span><\/p>\n<h3><b>Question 372<\/b><\/h3>\n<p><b>Which network security control can limit the number of connection attempts accepted by an internet-facing service?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rate limiting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset tagging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Rate limiting restricts how frequently requests or connection attempts can be processed from a user, client, source, or other defined context during a specified period. It can help reduce the impact of excessive requests, automated abuse, certain denial-of-service conditions, and repeated authentication attempts. Rate limits should be designed carefully so that legitimate users are not unnecessarily blocked. File compression reduces data size, data classification categorizes information according to sensitivity or impact, and asset tagging supports inventory management. Rate limiting works best when combined with monitoring, appropriate thresholds, and additional protective controls.<\/span><\/p>\n<h3><b>Question 373<\/b><\/h3>\n<p><b>An organization wants to prevent a compromised web server from directly communicating with every internal network segment. Which architecture is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation with controlled paths<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Universal routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted internal connectivity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation with controlled communication paths limits which internal systems a compromised server can reach. A web server can be placed in an appropriate network zone and permitted to communicate only with required services, such as a designated application or database tier. This reduces opportunities for lateral movement if the server is compromised. Flat networks and unrestricted connectivity provide broader access and can increase the potential scope of an intrusion. Segmentation should be supported by firewall or access-control rules, documented communication requirements, monitoring, and periodic review to ensure that unnecessary connections are removed.<\/span><\/p>\n<h3><b>Question 374<\/b><\/h3>\n<p><b>Which method can help determine whether a user should continue receiving access after moving to another department?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access recertification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log formatting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Access recertification requires authorized personnel to periodically confirm that users still require their assigned permissions. When an employee changes departments or responsibilities, recertification can reveal access that no longer matches the person&#8217;s current duties. Unnecessary permissions can then be removed through approved processes. This supports least privilege and reduces the risk created by accumulated access rights. Data compression affects storage efficiency, DNS caching supports name resolution, and log formatting concerns the presentation of recorded events. Access recertification should cover sensitive privileges and should maintain evidence that reviews were completed and identified issues were addressed.<\/span><\/p>\n<h3><b>Question 375<\/b><\/h3>\n<p><b>Which approach provides a secure way to store application secrets without embedding them directly in source code?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public text files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Source-code comments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secrets management system<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared spreadsheet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A secrets management system provides controlled storage and retrieval for sensitive values such as API keys, passwords, tokens, and certificates. Applications can retrieve required secrets through authenticated mechanisms rather than storing them directly in source code or configuration files that may be widely accessible. Centralized secrets management can also support access control, auditing, rotation, and lifecycle management. Public text files, source-code comments, and shared spreadsheets can expose credentials through repositories, backups, collaboration systems, or unauthorized access. Secret storage should follow least privilege and should provide appropriate monitoring and rotation capabilities.<\/span><\/p>\n<h3><b>Question 376<\/b><\/h3>\n<p><b>Which action helps maintain reliable timestamps across security devices when investigating an incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable system clocks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use synchronized time sources<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Change clocks manually after incidents<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow unrestricted clock changes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Synchronized time sources help security devices, servers, applications, and monitoring systems maintain consistent timestamps. Accurate and consistent time is important when reconstructing the sequence of events across multiple systems during an investigation. Without synchronization, events may appear out of order or have misleading timestamps, making correlation more difficult. Manual changes after an incident can undermine confidence in records, while unrestricted clock changes can allow inaccurate or manipulated timestamps. Organizations should use approved time sources, monitor synchronization status, protect time-service configurations, and investigate significant clock deviations.<\/span><\/p>\n<h3><b>Question 377<\/b><\/h3>\n<p><b>A security team wants to ensure that a cloud provider&#8217;s responsibilities for protecting customer data are clearly documented. Which document should be reviewed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service agreement and security terms<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office seating plan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer maintenance record<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee vacation schedule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The service agreement and associated security terms can document responsibilities between an organization and its cloud provider. Depending on the service, these terms may address data protection, access management, incident notification, availability, security controls, audit rights, retention, and other contractual obligations. Clearly defined responsibilities help reduce uncertainty about which party must implement or operate particular controls. Office seating plans, printer maintenance records, and vacation schedules do not establish cloud security responsibilities. Organizations should review provider agreements before adoption and periodically reassess them when services, requirements, regulations, or contractual terms change.<\/span><\/p>\n<h3><b>Question 378<\/b><\/h3>\n<p><b>Which security control can help ensure that only approved devices connect to an organization&#8217;s internal network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public file sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open wireless access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network access control can evaluate connection requests and enforce requirements before allowing devices to access organizational network resources. Depending on the implementation, checks may include device identity, authentication status, security posture, certificate information, or compliance with defined endpoint requirements. This can help prevent unmanaged or unauthorized devices from obtaining unrestricted internal access. Public file sharing and anonymous authentication weaken access restrictions, while open wireless access allows broader connectivity. Network access control should be integrated with identity, endpoint, and network-security processes and should provide appropriate handling for approved exceptions and remediation.<\/span><\/p>\n<h3><b>Question 379<\/b><\/h3>\n<p><b>Which activity can help identify whether a security control remains appropriate after a major business process changes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control reassessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password publication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Random configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control reassessment evaluates whether an existing security control continues to address the risks and requirements associated with a changed environment. A major business process change can introduce new systems, data flows, users, dependencies, threats, or compliance obligations, potentially making an existing control insufficient or unnecessary. Reassessment allows security teams and business stakeholders to identify these changes and determine whether controls should be modified, replaced, or supplemented. Password publication and unrestricted access create security weaknesses, while random configuration changes do not provide structured assurance. Reassessment should be documented and performed according to organizational risk-management procedures.<\/span><\/p>\n<h3><b>Question 380<\/b><\/h3>\n<p><b>Which security practice helps ensure that sensitive credentials are not exposed in application source repositories?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store credentials in source files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Commit secrets for convenience<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use secret scanning and protected storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publish configuration files publicly<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secret scanning can identify credentials or other sensitive values accidentally placed in source repositories, while protected secret storage keeps operational credentials outside ordinary application source code. Combining these practices reduces the likelihood that passwords, API keys, tokens, or private keys will be exposed through repository history or developer workflows. Credentials should not be committed merely for convenience because removing them later may not eliminate copies from historical revisions. Publicly publishing configuration files creates additional exposure. Secure development processes should include secret-handling guidance, automated scanning, appropriate access controls, and credential rotation when exposure is suspected.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC SSCP Exam Dumps and Practice Test Dumps. &nbsp; Question 361 Which document identifies identified risks, their owners, and planned responses within an organization? Risk register Network diagram Asset label Incident ticket Correct Answer: 1 Explanation A risk register provides a structured record of identified risks and commonly includes information such as risk [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24932"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=24932"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24932\/revisions"}],"predecessor-version":[{"id":24933,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24932\/revisions\/24933"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=24932"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=24932"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=24932"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}