Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

SSCP Practice Questions

Updated 10 min read
Key takeaway

These original SSCP-style questions practice decisions across the current seven-domain outline.

  • They are not ISC2 exam items and cannot reproduce CAT selection or scoring.
  • For each, choose the best answer before reading the explanation; then review why every alternative fails and which fact would change the response.
On this page21 sections
  1. How to use this set
  2. Question 1. Access lifecycle
  3. Question 2. Monitoring and analysis
  4. Question 3. Incident evidence
  5. Question 4. Cryptographic purpose
  6. Question 5. Network segmentation
  7. Question 6. Risk and vulnerability handling
  8. Question 7. Systems and mobile security
  9. Question 8. Recovery and backup
  10. Review the reasoning
  11. Turn misses into study
  12. What this set does not simulate
  13. Question 9: trust and authentication
  14. Options
  15. Answer: A
  16. Question 10: cryptographic integrity
  17. Options
  18. Answer: A
  19. Question 11: risk treatment
  20. Options
  21. Answer: A

How to use this set

Answer each item before reading the rationale. Identify the task, the control objective, the role authorized to act and any evidence that must be preserved. These are original educational questions, not copied or recalled ISC2 content. The actual SSCP exam uses CAT; this fixed set cannot emulate adaptive selection or predict a scaled result.

For every wrong choice, ask what fact would make it appropriate. That step turns practice into reasoning rather than a memory exercise.

Question 1. Access lifecycle

A contractor’s project ended yesterday. The project manager confirms no further work is scheduled, but the contractor account remains enabled. It has not been used since the end date. What should the practitioner do first?

  • A. Disable the account using approved deprovisioning, verify related access is removed, and preserve the action record.
  • B. Leave it enabled for a month and monitor for use.
  • C. Delete the authentication logs.
  • D. Disable every contractor account immediately.

Correct answer: A. The need has ended and the accountable owner confirms it. Prompt deprovisioning applies least privilege. Verify associated credentials or active sessions as required and preserve the request and action record. B leaves unnecessary access active while waiting for misuse. C destroys evidence and does not remove access. D exceeds the facts: only one account is established. If the end date were uncertain, validate authorization first.

Question 2. Monitoring and analysis

A SIEM flags repeated failed logins followed by a successful privileged login from an unfamiliar location. The account owner is on call but has not yet been reached. What is the best next action?

  • A. Close the alert because failed logins are common.
  • B. Preserve relevant records, validate the event through a trusted channel, assess active sessions and escalate under the incident process.
  • C. Delete the account and wipe the server.
  • D. Email the account password to the owner for confirmation.

Correct answer: B. The sequence warrants investigation, but the stem does not yet confirm compromise. Preserve logs, validate through a trusted channel, assess the account and systems, and escalate. If compromise is confirmed, contain it under the playbook. A assumes the alert is benign. C may destroy evidence and disrupt service before scope is known. D exposes credentials and uses an unsafe verification method. Confirmed active exfiltration would make immediate containment more urgent.

Question 3. Incident evidence

A laptop appears to contain malware. The incident lead asks the first responder to preserve evidence before remediation. Which action best supports that request?

  • A. Reimage the laptop immediately.
  • B. Follow forensic handling procedures, document custody and collection, and preserve relevant data before destructive changes.
  • C. Allow several staff to inspect the disk with personal USB devices.
  • D. Delete suspicious files and report only if the user complains.

Correct answer: B. The incident lead has specified the objective. Follow the evidence-handling procedure, limit access, record transfers and preserve relevant data. A can overwrite artifacts. C introduces uncontrolled handling and may alter the evidence. D destroys data and makes reporting contingent on an irrelevant condition. If active malware is causing immediate harm, containment can happen in coordination with the lead while preserving evidence as feasible.

Question 4. Cryptographic purpose

A service stores passwords using a fast, unsalted hash. The team wants to reduce the risk that a stolen database will reveal users’ passwords. Which change best addresses the problem?

  • A. Encrypt all passwords using one reversible key stored beside the database.
  • B. Use a password-storage function with a unique salt per password and an appropriate work factor, protecting its configuration and secrets.
  • C. Replace hashes with digital signatures made from the passwords.
  • D. Compress the file and restrict archive access.

Correct answer: B. A password-storage function designed to resist offline guessing, with unique salts and an appropriate work factor, makes precomputed attacks less useful and raises guessing cost. A introduces a reversible secret next to the data. C confuses signatures with password verification. D is not cryptographic confidentiality. If the goal were to protect a file in transit, encryption would be relevant; the stated problem is password guessing after database theft.

Question 5. Network segmentation

A development workstation needs access to a test application but has no business need to reach a production database. The network currently permits both paths. What control change best reduces exposure?

  • A. Add a narrowly scoped, approved rule for the required test path and deny the unnecessary production path; log and validate the change.
  • B. Disable network logs.
  • C. Move the database to another subnet but retain unrestricted routing.
  • D. Grant workstation administrator access to the developer.

Correct answer: A. This enforces the actual business need and blocks an unnecessary path. Keep the rule narrow, approved, monitored and validated. B removes visibility without restricting connectivity. C changes the diagram but not the trust boundary. D grants excess privilege and does not solve the network exposure. If the test service is compromised, the restricted rule also limits lateral movement.

Question 6. Risk and vulnerability handling

A vulnerability scan identifies a high-severity issue on an internet-facing application with sensitive customer data. A patch exists but is untested. What is the best immediate response?

  • A. Ignore the issue because a patch is available.
  • B. Assess exposure and impact, involve the owner, test and schedule prompt remediation, and use feasible interim controls and monitoring.
  • C. Install the patch in production without change review.
  • D. Close the finding because remediation is obvious.

Correct answer: B. The risk is urgent, but an untested production change can affect availability. Assess the service and exposure, engage the owner, test the fix, use feasible mitigations and track the risk until remediation is verified. A confuses availability of a patch with completed remediation. C bypasses testing and change control. D confuses a severity label with a closed risk. Confirmed active exploitation could justify emergency action under policy.

Question 7. Systems and mobile security

A work mobile device is lost. It had disk encryption enabled but has not connected to management for several days. What should the administrator do?

  • A. Report and assess the loss, follow the mobile-device process, restrict credentials or sessions as appropriate, and document remote-wipe feasibility.
  • B. Assume encryption makes the incident harmless.
  • C. Delete the employee mailbox.
  • D. Publish the device serial number and employee identity to all staff.

Correct answer: A. Encryption reduces the chance that stored data is readable, but the team must assess cached data, credentials, sessions, device status and management connectivity. Follow the response process and document approved actions. B overstates encryption. C deletes unrelated records and may not revoke access. D discloses personal and asset information unnecessarily. If evidence shows no business data was present, severity may be lower, but assessment is still required.

Question 8. Recovery and backup

A server is restored after ransomware. The application is online, but the team has not checked whether the backup predates compromise or whether privileged credentials were rotated. What must happen before declaring recovery complete?

  • A. Verify the backup and restored system are clean, remediate the compromise path, validate the application and document recovery checks.
  • B. Close the incident because users can connect.
  • C. Delete all older backups.
  • D. Restore every system from the same backup immediately.

Correct answer: A. Availability alone does not prove safe recovery. Confirm the backup is trustworthy, address the compromise path, rotate credentials or keys as needed, validate integrity and monitor for recurrence. B ignores integrity and reinfection. C destroys recovery options without solving the cause. D expands restoration before scope and backup integrity are known. Use the approved recovery plan and business objectives.

Review the reasoning

These questions connect security principles, access management, risk analysis, incident response, cryptography, networks and systems. The best choice usually fits the requested timing, authority and evidence constraints. A control is not automatically appropriate merely because it is technically effective in isolation.

Turn misses into study

For each missed or guessed answer, record the domain, the detail in the stem that mattered, the tempting assumption, and the principle that selects the better response. After a day, try a new scenario on the same concept. If you recall only the wording or answer letter, review the idea again.

What this set does not simulate

The SSCP exam is adaptive, has 25 indistinguishable unscored pretest items, and does not allow review of finalized answers. This set is static practice for knowledge and reasoning, not a CAT simulator, live-item collection, pass predictor or promise of a particular score.

Question 9: trust and authentication

A vendor application uses a federated sign-in. A user can authenticate successfully, but the app grants administrator rights that are not present in the user’s approved role. Which issue should be addressed first?

Options

A. The authorization mapping or entitlement that assigns the excessive role, using the approved identity-management process.

B. The user’s ability to authenticate, because all successful logins are excessive privilege.

C. Disable all federation relationships across the company.

D. Remove authentication logs so the vendor cannot infer the user’s role.

Answer: A

Authentication establishes the identity; authorization determines permissions. The login can be valid while the role mapping is wrong. Restrict the excessive entitlement, preserve evidence and review the federation mapping. B conflates authentication with authorization. C is disproportionate and may disrupt unrelated applications. D removes auditability. If there were evidence of credential theft, the response would also include account compromise investigation.

Question 10: cryptographic integrity

A software vendor signs a security update. Before installation, an administrator wants to confirm both that the package has not changed and that it came from the expected publisher. What should the administrator validate?

Options

A. The digital signature and certificate trust chain, including validity and revocation status under policy.

B. The file name and download size only.

C. A plain hash posted by an unauthenticated sender.

D. The update’s compression ratio.

Answer: A

A valid digital signature can support integrity and publisher authenticity when it chains to a trusted certificate and passes validity checks. The administrator should also follow approved update and change procedures. B and D do not authenticate content. C can detect a mismatch only if the expected hash is obtained through a trustworthy channel; alone it does not prove publisher identity.

Question 11: risk treatment

A department owns an exposed legacy server that cannot be upgraded for two weeks. The business owner approves a temporary exception, but the exception has no end date or interim safeguards. What is the best practitioner response?

Options

A. Record the scope and accountable owner, define an expiration or review date, apply feasible interim safeguards, monitor the exposure and track the planned upgrade.

B. Permanently accept the risk because the owner approved it once.

C. Hide the server from the asset inventory until it is upgraded.

D. Shut down all department servers without assessing impact.

Answer: A

Risk acceptance should be explicit, scoped and monitored. A temporary exception needs an owner, rationale, review or expiry date, interim controls and a remediation plan. B turns temporary approval into indefinite acceptance. C undermines asset management and monitoring. D is disproportionate. If active exploitation is identified, the risk response may require urgent containment or emergency change.

Common questions

Are these actual SSCP exam questions?

No. They are independently written educational questions, not ISC2 items or recalled exam content.

Does this page simulate SSCP CAT?

No. It is fixed practice and cannot reproduce adaptive selection, pretest items or scoring.

How should I review a wrong answer?

Identify the fact that mattered, the mistaken assumption, and why each distractor is weaker.

What domains do these questions cover?

The examples span access, risk and monitoring, incident response, cryptography, networks, systems and security practices.