SSCP Systems Security Certified Practitioner practice questions
226 free questions with answers and explanations.
- 101.A security operations center (SOC) analyst observes a series of alerts indicating that an internal host is attempting to communicate with multiple external IP addresses over non-standard ports, immediately after a user opened an email attachment. This behavior is highly unusual for that host. Which of the following best describes the type of security event being observed?Risk Identification, Monitoring, and Analysis
- 102.An organization is evaluating its current backup strategy to ensure data availability in the event of a localized disaster. They require a solution that provides the fastest possible recovery time for critical data, even if it means higher storage costs. Which backup method would best meet this requirement?Incident Response and Recovery
- 103.A security incident response team receives an alert indicating unusually high outbound network traffic from an internal server, destined for a known malicious IP address. Upon further investigation, they discover that multiple files have been encrypted on the server. Which of the following threat intelligence indicators is most relevant to understanding this specific incident?Risk Identification, Monitoring, and Analysis
- 104.An organization is performing a risk assessment for a new cloud service. They determine that the service has a low likelihood of a data breach, but if one were to occur, the impact would be catastrophic due to sensitive customer data being exposed. After considering various controls, they decide to implement strong encryption and multi-factor authentication, which significantly reduces the likelihood of a breach but still leaves a small chance. The remaining risk is deemed acceptable given the business benefits. What risk response strategy has the organization adopted for the remaining risk?Risk Identification, Monitoring, and Analysis
- 105.A company is reviewing its disaster recovery plan. They have identified that their critical financial reporting system requires a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objective (RPO) of 1 hour. To meet these objectives, which combination of backup strategy and recovery site is MOST appropriate?Incident Response and Recovery
- 106.A security team is performing a post-incident review following a successful phishing attack that led to credential compromise. Which of the following activities is a primary objective of the 'Lessons Learned' phase?Incident Response and Recovery
- 107.A security team is conducting a comprehensive assessment of their web application. They use an automated tool to scan the application's code for known vulnerabilities and coding errors without executing the code. This process is integrated into their Continuous Integration/Continuous Deployment (CI/CD) pipeline to identify issues early in the development lifecycle. What type of security assessment is being performed?Risk Identification, Monitoring, and Analysis
- 108.A security analyst is investigating a suspected malware infection. After containing the threat, the analyst needs to ensure the malware is completely removed from all affected systems and that no backdoors remain. Which phase of incident handling is the analyst currently focused on?Incident Response and Recovery
- 109.A financial institution is updating its Business Continuity Plan (BCP). The BCP team has identified several critical business functions, including trading operations and customer account access. For these functions, they need to ensure that the maximum amount of data loss that can be tolerated is less than 15 minutes. What element of the BCP is being defined here?Incident Response and Recovery
- 110.A security team is conducting a quantitative risk assessment for a critical database server. They determine that the Single Loss Expectancy (SLE) for a data breach event is $500,000. Based on historical data and threat intelligence, they estimate the Annualized Rate of Occurrence (ARO) for such an event is 0.2 (meaning, a breach is expected once every five years). What is the Annualized Loss Expectancy (ALE) for this specific risk?Risk Identification, Monitoring, and Analysis
- 111.A security analyst is investigating an incident where a critical server was compromised. The attacker gained initial access through a known vulnerability in an unpatched application. After gaining access, the attacker installed a backdoor and moved laterally to other systems. Which of the following risk management concepts BEST describes the initial point of failure that allowed the compromise?Risk Identification, Monitoring, and Analysis
- 112.An organization relies heavily on a third-party cloud provider for its critical infrastructure. During a recent audit, it was discovered that the cloud provider experienced a significant outage due to a configuration error in their global load balancing service, impacting several of the organization's applications. The organization had performed due diligence on the provider's security controls but did not adequately assess the provider's operational resilience. This scenario highlights the importance of understanding which type of risk from a third-party perspective?Risk Identification, Monitoring, and Analysis
- 113.During a security audit, an organization discovers that several critical servers are running outdated operating systems with known, unpatched vulnerabilities. Management is aware of the risk but has decided to accept it due to the high cost and potential downtime associated with upgrading the legacy systems. This decision represents which type of risk response strategy?Risk Identification, Monitoring, and Analysis
- 114.A security analyst is reviewing an organization's incident response plan (IRP). The plan outlines several phases, including identification, containment, eradication, recovery, and lessons learned. During which phase would the analyst typically focus on removing the root cause of the incident and restoring affected systems to a secure state?Incident Response and Recovery
- 115.A global manufacturing company faces a potential supply chain disruption due to a regional natural disaster affecting a key component supplier. The company's Business Continuity Plan (BCP) has been activated. Which of the following is the MOST critical initial step the BCP team should take to mitigate the impact on production?Incident Response and Recovery
- 116.A security incident response team is analyzing a series of low-level alerts that, individually, seem insignificant but collectively suggest a potential reconnaissance phase by an advanced adversary. To effectively identify and track this evolving threat, which of the following threat intelligence concepts is most beneficial for correlating these disparate events?Risk Identification, Monitoring, and Analysis
- 117.A security analyst is reviewing a threat intelligence feed and notices an alert about a new zero-day exploit targeting a specific version of their organization's critical database software. The alert includes details about the exploit's method and potential indicators of compromise. What is the MOST immediate and critical action the analyst should take regarding this intelligence?Risk Identification, Monitoring, and Analysis
- 118.A security analyst is investigating a series of failed login attempts against a critical server. The attempts originate from various IP addresses globally, occur over a short period, and target common usernames like 'admin' and 'root'. This activity aligns with known TTPs (Tactics, Techniques, and Procedures) of a specific threat group known for credential stuffing. What type of threat intelligence would be most valuable for the analyst to assess the immediate danger and potential impact?Risk Identification, Monitoring, and Analysis
- 119.A security operations center (SOC) analyst observes a series of alerts indicating that an internal host is attempting to establish connections to multiple external IP addresses on unusual ports, and the volume of data being exfiltrated is significantly higher than normal baseline traffic for that host. The analyst cross-references this behavior with known threat intelligence and finds similarities to a recently documented command and control (C2) communication pattern. Which type of threat intelligence is the analyst primarily using to correlate these observations?Risk Identification, Monitoring, and Analysis
- 120.A financial institution is developing its Business Continuity Plan (BCP) and has identified several critical business functions. To ensure the availability of these functions during a disruption, they need to establish a secondary operational facility that can be brought online with minimal delay, complete with hardware, software, and up-to-date data. Which type of alternative site best meets these requirements?Incident Response and Recovery
- 121.A security analyst is investigating a potential data breach. They discover that sensitive customer data was exfiltrated from a web server due to an unpatched vulnerability in the web application. The organization had identified this vulnerability during a previous scan but had not yet applied the patch. What is the primary contributor to this data breach from a risk management perspective?Risk Identification, Monitoring, and Analysis
- 122.A security analyst is investigating a series of suspicious activities involving several user accounts. They notice that the affected accounts exhibit similar patterns: unusual login times, access to sensitive data they normally don't use, and attempts to connect to internal systems from unfamiliar IP addresses. The analyst suspects a coordinated attack by a specific threat actor group. Which concept is the analyst primarily trying to identify to understand the adversary's actions?Risk Identification, Monitoring, and Analysis
- 123.A security analyst is reviewing network traffic logs for unusual activity. They observe a significant amount of outbound traffic from an internal server to an unknown external IP address on TCP port 443, but the traffic does not appear to be standard HTTPS. Further investigation reveals that the server is communicating with a known malicious domain. Which type of communication is MOST likely occurring?Risk Identification, Monitoring, and Analysis
- 124.An organization is updating its incident response plan. The security team wants to ensure that critical evidence is properly collected and preserved for potential legal action or detailed forensic analysis. Which incident response principle is addressed by this concern?Incident Response and Recovery
- 125.A penetration tester is conducting a black-box assessment on a client's external web application. Which of the following best describes the information the penetration tester has access to at the start of the assessment?Risk Identification, Monitoring, and Analysis
- 126.During a significant data breach, the incident response team determines that sensitive customer data has been exfiltrated. The organization has an RTO of 4 hours and an RPO of 1 hour for this data. Which of the following actions, if not already performed, is most critical to address the RPO requirement?Incident Response and Recovery
- 127.A company performs an annual quantitative risk assessment. They identify a critical server that, if compromised, would cost an estimated \$500,000 in damages. The likelihood of this compromise occurring is estimated to be once every 5 years. What is the Annualized Loss Expectancy (ALE) for this risk?Risk Identification, Monitoring, and Analysis
- 128.A critical server hosting a web application has crashed due to a hardware failure. The disaster recovery team has successfully brought up the application on a redundant server at an alternate site. Which type of recovery site was MOST likely utilized to achieve this rapid restoration?Incident Response and Recovery
- 129.A company is developing a disaster recovery plan (DRP) and is evaluating different backup strategies. They need a solution that provides the fastest recovery time objective (RTO) for mission-critical data while minimizing potential data loss. Which backup strategy best meets these requirements?Incident Response and Recovery
- 130.A security analyst is reviewing network traffic logs and observes multiple connections from an internal server to a known malicious IP address associated with a recent phishing campaign targeting the organization. The connections are encrypted and occur at irregular intervals. The analyst needs to determine the full scope of the compromise quickly. Which of the following analysis techniques would be most effective for understanding the communication patterns and potential data exfiltration without decrypting every packet?Risk Identification, Monitoring, and Analysis
- 131.A small medical clinic is developing its disaster recovery plan. Due to budget constraints, they cannot afford a hot site. They decide to use a facility that includes basic office space, power, and network connectivity, but requires them to bring their own computers, servers, and data backups. What type of alternate site have they chosen?Incident Response and Recovery
- 132.A financial institution is evaluating the risk associated with a potential data breach. They estimate that if a breach occurs, it has a 30% chance of happening annually. The single loss expectancy (SLE) for such an event is calculated to be $500,000, considering direct costs, regulatory fines, and reputational damage. What is the Annualized Loss Expectancy (ALE) for this risk?Risk Identification, Monitoring, and Analysis
- 133.A developer is writing a RESTful API for a new mobile application. The API needs to enforce access control based on the user's role (e.g., 'admin', 'user', 'guest'). If a user attempts to access a resource that they are not authorized for, the API should reject the request. Which authorization model is being implemented here?Systems and Application Security
- 134.A large enterprise is migrating its legacy applications to a cloud-native architecture using microservices. The security team is concerned about ensuring secure communication and authentication between these distributed microservices. Which security pattern is most appropriate for managing identity and access for inter-service communication in this environment?Systems and Application Security
- 135.A software development team is implementing a new microservices architecture. They need a mechanism to securely manage and distribute secrets, such as API keys and database credentials, to different services without hardcoding them into the application code or configuration files. Which of the following solutions would best address this requirement?Systems and Application Security
- 136.A security architect is reviewing the design of a new e-commerce platform. The platform will interact with several third-party payment gateways and shipping providers. To minimize the impact of a potential compromise of any single third-party service, the architect proposes isolating each integration point. Which security principle is the architect applying?Systems and Application Security
- 137.A legacy application is identified as having multiple hardcoded credentials within its source code. A security audit recommends immediate remediation. Given that recompiling and redeploying the entire application is a complex and time-consuming process for a quick fix, which of the following interim mitigation strategies would be the MOST effective to reduce the immediate risk?Systems and Application Security
- 138.A development team is working on an application that requires secure communication between its front-end web server and a back-end API server. Both servers are within the same private network segment, but the data exchanged is highly sensitive. The team wants to ensure that the communication is both encrypted and authenticated. Which protocol combination would be most suitable for this purpose, assuming HTTP is the application layer protocol?Systems and Application Security
- 139.A company is developing a new mobile application that will handle sensitive customer financial data. Due to strict regulatory compliance requirements, the application must ensure end-to-end encryption for all data transmitted between the mobile device and the backend servers. Which protocol is most suitable for achieving this goal?Systems and Application Security
- 140.A software vendor needs to distribute signed software updates to its customers. The customers must be able to verify the authenticity and integrity of the updates before installation. Which cryptographic concept is essential for achieving both authenticity and integrity in this scenario?Systems and Application Security
- 141.A security engineer is designing a secure software development lifecycle (SDLC) for a critical application. They want to ensure that security is integrated at every phase, from requirements gathering to deployment and maintenance. Which of the following is the BEST approach to achieve this 'security by design' philosophy?Systems and Application Security
- 142.A company is migrating its on-premises applications to a cloud environment. As part of the migration, they need to ensure that the virtual machines (VMs) are securely configured and hardened according to industry best practices. Which of the following is a critical step in hardening a cloud-based VM?Systems and Application Security
- 143.During a security audit, it was discovered that an internal web application transmits user session IDs in the URL query string. This practice poses a significant security risk. Which of the following is the primary risk associated with transmitting session IDs in the URL?Systems and Application Security
- 144.A security analyst is hardening a Linux web server. The server hosts a critical application that processes sensitive customer data. The analyst needs to ensure that all non-essential services are disabled and that the system's attack surface is minimized. Which of the following actions best addresses this requirement?Systems and Application Security
- 145.A system administrator is configuring a new web server that will host several customer-facing applications. To prevent attacks where malicious code is injected into the server's memory, potentially leading to arbitrary code execution, the administrator implements Data Execution Prevention (DEP). Which type of attack is DEP specifically designed to mitigate?Systems and Application Security
- 146.A security analyst is reviewing a web application's design for potential vulnerabilities related to user input. The application allows users to submit HTML-formatted comments, which are then displayed to other users. The analyst is concerned about attacks where malicious scripts could be executed in other users' browsers. Which of the following mitigation techniques would be most effective against this specific type of attack?Systems and Application Security
- 147.A software company is developing a new mobile application that will handle sensitive customer data. Before deployment, the application must undergo a thorough security review. The development team wants to identify vulnerabilities in the application's source code without actually executing the code. Which type of security testing would be most appropriate for this requirement?Systems and Application Security
- 148.A penetration tester is evaluating a web application for common vulnerabilities. During the testing phase, they discover that by manipulating a parameter in the URL, they can force the application to display directory listings and even potentially access sensitive configuration files outside of the web root. Which of the following vulnerabilities has the penetration tester most likely identified?Systems and Application Security
- 149.A web application developer is designing a new e-commerce platform. To protect against SQL injection attacks, the developer must ensure that user-supplied input to database queries is handled securely. Which of the following is the most effective defense against SQL injection?Systems and Application Security
- 150.A software development team is adopting a DevSecOps methodology. They want to integrate security checks early and continuously throughout their development pipeline. Which of the following practices is most effective for finding security vulnerabilities within the application's source code before deployment?Systems and Application Security