SSCP Systems Security Certified Practitioner practice questions
226 free questions with answers and explanations.
- 151.A developer is writing code for a new payment processing module. To prevent buffer overflow vulnerabilities, which programming practice should be strictly followed, especially when handling user input or external data?Systems and Application Security
- 152.A financial institution is developing a new online banking application. They require a robust mechanism to ensure the integrity and authenticity of transactions, preventing both accidental alteration and malicious tampering of data during transmission. Which cryptographic control would be most appropriate for this requirement?Systems and Application Security
- 153.A security architect is designing a system that requires the highest level of assurance for user identity verification before granting access to sensitive data. The system must confirm the user's identity based on something they know, something they have, and something they are. Which authentication mechanism meets these requirements?Systems and Application Security
- 154.A company is implementing a new customer relationship management (CRM) system. To comply with data privacy regulations, all personally identifiable information (PII) stored in the database must be protected even if the database itself is compromised. Which cryptographic control best ensures PII confidentiality at rest in this scenario?Systems and Application Security
- 155.A developer is writing a RESTful API for a new mobile application. The API needs to enforce access control based on the user's role (e.g., 'admin', 'user', 'guest'). If a user attempts to access a resource that they are not authorized for, the API should reject the request. Which authorization model is being implemented here?Systems and Application Security
- 156.A large enterprise is migrating its legacy applications to a cloud-native architecture using microservices. The security team is concerned about ensuring secure communication and authentication between these distributed microservices. Which security pattern is most appropriate for managing identity and access for inter-service communication in this environment?Systems and Application Security
- 157.A software development team is implementing a new microservices architecture. They need a mechanism to securely manage and distribute secrets, such as API keys and database credentials, to different services without hardcoding them into the application code or configuration files. Which of the following solutions would best address this requirement?Systems and Application Security
- 158.A security architect is reviewing the design of a new e-commerce platform. The platform will interact with several third-party payment gateways and shipping providers. To minimize the impact of a potential compromise of any single third-party service, the architect proposes isolating each integration point. Which security principle is the architect applying?Systems and Application Security
- 159.A network security engineer is designing a secure wireless network for a critical operational technology (OT) environment. The design requires mutual authentication between wireless clients and the access points, along with strong encryption that can resist future cryptanalysis. Which EAP method, combined with WPA3, would best fulfill these requirements?Network and Communications Security
- 160.A large multinational corporation is integrating its diverse, geographically dispersed identity management systems. The goal is to allow employees to use their corporate credentials from their home domain to authenticate to applications hosted in another domain (e.g., an employee from the European division logging into an application hosted by the Asian division) without creating duplicate accounts. Which of the following identity and access management concepts is best suited for this requirement?Access Controls
- 161.A network administrator is setting up a new wireless network and wants to hide the network's presence from casual users. Which of the following actions would best achieve this goal, though it is not considered a strong security measure?Network and Communications Security
- 162.A security team is implementing a network access control (NAC) solution. The primary goal is to ensure that only devices compliant with the organization's security posture (e.g., up-to-date antivirus, OS patches) are allowed to connect to the corporate network. Which NAC deployment model is best suited for real-time assessment and enforcement before granting full network access?Network and Communications Security
- 163.A security technician is investigating a network performance issue where legitimate users are experiencing slow access to a critical web application. Analysis shows an abnormally high number of half-open TCP connections to the web server. Which type of attack is likely occurring, and what is the common mitigation strategy?Network and Communications Security
- 164.A security analyst is investigating a network where an attacker is attempting to overwhelm a web server by sending a flood of HTTP GET requests from multiple compromised machines. Which type of attack is this, and what is its primary objective?Network and Communications Security
- 165.A company requires its employees to use a physical smart card containing a digital certificate, along with a personal identification number (PIN), to log in to their workstations. This system aims to enhance security beyond a simple password. Which of the following authentication methods is being employed?Access Controls
- 166.A security technician is investigating a wireless network where clients are frequently experiencing disconnections and poor performance. The technician suspects interference from other wireless devices operating on the same frequency channels. Which of the following tools or techniques would be most effective in identifying and mitigating this issue?Network and Communications Security
- 167.A security auditor discovers that a company's internal network uses unmanaged switches and is susceptible to Layer 2 attacks, such as MAC flooding and ARP poisoning. Which of the following security controls would most effectively mitigate these types of attacks?Network and Communications Security
- 168.A security engineer is designing a secure network architecture. The design includes a perimeter network (DMZ) to host public-facing servers, which must be accessible from the internet but isolated from the internal corporate network. What is the primary purpose of implementing a DMZ in this scenario?Network and Communications Security
- 169.A network security engineer is configuring a wireless network for a critical industrial control system (ICS). Due to the sensitive nature of the data and the need for strict authentication, the engineer wants to use the strongest available encryption and authentication protocols. Which combination of protocols should be selected?Network and Communications Security
- 170.A network administrator is configuring a new wireless access point (WAP) for a small office. The administrator wants to prevent unauthorized devices from connecting to the network by filtering based on hardware addresses. Which of the following security features should the administrator enable?Network and Communications Security
- 171.A security architect is designing a network for a new branch office. The design includes a perimeter firewall that must inspect all inbound and outbound traffic, perform deep packet inspection, and apply application-aware policies. Which type of firewall is best suited for these advanced security requirements?Network and Communications Security
- 172.A new employee is onboarding, and the HR department needs to grant them access to various internal systems. Instead of manually creating accounts and assigning permissions in each system, HR uses a centralized identity management system that automatically provisions the necessary accounts and assigns default roles based on the employee's department and job title. What concept is being demonstrated by this automated process?Access Controls
- 173.A security administrator is configuring access for a new network-attached storage (NAS) device. The policy states that only members of the 'Finance' group should have read and write access to the 'Budgets' share, while all other authenticated users should have no access. Which of the following access control models is being primarily implemented?Access Controls
- 174.A security auditor discovers that several network devices, including switches and routers, are configured with default community strings for SNMPv1. The auditor recommends upgrading to a more secure version. Which SNMP version provides encryption for messages and stronger authentication mechanisms?Network and Communications Security
- 175.A network administrator needs to implement a secure solution for remote access to the corporate network for employees working from home. The solution must ensure confidentiality and integrity of all transmitted data and support a wide range of client operating systems without requiring specialized client software beyond what is typically available in modern browsers. Which VPN technology would be the most suitable?Network and Communications Security
- 176.A company is setting up a guest wireless network. Policy dictates that guest users should only have internet access and be strictly isolated from the internal corporate network resources. Which of the following network configurations would effectively achieve this isolation?Network and Communications Security
- 177.A company is implementing a new voice over IP (VoIP) system and needs to ensure that voice traffic receives priority over other network traffic to maintain call quality. Which Quality of Service (QoS) mechanism is most appropriate for marking and prioritizing this time-sensitive traffic?Network and Communications Security
- 178.A network administrator is troubleshooting an issue where a server in the DMZ cannot receive incoming connections from the internet, despite the perimeter firewall having an explicit rule to allow traffic to the server's public IP address on the correct port. Upon further investigation, it is discovered that the server's private IP address is 10.0.0.50, and the public IP address configured on the firewall for this server is 203.0.113.10. Which network service is likely misconfigured or missing, preventing the connections?Network and Communications Security
- 179.A company is implementing a new wireless network that requires strong authentication for all users and devices, along with dynamic encryption keys for each session. Which of the following wireless security protocols is best suited to meet these requirements?Network and Communications Security
- 180.A software development team is building a new application that needs to securely access a database containing customer personal identifiable information (PII). The security policy dictates that the application should only be able to retrieve the specific PII fields absolutely necessary for its function (e.g., name and email, but not home address or phone number) and only when a specific, authorized request is made. This principle aims to minimize the potential impact of a data breach. Which security principle is being applied?Access Controls
- 181.A company is deploying a new application that requires high availability and resilience against network outages. The application servers are located in two different data centers. To ensure that user traffic is directed to the optimal server and automatically fails over in case of an issue, which network service would be most appropriate?Network and Communications Security
- 182.A system administrator needs to secure remote access to internal servers for external contractors. The solution must provide strong encryption for data in transit and allow granular control over which internal resources each contractor can access. Which of the following solutions best meets these requirements?Network and Communications Security
- 183.A security analyst is investigating a network where multiple devices are experiencing intermittent connectivity issues, and a significant amount of unexpected broadcast traffic is observed. The network uses a flat topology without VLANs. Which of the following network security concepts is most directly violated by this configuration, leading to the observed issues?Network and Communications Security
- 184.A network administrator is configuring a new firewall rule to allow specific internal servers to initiate outbound connections to a web service hosted on the internet on a non-standard port, 8443. Which of the following firewall rules would correctly permit this communication while adhering to the principle of least privilege?Network and Communications Security
- 185.A system architect is designing an access control system for a highly sensitive research laboratory. The policy prohibits any subject from writing to an object at a lower security level (no write-down) and also prevents reading from an object at a higher security level (no read-up). This design is intended to prevent information flow from higher to lower sensitivity levels. Which specific access control model property is being implemented?Access Controls
- 186.A network administrator is configuring a firewall to allow only secure web traffic (HTTPS) from the internal network to external web servers. Which of the following port numbers must be explicitly allowed in the outbound firewall rule?Network and Communications Security
- 187.A company is deploying a new web application that needs to handle a large volume of traffic and remain resilient to single points of failure. The application will be hosted across multiple servers. Which network device is essential for distributing incoming client requests among these servers and ensuring high availability?Network and Communications Security
- 188.A company is experiencing slow network performance and suspects that unauthorized devices are consuming excessive bandwidth. An investigation reveals that several employees have connected personal wireless routers to the corporate network switches, creating rogue access points. Which of the following wireless security measures would be most effective in detecting and locating these unauthorized devices?Network and Communications Security
- 189.A network engineer is configuring a firewall to allow specific traffic. The policy states that only traffic from the internal 'Web Servers' subnet (192.168.10.0/24) should be allowed to access the external 'DMZ Database' server (172.16.1.50) on port 3306. All other traffic to this database server should be denied. What type of authorization mechanism is primarily being used?Access Controls
- 190.A security analyst is investigating a persistent denial-of-service (DoS) attack targeting a web server. The attack involves a flood of SYN packets, causing the server's connection tables to fill up and legitimate connections to be dropped. Which of the following network security devices or features is specifically designed to mitigate this type of attack by acting as a proxy and managing TCP handshakes?Network and Communications Security
- 191.A company policy mandates that all data transmitted over the internal network must be encrypted, even between devices within the same subnet. The existing network infrastructure predominantly consists of managed switches that support various security features. Which of the following technologies would be most appropriate to implement this policy efficiently without requiring a full VPN tunnel for every internal communication?Network and Communications Security
- 192.An organization is implementing a new security awareness training program. To ensure the program is effective, the security manager plans to include interactive modules, real-world examples of phishing emails, and engaging quizzes. Which principle of adult learning is being applied to maximize the program's impact?Security Operations and Administration
- 193.A security team is preparing for a scheduled penetration test against their external-facing web applications. They want to ensure that the penetration testers have no prior knowledge of the internal network architecture, source code, or credentials, simulating a real-world attacker's perspective. Which type of penetration test engagement is being described?Security Operations and Administration
- 194.A security administrator is configuring a new intrusion detection system (IDS). To minimize false positives and focus on critical threats, the administrator wants to train the IDS to recognize normal network traffic patterns. Which detection method would be most suitable for this approach?Security Operations and Administration
- 195.A security administrator is configuring a new firewall for a data center. The policy states that only specific services (HTTP, HTTPS, SSH) are allowed to external networks, and all other traffic is implicitly denied. Which of the following concepts is being applied here?Security Operations and Administration
- 196.A security auditor is reviewing an organization's incident response plan. The auditor notes that the plan includes steps for containment, eradication, and recovery, but lacks clear guidance on how to initially identify and confirm a security breach. Which phase of the incident response process is inadequately addressed?Security Operations and Administration
- 197.A security manager is evaluating various metrics to assess the effectiveness of the organization's security awareness program. Which of the following metrics would provide the MOST direct evidence of improved employee behavior regarding phishing attempts?Security Operations and Administration
- 198.A security analyst is reviewing logs and notices an unusual number of failed login attempts from an external IP address targeting multiple user accounts. After a short period, the attempts stop, but then resume from a different external IP address with the same pattern. Which of the following attack types is most likely occurring?Security Operations and Administration
- 199.A large enterprise is implementing a new endpoint detection and response (EDR) solution across its global network. After initial deployment, security analysts notice a significant increase in the number of alerts generated, many of which are benign activities. This is causing alert fatigue and delaying response to actual threats. Which of the following actions should the security team prioritize to address this issue?Security Operations and Administration
- 200.A security analyst is investigating a potential data exfiltration incident. During the investigation, the analyst discovers that a critical server's log files have been intentionally deleted, hindering the ability to trace the attacker's actions. Which of the following security controls would have been MOST effective in preventing this specific issue?Security Operations and Administration