SSCP Systems Security Certified Practitioner practice questions
226 free questions with answers and explanations.
- 201.A company is implementing a new BYOD (Bring Your Own Device) policy. To ensure that personal devices accessing corporate resources maintain a minimum security posture without directly managing the device's operating system, which of the following solutions would be MOST appropriate?Security Operations and Administration
- 202.A security team is conducting a vulnerability assessment of an internal web application. They discover a critical SQL injection vulnerability that could allow an attacker to bypass authentication. Which of the following is the MOST appropriate immediate action to take after confirming the vulnerability?Security Operations and Administration
- 203.A small business is setting up its first server room and needs to ensure physical security for its critical systems. Which of the following is the MOST important initial physical security control to implement for restricting access to the server room?Security Operations and Administration
- 204.A security operations center (SOC) analyst observes a significant increase in failed login attempts originating from various external IP addresses targeting the organization's VPN gateway. This activity occurs during off-hours and targets common usernames. Which type of attack is MOST likely occurring?Security Operations and Administration
- 205.A security administrator is configuring a new firewall for a data center. The policy states that all outbound connections to the internet should be explicitly denied by default, and only specific, necessary services should be allowed. Which firewall rule configuration approach does this describe?Security Operations and Administration
- 206.A security team is implementing a new security awareness program. They want to ensure that the training content is relevant and engaging for different departments, considering their varied roles and technical backgrounds. Which adult learning principle is MOST directly addressed by tailoring the training content?Security Operations and Administration
- 207.A company has recently experienced a data breach due to a phishing attack. As part of the post-incident activities, the security team is reviewing the incident to understand what happened, why it happened, and how to prevent similar incidents in the future. Which of the following best describes this phase?Security Operations and Administration
- 208.During a security incident, a forensic investigator needs to collect volatile data from a compromised server. Which of the following data types should be collected FIRST due to its ephemeral nature?Security Operations and Administration
- 209.A company is developing a new web application that will handle sensitive customer data. Before deployment, a security team conducts a thorough review to identify potential vulnerabilities by simulating attacks from the perspective of a malicious actor without prior knowledge of the internal system. Which type of security assessment is being performed?Security Operations and Administration
- 210.A security auditor is reviewing an organization's change management process. The auditor notes that changes to critical production systems are sometimes implemented without a formal review by a separate, independent team. Which principle of security operations is MOST directly violated by this practice?Security Operations and Administration
- 211.A security team is conducting a vulnerability scan on a web application. The scan identifies several potential SQL injection vulnerabilities. Which of the following phases of the incident response life cycle would these findings primarily inform?Security Operations and Administration
- 212.A security architect is designing a secure network for a new cloud-based application. The architect wants to ensure that all traffic entering and leaving the application's subnet is inspected and filtered based on a set of predefined security rules. Which security control would best fulfill this requirement?Security Operations and Administration
- 213.A security analyst is investigating a suspected malware infection on a critical server. The analyst needs to quickly isolate the server from the network to prevent further spread while ensuring that forensic data can still be collected. Which of the following actions is the MOST appropriate initial step?Security Operations and Administration
- 214.A security team is developing an incident response plan. They are currently defining procedures for containing an incident once it has been detected and analyzed. Which of the following actions is a primary objective during the containment phase?Security Operations and Administration
- 215.An organization is developing a new critical application and is concerned about the security of its supply chain, particularly the third-party components and libraries used. To ensure these components do not introduce known vulnerabilities, which of the following practices should be integrated into the development lifecycle?Security Operations and Administration
- 216.A security auditor is reviewing an organization's access control policies. The auditor notes that a single administrator has the authority to create user accounts, assign permissions, and approve access requests for critical systems. This situation violates which key security principle?Security Operations and Administration
- 217.An organization is preparing for an upcoming regulatory compliance audit. The auditor requests evidence of regular security control effectiveness testing. The security manager needs to provide documentation demonstrating that the implemented controls are working as intended against known attack patterns and vulnerabilities. Which type of assessment would BEST fulfill this request?Security Operations and Administration
- 218.A security incident response team is conducting a forensic analysis of a compromised workstation. They need to collect volatile data quickly before the system is powered off or rebooted. Which of the following data types should be prioritized for collection due to its highly volatile nature?Security Operations and Administration
- 219.A security team is implementing a new security policy that dictates all remote access to internal resources must use multi-factor authentication (MFA). Which of the following components of a security policy framework does this specific requirement fall under?Security Operations and Administration
- 220.An organization is implementing a new security awareness training program. To ensure the program is effective and meets compliance requirements, the security manager wants to verify that all employees understand their roles and responsibilities regarding data protection. Which of the following is the MOST effective method to achieve this goal?Security Operations and Administration
- 221.A security manager is tasked with establishing a new security policy for remote access. The policy must ensure that all devices connecting to the corporate network from outside the perimeter meet specific security benchmarks, such as up-to-date antivirus definitions and operating system patches, before being granted access. Which technology is BEST suited to enforce this policy?Security Operations and Administration
- 222.A security analyst observes multiple failed login attempts originating from a single IP address against an organization's SSH server. The attempts are occurring rapidly, targeting various common usernames. Which of the following best describes this type of attack?Risk Identification, Monitoring, and Analysis
- 223.A security administrator is configuring access controls for a new project management system. The system requires that only users in the 'Project Managers' group can create new projects, while users in the 'Project Team' group can only view and update existing project tasks. Which access control model is MOST appropriate for implementing these granular permissions?Security Operations and Administration
- 224.A financial institution is implementing a new customer authentication system. They require customers to enter a username and password, then receive a one-time passcode (OTP) via a registered mobile device, and finally, answer a security question from a pre-defined list. This combination satisfies which authentication concept?Access Controls
- 225.A security operations center (SOC) analyst observes unusual outbound network traffic from an internal server to an unknown external IP address. The traffic pattern is consistent with data exfiltration, but the server is not authorized to initiate external connections. Which of the following security controls would BEST prevent this type of communication in the future?Security Operations and Administration
- 226.A security administrator is configuring access for a new human resources application. The policy states that only HR managers can approve leave requests, but only if the request is for an employee within their direct reporting structure and the requested leave period does not conflict with critical project deadlines. Which access control mechanism best describes this scenario?Access Controls