SSCP Systems Security Certified Practitioner practice questions
226 free questions with answers and explanations.
- 51.A system administrator is configuring a secure tunnel using IPsec. During the Internet Key Exchange (IKE) phase, the administrator needs to ensure that the two endpoints can agree on a shared secret key over an insecure channel without actually transmitting the key itself. Which cryptographic algorithm facilitates this process?Cryptography
- 52.A security architect is designing an authentication system for a highly sensitive research facility. They require an authentication method that provides very high assurance of identity, is difficult to forge, and is resistant to replay attacks. Which authentication method, when properly implemented, would best meet these stringent requirements?Access Controls
- 53.A security architect is designing a system for secure communication between microservices within a cloud environment. The architect wants to ensure that even if a long-term private key is compromised, past communication sessions cannot be decrypted. Which cryptographic property is essential for achieving this goal?Cryptography
- 54.A security architect is designing a system that requires users to have unique, verifiable identities without relying on a centralized Certificate Authority. The goal is to allow users to generate and manage their own keys and certificates in a distributed trust model. Which cryptographic concept best describes this design principle?Cryptography
- 55.A system architect is designing a secure communication protocol between a client application and a server. The architect wants to ensure that the protocol provides both confidentiality and data integrity, as well as authentication of the sender. Which type of cryptographic primitive combines these three security services efficiently?Cryptography
- 56.A system architect is designing a secure data storage solution for highly sensitive government data. They require a cryptographic algorithm that has been rigorously tested, published, and widely adopted by both government and industry for its strong security properties. Which algorithm would be the most appropriate choice for encrypting the data at rest?Cryptography
- 57.A security architect is designing a system for storing highly sensitive government documents. The requirement explicitly states that the encryption method must be resistant to all known forms of cryptanalysis, including attacks from quantum computers, for the foreseeable future. Which cryptographic concept is most relevant to this requirement?Cryptography
- 58.A security analyst is investigating a suspected man-in-the-middle (MITM) attack where a malicious actor intercepted communication between a client and a server. The client's browser displayed a warning about an untrusted certificate. Which cryptographic concept, if properly implemented and verified by the client, would have primarily helped detect or prevent this specific MITM attack?Cryptography
- 59.A company is implementing a Public Key Infrastructure (PKI) and needs to define the structure for its digital certificates. They are particularly concerned with ensuring that certificates can be efficiently validated and that the chain of trust is clearly established. Which component of a digital certificate is primarily responsible for linking it to its issuing authority and allowing for hierarchical validation?Cryptography
- 60.An organization is implementing a new system where access to data is dynamically granted or denied based on automated rules that evaluate the user's current network segment, the time of day, and whether their device is compliant with security policies. Users do not directly control permissions, and there are no explicit security labels on the data itself. Which access control model best fits this description?Access Controls
- 61.A security auditor is examining a client's Certificate Revocation List (CRL) distribution points. The auditor notices that the CRLs are updated only once every 24 hours. Given this update frequency, what is the maximum window of vulnerability for a revoked certificate before its status is officially published to all relying parties?Cryptography
- 62.A forensic investigator is examining encrypted files found on a suspect's computer. The files appear to be encrypted using a symmetric key, and the investigator knows that the suspect used a passphrase to protect this key. To gain access to the files, the investigator needs to determine the symmetric key. Which cryptographic technique is MOST relevant to breaking the passphrase protection and recovering the key?Cryptography
- 63.A software development team is building a new application that needs to securely access a database. Instead of embedding database credentials directly into the application code, the developers implement a mechanism where the application requests temporary, short-lived credentials from an identity provider (IdP) just before it needs to connect to the database. These temporary credentials are valid only for a specific duration and a limited set of operations. This approach primarily exemplifies which security principle?Access Controls
- 64.A cryptanalyst is attempting to break a new block cipher. They have observed that when the same plaintext block is encrypted multiple times with the same key, it always produces the same ciphertext block. This observation indicates a lack of which important cryptographic property that helps obscure patterns in encrypted data?Cryptography
- 65.A security engineer is implementing a cryptographic solution for protecting sensitive data at rest on a server. The requirement states that even if the server's memory is dumped, the encryption keys for the data should not be easily recoverable from the dump. Which of the following techniques would best address this requirement?Cryptography
- 66.A security auditor is reviewing an organization's access control policies and discovers that several administrators have been granted 'full control' over all critical production servers, regardless of their specific job function or the principle of least privilege. This situation represents a failure in which crucial Identity and Access Management (IAM) concept?Access Controls
- 67.A developer is designing a system that requires users to digitally sign documents to ensure non-repudiation. The system must also guarantee the integrity of the document and authenticate the signer. Which component of a digital signature provides the integrity guarantee?Cryptography
- 68.An organization is migrating from an older cryptographic algorithm to a stronger one. They are currently using an algorithm with a 56-bit key that is vulnerable to brute-force attacks. Which of the following symmetric encryption algorithms would be a suitable replacement, offering a higher level of security for data at rest?Cryptography
- 69.A cryptocurrency project aims to use a hashing algorithm that is resistant to quantum computing attacks. Which of the following hashing algorithms is currently considered to offer post-quantum security properties?Cryptography
- 70.A security auditor is reviewing a company's SSL/TLS configuration for its web servers. The auditor discovers that the servers are configured to use ephemeral Diffie-Hellman (DHE) key exchange with certificates that are signed using RSA. The auditor notes that even if the server's long-term RSA private key were compromised in the future, past communications would remain confidential. This property is primarily due to which cryptographic concept?Cryptography
- 71.A cryptocurrency project aims to use a hashing algorithm that is resistant to quantum computer attacks, specifically for its proof-of-work mechanism. Which type of hashing algorithm is being sought?Cryptography
- 72.A security team is investigating a potential breach where an attacker gained access to a server hosting encrypted data. The data was encrypted using a strong symmetric algorithm, but the team suspects the attacker might have also stolen the symmetric key from the server's memory before it was wiped. To mitigate such risks in the future, they want to implement a method where the encryption key is never directly present in memory in its raw form for extended periods. Which of the following techniques would BEST address this concern?Cryptography
- 73.A system administrator needs to implement a secure method for storing user passwords in a database. The solution must make it computationally expensive for an attacker to crack passwords even if the hashed password database is stolen. Which cryptographic technique is specifically designed to achieve this goal?Cryptography
- 74.A security auditor is reviewing a client's Certificate Revocation List (CRL) distribution points. The auditor observes that the CRLs are being distributed over HTTP without any additional security measures. What is the primary security concern with this distribution method?Cryptography
- 75.A system implements an access control matrix where each cell defines the permissions a specific subject has over a specific object. This matrix is directly managed by the system and can be quite granular, allowing for unique permissions for every subject-object pair. Which access control model is most closely associated with this implementation?Access Controls
- 76.During a post-incident review, an organization determines that the incident response team struggled to communicate effectively and follow established procedures due to outdated contact information and poorly defined roles. Which component of the incident response plan (IRP) should be updated to address these issues?Incident Response and Recovery
- 77.A security analyst is reviewing logs after a suspected intrusion. They observe multiple failed login attempts from an external IP address, followed by a successful login using a legitimate user account from the same external IP address. The successful login occurred shortly after the failed attempts. Which of the following attack types has most likely occurred?Risk Identification, Monitoring, and Analysis
- 78.A security operations center (SOC) analyst observes a sudden, sustained increase in network traffic originating from an internal server to various external IP addresses, primarily on port 53 (DNS) and port 443 (HTTPS). This traffic pattern is highly unusual for this particular server, which typically only communicates internally. What type of security event is this most indicative of?Risk Identification, Monitoring, and Analysis
- 79.A company is conducting its annual Business Impact Analysis (BIA). The primary goal of this analysis is to identify and prioritize critical business functions and their associated resources. Which of the following is an essential outcome of a well-performed BIA?Incident Response and Recovery
- 80.A security incident occurs where sensitive customer data is exfiltrated from a web application. After containing the incident, the team performs a forensic analysis and identifies a zero-day vulnerability in the application as the root cause. Which of the following activities is performed during the 'Eradication' phase to address this root cause?Incident Response and Recovery
- 81.A security team is using the MITRE ATT&CK framework to understand a recent advanced persistent threat (APT) campaign targeting their industry. They are focusing on how the adversary gained initial access and then moved laterally within the network. Which layer of the ATT&CK framework are they primarily examining?Risk Identification, Monitoring, and Analysis
- 82.A financial institution is developing a new mobile banking application. The project manager is concerned about potential risks from third-party libraries and open-source components used in the application. To proactively identify and mitigate these risks during the development lifecycle, which security assessment technique should be continuously integrated?Risk Identification, Monitoring, and Analysis
- 83.A healthcare organization is developing its disaster recovery plan. They have determined that their Electronic Health Record (EHR) system can tolerate a maximum data loss equivalent to 4 hours of transactions. Beyond this point, the impact on patient care and regulatory compliance becomes unacceptable. What concept does this 4-hour tolerance represent?Incident Response and Recovery
- 84.An organization's incident response team has identified a sophisticated, persistent threat actor operating within their network. After containing the initial breach, they realize the attacker has established multiple backdoors and modified system configurations to maintain access. Which incident response phase focuses on completely removing these persistent elements and ensuring the attacker can no longer access the system?Incident Response and Recovery
- 85.A security team is implementing a new risk management framework. They have just completed the step of identifying assets, threats, and vulnerabilities. What is the immediate next step in a standard risk management process?Risk Identification, Monitoring, and Analysis
- 86.A large enterprise is implementing a new security information and event management (SIEM) system. During the initial configuration, the security team is deciding which logs to prioritize for ingestion and analysis. They aim to focus on events that provide the clearest indicators of potential compromise or malicious activity. Which of the following log sources typically provides the richest data for identifying security incidents?Risk Identification, Monitoring, and Analysis
- 87.An organization is updating its disaster recovery plan. The plan currently focuses on restoring IT systems. A consultant advises that the plan needs to be expanded to address the broader continuity of business operations, including non-IT functions, personnel, and critical processes. What type of plan is the consultant suggesting the organization develop or incorporate?Incident Response and Recovery
- 88.A security team receives an alert indicating unauthorized access to a critical database server. During the initial investigation, they observe unusual queries and data exfiltration attempts. To prevent further data loss while preserving evidence for forensic analysis, which of the following containment strategies is generally considered the MOST appropriate immediate action?Incident Response and Recovery
- 89.During a post-incident review, a security team determines that a recent breach could have been prevented if security patches had been applied to a critical server two months prior. The vulnerability was publicly disclosed, and a patch was available. This situation highlights a failure in which aspect of the security program?Risk Identification, Monitoring, and Analysis
- 90.A global manufacturing company faces a potential supply chain disruption due to a regional natural disaster affecting a key component supplier. The company's Business Continuity Plan (BCP) team convenes to assess the situation and implement pre-defined strategies to mitigate the impact. What is the immediate next step for the BCP team after recognizing this potential disruption?Incident Response and Recovery
- 91.A small business recently experienced a data breach where customer credit card information was exfiltrated. The incident response team has contained the breach and eradicated the malware. What is the immediate next step according to standard incident response procedures?Incident Response and Recovery
- 92.During the identification phase of an incident, an analyst discovers unusual outbound network traffic from a critical server. Upon further investigation, it's determined that an unauthorized process is attempting to exfiltrate data. What is the MOST appropriate next action?Incident Response and Recovery
- 93.A company is conducting a Business Impact Analysis (BIA) to determine the potential financial and operational losses associated with various disruptions. They are currently focusing on the maximum tolerable downtime for their core payment processing system, which directly impacts revenue. What metric are they trying to establish?Incident Response and Recovery
- 94.A company's Business Impact Analysis (BIA) determines that its e-commerce website has a Maximum Tolerable Downtime (MTD) of 4 hours and a Recovery Time Objective (RTO) of 2 hours. What is the MOST critical implication of these metrics for the disaster recovery plan?Incident Response and Recovery
- 95.A security analyst is reviewing an organization's incident response plan (IRP) and discovers that there is no dedicated process for identifying the root cause of security incidents. Which phase of the incident response process is most directly impacted by this omission?Incident Response and Recovery
- 96.A large e-commerce company experiences a major distributed denial-of-service (DDoS) attack that overwhelms its primary data center. The company's disaster recovery plan (DRP) dictates a switch to an alternate site. Which type of alternate site provides the most immediate cutover with minimal disruption for critical services?Incident Response and Recovery
- 97.A company is performing its annual security audit. An auditor notes that the organization has a comprehensive incident response plan, but it has not been tested or updated in the past three years, despite significant changes in the IT infrastructure and business processes. This situation primarily represents which type of risk?Risk Identification, Monitoring, and Analysis
- 98.A financial institution is developing its Business Continuity Plan (BCP). A key concern is ensuring the availability of critical services in the event of a regional power outage lasting several days. Which BCP strategy would be most effective for maintaining operational capability during such an extended disruption?Incident Response and Recovery
- 99.A security auditor is reviewing an organization's vulnerability management program. The auditor finds that while vulnerabilities are identified regularly through scanning, there is no formal process for prioritizing remediation efforts based on asset criticality, exploitability, or potential impact. Instead, vulnerabilities are patched on a 'first-come, first-served' basis. What is the most significant deficiency in this program?Risk Identification, Monitoring, and Analysis
- 100.A security analyst is reviewing a new vendor's security posture before integrating their API into the company's core application. The analyst discovers that the vendor's API uses HTTP for all communications, transmits authentication credentials in plaintext, and has no rate limiting implemented. Which of the following risk management concepts is most directly highlighted by these findings?Risk Identification, Monitoring, and Analysis