CertSafari

    Free ISC2 Systems Security Certified Practitioner (SSCP) Sample Questions

    35 free sample questions from our bank of 348+, covering every exam domain, with answers and detailed explanations. Updated August 2026.

    Domain 1: Security Concepts and Practices

    Subdomain 1.4: Document and maintain functional security controls

    1.A security architect is designing controls to protect a new web application. Which of the following are examples of preventative controls? (Select all that apply.)(Select 2)

    1. A.Blocking unauthorized network access with a firewall
    2. B.Detecting suspicious network activity using an IDS
    3. C.Identifying malware on systems through antivirus scans
    4. D.Observing physical premises via security cameras
    5. E.Protecting data confidentiality with encryption
    6. F.Restoring systems from backup tapes after failure
    Show answer & explanation

    Correct answers: A, EBlocking unauthorized network access with a firewall; Protecting data confidentiality with encryption

    • A. Correct. A firewall blocks unauthorized traffic before it reaches the application or network, actively stopping unauthorized access. This is a preventative control designed to prevent malicious or unwanted access attempts in advance.
    • B. Incorrect. An IDS is a detective control because it identifies and alerts on suspicious activity after it occurs or as it is happening. It does not primarily stop traffic from entering the environment.
    • C. Incorrect. Antivirus scanning is primarily a detective control because it identifies malware that has already entered the system. While some antivirus tools can block known threats, scanning itself is about detection, not prevention.
    • D. Incorrect. Security cameras are a detective control because they observe and record activity for later review. They do not prevent physical intrusion from occurring.
    • E. Correct. Encryption protects data confidentiality by preventing unauthorized parties from reading sensitive data. It is a preventative control because it reduces the impact of unauthorized access to data.
    • F. Incorrect. Restoring systems from backup tapes after failure is a corrective or recovery control because it helps return systems to normal after an incident. It does not prevent the incident from occurring.

    Subdomain 1.7: Support and/or implement security awareness and training (e.g., social engineering/phishing/tabletop exercises/awareness communications)

    2.Which of the following is a core component of an effective security awareness and training program?

    1. A.Enforcement of strict password expiration policies every 30 days.
    2. B.Role-based training tailored to specific job functions and risks.
    3. C.Annual penetration testing with publicly released results.
    4. D.Deployment of advanced threat detection systems across the network.
    Show answer & explanation

    Correct answer: BRole-based training tailored to specific job functions and risks.

    • A. Incorrect. While password policies are important, they are a technical or administrative control, not a core element of a security awareness and training program, which focuses on user education and behavior change rather than policy enforcement.
    • B. Correct. Role-based training ensures that employees receive relevant education tailored to their specific job functions, access levels, and associated risks. This tailoring improves relevance, retention, and practical application, making it a fundamental component of an effective awareness program.
    • C. Incorrect. Penetration testing is a technical security assessment activity, not a training or awareness component. Publicly releasing results is also inappropriate as it could expose vulnerabilities and is not a standard practice for awareness programs.
    • D. Incorrect. Advanced threat detection systems are technical safeguards used for monitoring and incident detection. They are not part of a security awareness and training program, which focuses on educating users and changing behavior.

    Subdomain 1.3: Identify and implement security controls

    3.Which of the following is an example of an administrative security control?

    1. A.Firewall
    2. B.Security policy
    3. C.Mantrap
    4. D.Surveillance camera
    Show answer & explanation

    Correct answer: BSecurity policy

    • A. Incorrect. A firewall is a technical security control, as it is a hardware or software solution that enforces network access rules between networks. It is not classified as an administrative control.
    • B. Correct. A security policy is an administrative control because it defines rules, procedures, and guidelines for security, focusing on human behavior and management direction. Administrative controls include policies, standards, procedures, and training.
    • C. Incorrect. A mantrap is a physical security control, designed as a physical barrier to control and monitor access between two areas. It restricts unauthorized entry rather than defining security behavior.
    • D. Incorrect. A surveillance camera is a physical/deterrent control used to monitor and record activity in a specific area. It does not fall under administrative controls, which are management-oriented.

    Subdomain 1.3: Identify and implement security controls

    4.During a quarterly review of user access rights, the security team discovers that a terminated employee's account is still active. What should they do immediately?

    1. A.Disable the account and review the offboarding process.
    2. B.Update the offboarding policy to prevent recurrence.
    3. C.Contact the former employee's supervisor for details.
    4. D.Audit all accounts to find any other active ex-employees.
    Show answer & explanation

    Correct answer: ADisable the account and review the offboarding process.

    • A. Correct. The immediate priority is to disable the account to prevent unauthorized access. After that, reviewing the offboarding process helps identify why the account remained active and prevents future occurrences.
    • B. Incorrect. Updating the offboarding policy is a valuable follow-up action, but it does not address the immediate security risk posed by the still-active account. The account must be disabled first.
    • C. Incorrect. Contacting the supervisor may provide context but does not mitigate the ongoing access risk. The account should be disabled immediately before any further investigation.
    • D. Incorrect. Auditing all accounts is a good proactive measure for broader remediation, but it is not the immediate action needed for the discovered active account. The first step is to disable the terminated user's account.

    Subdomain 1.5: Support and implement asset management lifecycle (i.e., hardware, software, and data)

    5.Which of the following best describes the primary purpose of data retention policies in the context of asset management?

    1. A.Minimize storage costs by routinely deleting data that is no longer actively used.
    2. B.Ensure adherence to legal, regulatory, and organizational mandates for keeping records available.
    3. C.Guarantee that critical data is replicated to offsite locations for disaster recovery purposes.
    4. D.Categorize information based on its confidentiality level and business importance.
    Show answer & explanation

    Correct answer: BEnsure adherence to legal, regulatory, and organizational mandates for keeping records available.

    • A. Incorrect. While minimizing storage costs can be a secondary benefit, it is not the primary purpose of data retention policies. Retention policies focus on how long data must be kept and when it can be disposed of, based on compliance requirements rather than cost alone.
    • B. Correct. Data retention policies are primarily designed to ensure that records are kept for the required period to satisfy legal, regulatory, contractual, and organizational obligations. They also define when data can be securely disposed of once those requirements are met.
    • C. Incorrect. Replicating critical data to offsite locations is a disaster recovery and backup function, not the main purpose of retention policies. Retention addresses how long data must be preserved, not where it is stored for resilience.
    • D. Incorrect. Categorizing information by confidentiality and business value is part of data classification, not retention. Classification helps determine handling requirements, while retention defines the lifecycle and required preservation period of the data.

    Subdomain 1.1: Comply with codes of ethics

    6.An SSCP researcher discovers a zero-day vulnerability in a popular open-source tool. The maintainers ask the SSCP to delay public disclosure by 90 days to develop a patch. According to the (ISC)² Code of Ethics, what is the most appropriate course of action?

    1. A.Immediately publish the vulnerability details to ensure full transparency for the public good.
    2. B.Agree to a coordinated disclosure timeline, allowing the maintainers reasonable time to fix the flaw.
    3. C.Keep the vulnerability secret indefinitely to avoid alarming users and potential attackers.
    4. D.Sell the vulnerability information to a third-party broker to fund further security research.
    Show answer & explanation

    Correct answer: BAgree to a coordinated disclosure timeline, allowing the maintainers reasonable time to fix the flaw.

    • A. Incorrect. The (ISC)² Code of Ethics emphasizes protecting society and acting responsibly. Immediate public disclosure without coordination can lead to exploitation before a patch is available, violating the principle of minimizing harm and acting honorably.
    • B. Correct. The (ISC)² Code of Ethics promotes acting in the best interest of the public and the profession. Coordinated disclosure gives the maintainers reasonable time to develop a patch, reducing risk to users while maintaining transparency and responsibility. This approach balances public safety with ethical disclosure practices.
    • C. Incorrect. Keeping the vulnerability secret indefinitely violates the principle of providing diligent and competent service. It fails to protect the public, as users remain unaware and no remediation is pursued, while attackers may still discover and exploit the flaw.
    • D. Incorrect. Selling vulnerability information to a third-party broker prioritizes profit over public welfare and can increase the risk of exploitation. This is inconsistent with the (ISC)² Code of Ethics, which requires professionals to act in the interest of society and avoid actions that could harm others.

    Subdomain 1.6: Support and/or implement change management lifecycle

    7.Which of the following actions are essential to a proper change management lifecycle?(Select 4)

    1. A.Submitting a Request for Change (RFC) for review.
    2. B.Performing a security impact analysis on changes.
    3. C.Implementing changes directly without any review.
    4. D.Conducting a post-implementation review of changes.
    5. E.Notifying only the IT department about the change.
    6. F.Obtaining approval from the change authority.
    Show answer & explanation

    Correct answers: A, B, D, FSubmitting a Request for Change (RFC) for review.; Performing a security impact analysis on changes.; Conducting a post-implementation review of changes.; Obtaining approval from the change authority.

    • A. Submitting a Request for Change (RFC) for review initiates the formal change management process, documenting the proposed change for evaluation, tracking, and approval. It is a critical first step that ensures proper oversight.
    • B. Performing a security impact analysis identifies risks, dependencies, and potential effects on confidentiality, integrity, and availability. This supports informed decision-making before approval or implementation.
    • C. Implementing changes directly without review bypasses governance, risk assessment, and approval, increasing the likelihood of outages, vulnerabilities, or compliance issues. Change management exists to prevent unapproved changes.
    • D. Conducting a post-implementation review verifies that the change achieved the intended result, identifies any unexpected issues, and helps improve future changes. It validates the effectiveness of the process.
    • E. Notifying only the IT department is insufficient; communication should reach all impacted stakeholders, including security, operations, business owners, and end users, to ensure transparency and accountability.
    • F. Obtaining approval from the change authority is a mandatory control that ensures the change is reviewed, authorized, and aligned with business and security requirements before implementation.

    Subdomain 1.2: Understand security concepts

    8.A financial analyst discovers that quarterly revenue figures in a report have been altered after it was generated. Which mechanism would have best prevented this unauthorized modification?

    1. A.Use digital signatures to verify report integrity.
    2. B.Encrypt the report to prevent unauthorized changes.
    3. C.Implement access controls to restrict report editing.
    4. D.Deploy firewalls to block unauthorized network access.
    Show answer & explanation

    Correct answer: AUse digital signatures to verify report integrity.

    • A. Correct. Digital signatures provide integrity verification by ensuring the report has not been altered after signing. They also authenticate the signer, making unauthorized modifications detectable. If the content changes, signature verification fails, helping prevent undetected unauthorized modification.
    • B. Incorrect. Encryption protects confidentiality by preventing unauthorized reading of the report, but it does not detect or prevent modifications to the data. An encrypted file can still be changed if the attacker has access, and encryption alone would not reveal tampering as effectively as a digital signature.
    • C. Incorrect. Access controls restrict who can edit the report, but they do not provide cryptographic assurance that the report has not been modified. If permissions are bypassed or a privileged user changes the file, access controls alone may not detect the alteration.
    • D. Incorrect. Firewalls are designed to control network traffic and help prevent unauthorized network access, but they do not protect the integrity of a report after it has been generated. They are not a mechanism for detecting or preventing content tampering in a document.

    Subdomain 1.8: Collaborate with physical security operations (e.g., data center/facility assessment, badging and visitor management, personal device restrictions)

    9.Which of the following is the most effective physical security measure to enforce a personal device restriction policy in a sensitive lab?

    1. A.Provide lockers at the lab entrance to store personal devices before entry.
    2. B.Post additional warning signs inside the lab emphasizing the prohibition.
    3. C.Configure the Wi-Fi network to block all non-company device MAC addresses.
    4. D.Have managers issue written warnings to employees caught violating the policy.
    Show answer & explanation

    Correct answer: AProvide lockers at the lab entrance to store personal devices before entry.

    • A. Correct. Providing lockers at the lab entrance is a preventive physical control that directly enforces the policy by requiring employees to store personal devices before entering. This reduces the risk of unauthorized devices being brought into the sensitive area.
    • B. Incorrect. Posting warning signs is an administrative/deterrent control, not a physical barrier. It relies on awareness and compliance but does not physically prevent devices from entering the lab.
    • C. Incorrect. Configuring Wi-Fi to block MAC addresses is a technical control that only affects network connectivity, not physical presence. Personal devices can still be carried into the lab even if they cannot connect to the network.
    • D. Incorrect. Issuing written warnings is a reactive administrative control that addresses violations after they occur. It does not prevent devices from entering the lab in the first place.

    Domain 2: Access Controls

    Subdomain 2.2: Understand and support internetwork trust architectures

    10.A cloud-based productivity suite allows third-party add-ins to extend functionality. Which security concern is most critical when users install such extensions?

    1. A.Extensions may require excessive data permissions
    2. B.Extensions increase the cost of licensing
    3. C.Extension interfaces degrade user experience
    4. D.Extensions require frequent manual updates
    Show answer & explanation

    Correct answer: AExtensions may require excessive data permissions

    • A. Correct. Third-party extensions often request broad permissions to access sensitive data such as mail, files, or contacts, which can exceed what is necessary for their stated purpose. Excessive permissions create the highest risk because a malicious or compromised add-in can exfiltrate data or abuse the trusted context within the productivity suite.
    • B. Incorrect. While licensing costs may be a financial or operational consideration, they are not a security concern. The question asks specifically about the most critical security risk, and cost does not directly affect confidentiality, integrity, or availability.
    • C. Incorrect. User experience degradation is a usability issue, not a security risk. Security evaluation should focus on data protection, access control, and the potential for misuse of privileged data, not interface performance.
    • D. Incorrect. While outdated extensions can pose security risks, the need for frequent manual updates is primarily an operational or maintenance issue. The most critical concern remains the permissions and data access granted to extensions at installation time.

    Subdomain 2.4: Understand and administer access controls

    11.Which of the following are privileged access management (PAM) best practices?(Select 4)

    1. A.Just-in-time elevation of privileges
    2. B.Password vaulting for privileged accounts
    3. C.Recording and monitoring of sessions
    4. D.Role-based access control across applications
    5. E.Automatic discovery of privileged accounts
    6. F.Single sign-on to all corporate resources
    Show answer & explanation

    Correct answers: A, B, C, EJust-in-time elevation of privileges; Password vaulting for privileged accounts; Recording and monitoring of sessions; Automatic discovery of privileged accounts

    • A. Correct. Just-in-time elevation of privileges is a PAM best practice that grants temporary elevated access only when needed, reducing the risk of standing privileges being exploited.
    • B. Correct. Password vaulting for privileged accounts is a core PAM practice that securely stores, rotates, and controls access to privileged credentials, preventing hardcoding or sharing of passwords.
    • C. Correct. Recording and monitoring of sessions is a PAM best practice that provides audit trails and accountability for actions taken with privileged access.
    • D. Incorrect. Role-based access control (RBAC) across applications is a general access control mechanism, not a PAM-specific best practice, though it can complement PAM.
    • E. Correct. Automatic discovery of privileged accounts is a PAM best practice that helps identify and manage all accounts with elevated permissions across the environment.
    • F. Incorrect. Single sign-on (SSO) to all corporate resources is an identity and access management (IAM) practice, not a PAM-specific best practice, though it can integrate with PAM solutions.

    Subdomain 2.3: Support and/or implement the identity management lifecycle

    12.What is the best practice for granting a contractor temporary access to organizational resources while adhering to the principle of least privilege?

    1. A.Create a single user account with default group memberships only
    2. B.Manually assign individual permissions to the contractor's account directly
    3. C.Create a user account and assign predefined roles that map to required resources
    4. D.Grant the contractor temporary administrative privileges and revoke them later
    Show answer & explanation

    Correct answer: CCreate a user account and assign predefined roles that map to required resources

    • A. Incorrect. Creating a single user account with default group memberships does not ensure the principle of least privilege and may grant access that is too broad or insufficient for the contractor's role. Default groups often include broad permissions not tailored to specific needs.
    • B. Incorrect. Manually assigning individual permissions is difficult to manage, error-prone, and does not scale well. It also increases the risk of privilege creep and misconfiguration.
    • C. Correct. Creating a user account and assigning it to predefined roles aligns with role-based access control (RBAC) and the principle of least privilege. This standardizes access, simplifies administration, and supports identity lifecycle management.
    • D. Incorrect. Granting temporary administrative privileges exceeds what is normally needed for a contractor and violates least privilege. Administrative access should be limited, monitored, and used only when absolutely necessary, not as a default onboarding method.

    Subdomain 2.1: Implement and maintain authentication methods

    13.A security architect wants to use a Trusted Platform Module (TPM) to bind a device's identity to network authentication. Which method is most effective?

    1. A.Store the user's password in the TPM's non-volatile memory and release it to the supplicant upon each login attempt.
    2. B.Generate a device-specific private key within the TPM and use it with a certificate for EAP-TLS authentication, binding the device to the network identity.
    3. C.Use the TPM to measure the boot integrity and send the Platform Configuration Registers (PCR) values to the RADIUS server as an authentication factor.
    4. D.Configure the TPM as a virtual smart card, requiring the user to enter a PIN to release the private key, which is then used for certificate-based authentication.
    Show answer & explanation

    Correct answer: BGenerate a device-specific private key within the TPM and use it with a certificate for EAP-TLS authentication, binding the device to the network identity.

    • A. Incorrect. Storing a password in the TPM and releasing it on each login is insecure; passwords should not be stored in plaintext and the TPM is designed for cryptographic key protection, not password vaulting. This method does not securely bind device identity to network authentication.
    • B. Correct. The TPM can securely generate and protect a device-specific private key. Using this key with a certificate for EAP-TLS authentication provides strong mutual authentication and directly binds the device's hardware identity to the network identity, ensuring the device presenting credentials is the expected one.
    • C. Incorrect. PCR values are measurements of system integrity used for attestation, not standalone authentication factors. Sending them to a RADIUS server does not directly authenticate the device to the network; authentication typically relies on certificates and private keys, not integrity measurements alone.
    • D. Incorrect. While configuring the TPM as a virtual smart card with a PIN is a valid TPM-based authentication method, it involves user interaction and is more about user-plus-device authentication. The question focuses on binding device identity to network authentication, making the direct TPM-backed certificate approach in option B the most precise and effective method.

    Domain 3: Risk Identification, Monitoring and Analysis

    Subdomain 3.1: Understand risk management

    14.An organization is evaluating how to handle the risk of a natural disaster affecting its primary data center. The risk assessment indicates a high impact but a low likelihood. The organization decides to open a secondary data center in a different geographic region and also purchases a comprehensive insurance policy. Which of the following risk treatment strategies are the organization applying? (Select two.)(Select 2)

    1. A.Risk acceptance
    2. B.Risk avoidance
    3. C.Risk mitigation
    4. D.Risk transfer
    5. E.Risk ignorance
    Show answer & explanation

    Correct answers: C, DRisk mitigation; Risk transfer

    • A. Incorrect. Risk acceptance means acknowledging the risk and choosing to retain it without additional controls. The organization is actively implementing a secondary data center and purchasing insurance, so it is not accepting the risk.
    • B. Incorrect. Risk avoidance involves eliminating the risk entirely by not engaging in the activity. Opening a secondary data center does not eliminate the risk; it reduces impact, which is mitigation.
    • C. Correct. Risk mitigation involves reducing the likelihood or impact of a risk. The secondary data center reduces the operational impact of a natural disaster on the primary data center.
    • D. Correct. Risk transfer shifts the financial consequences to a third party. Purchasing insurance transfers the financial impact of the natural disaster to the insurer.
    • E. Incorrect. Risk ignorance is not a valid risk treatment strategy. The organization is actively managing the risk, not ignoring it.

    Subdomain 3.5: Analyze monitoring results

    15.After a DDoS attack, log analysis reveals a consistent surge in UDP traffic from a single source port to multiple destination ports over three hours. Which visualization would BEST help illustrate the attack timeline and impact?

    1. A.A pie chart showing the distribution of affected destination ports during the attack.
    2. B.A heatmap correlating time buckets with the volume of malicious traffic from the source.
    3. C.A real-time dashboard widget highlighting current bandwidth utilization on the network.
    4. D.A static table listing each logged packet’s header fields from the source IP.
    Show answer & explanation

    Correct answer: BA heatmap correlating time buckets with the volume of malicious traffic from the source.

    • A. A pie chart shows proportional distribution at a single point in time but does not capture the attack's progression or volume trends over the three-hour period, making it unsuitable for illustrating timeline and impact.
    • B. A heatmap effectively correlates time intervals with traffic volume, visually illustrating the surge, duration, and intensity of the attack over the three-hour window, making it ideal for depicting the timeline and impact.
    • C. A real-time dashboard widget is designed for current operational awareness and lacks historical context, making it ineffective for post-incident analysis of the attack timeline.
    • D. A static table of packet headers provides detailed forensic data but is poor for quickly discerning trends, timelines, or overall impact, as it lacks visual aggregation.

    Subdomain 3.4: Operate and monitor security platforms (e.g., continuous monitoring)

    16.An organization with multiple branch offices needs to centralize log collection from Windows servers, Linux servers, and network appliances. The security team must balance bandwidth constraints with the need for near real-time analysis. Which log collection approach is most appropriate?

    1. A.Install local log collectors at each branch, forwarding compressed logs hourly to the SIEM.
    2. B.Configure all devices to send syslog messages directly to the central SIEM over the internet.
    3. C.Store logs locally on each device, transferring them only to the central SIEM for alerting.
    4. D.Employ a cloud-based log service with agents installed on each device to collect logs.
    Show answer & explanation

    Correct answer: AInstall local log collectors at each branch, forwarding compressed logs hourly to the SIEM.

    • A. Correct. Installing local log collectors at each branch reduces WAN usage by aggregating, filtering, and compressing logs before forwarding them centrally. Hourly forwarding balances bandwidth constraints with near real-time analysis, as logs are still sent frequently enough for timely monitoring.
    • B. Incorrect. Sending all syslog traffic directly over the internet can overwhelm bandwidth, especially with high log volumes. It also does not account for Windows servers, which typically require agents rather than native syslog, and may expose log data to interception if not properly protected.
    • C. Incorrect. Keeping logs only on devices delays centralized visibility and weakens near real-time monitoring and alerting. It also increases the risk of log loss if a device fails or is compromised before logs are transferred.
    • D. Incorrect. While a cloud-based log service with agents can centralize logs, it does not inherently address bandwidth constraints as effectively as local branch collectors. Continuous agent sending may still consume significant bandwidth, and it introduces management overhead and potential latency.

    Subdomain 3.2: Understand legal and regulatory concerns (e.g., jurisdiction, limitations, privacy)

    17.A company's security policy mandates that employees must not share passwords. An employee, to work more efficiently, shares their password with a coworker, leading to a data leak. Under which legal principle could the company face liability for failing to enforce its own policy?

    1. A.Duty of care
    2. B.Respondeat superior
    3. C.Contributory negligence
    4. D.Vicarious liability
    Show answer & explanation

    Correct answer: ADuty of care

    • A. Correct. Duty of care is the legal obligation to take reasonable steps to prevent foreseeable harm. By failing to enforce its own password-sharing policy, the company may have breached this duty, potentially leading to liability for the data leak.
    • B. Incorrect. Respondeat superior holds employers liable for employees' actions within the scope of employment. The employee's unauthorized password sharing was against policy, so it falls outside the scope, making this principle inapplicable.
    • C. Incorrect. Contributory negligence is a defense that reduces a plaintiff's claim when the plaintiff's own negligence contributed to the harm. It does not create liability for the company; rather, it could be used by a third party against the company to reduce damages.
    • D. Incorrect. Vicarious liability holds an employer liable for an employee's authorized actions. Since the password sharing was unauthorized and violated policy, this principle does not apply.

    Subdomain 3.3: Perform security assessments and vulnerability management activities

    18.Which of the following activities is part of correlating vulnerability scan data with current threat intelligence sources?

    1. A.Confirming vulnerability existence via manual testing
    2. B.Installing patches to fix reported security weaknesses
    3. C.Analyzing business impact if the vulnerability is exploited
    4. D.Producing a detailed report for the change advisory board
    5. E.Correlating scan data with current threat intelligence
    6. F.Creating a remediation ticket for the operations team
    Show answer & explanation

    Correct answer: ECorrelating scan data with current threat intelligence

    • A. Confirming vulnerability existence via manual testing is a validation step, but it does not inherently involve correlating scan data with threat intelligence. While it helps reduce false positives, it focuses on verification rather than enrichment with external threat context.
    • B. Installing patches is a remediation activity that occurs after analysis and prioritization. It is not part of the correlation process, which is an analytical step that combines scan data with threat intelligence to inform prioritization.
    • C. Analyzing business impact is part of risk assessment and prioritization, but it does not involve correlating technical scan data with threat intelligence. It assesses potential damage rather than leveraging external threat context.
    • D. Producing a detailed report for the change advisory board is a governance and change-management activity that may follow correlation, but it is not the act of correlating scan data with threat intelligence itself.
    • E. Correlating scan data with threat intelligence sources is the key activity that enriches vulnerability findings with external context, such as known exploitation, attacker trends, and exploit availability. This directly supports prioritization by identifying which vulnerabilities are most relevant to the current threat landscape.
    • F. Creating a remediation ticket is a workflow and tracking activity that follows assessment and prioritization. It helps assign ownership but does not describe the correlation of scan data with threat intelligence.

    Domain 4: Incident Response and Recovery

    Subdomain 4.2: Understand and support forensic investigations

    19.You need to create a forensic image of a hard drive from a suspect's laptop. To ensure the integrity of the original evidence, what should you use?

    1. A.A software tool that copies files from the drive to your workstation.
    2. B.A write blocker to prevent any modifications to the source drive.
    3. C.A verified encryption algorithm to secure the drive contents.
    4. D.A hardware duplicator that writes the image to a blank drive.
    Show answer & explanation

    Correct answer: BA write blocker to prevent any modifications to the source drive.

    • A. Incorrect. A standard file-copying tool does not perform a bit-for-bit forensic image, so it may miss deleted files, slack space, and unallocated areas. Additionally, such tools can alter metadata or write to the source drive, compromising evidence integrity.
    • B. Correct. A write blocker (hardware or software) prevents any write operations to the source drive during acquisition, ensuring the original evidence remains unaltered. This is a fundamental forensic best practice for maintaining integrity.
    • C. Incorrect. Encryption protects data confidentiality but does not prevent modifications to the source drive during imaging. It cannot stop the operating system or examiner from accidentally writing to the drive, so it does not ensure integrity.
    • D. Incorrect. A hardware duplicator can create a copy, but without a write blocker, the source drive may still be modified during the process. The primary requirement for integrity is write protection, which a duplicator alone does not guarantee.

    Subdomain 4.1: Understand and support incident response lifecycle (e.g., National Institute of Standards and Technology (NIST), International Organization for Standardization (ISO))

    20.After containing a ransomware outbreak, the incident response team needs to ensure the threat is fully removed. According to best practices, what is the most critical step during eradication?

    1. A.Restore encrypted files from the most recent clean backup.
    2. B.Reformat all affected hard drives and reinstall operating systems.
    3. C.Remove all malware and any backdoors or persistence mechanisms.
    4. D.Update endpoint detection signatures to catch the ransomware variant.
    Show answer & explanation

    Correct answer: CRemove all malware and any backdoors or persistence mechanisms.

    • A. Incorrect. Restoring encrypted files from a clean backup is part of the recovery phase, not eradication. Eradication focuses on removing the threat, not restoring data. Restoring data alone does not ensure the ransomware and any associated persistence mechanisms are removed.
    • B. Incorrect. Reformatting and reinstalling operating systems can be an effective remediation action in severe cases, but it is not the most critical step in eradication. The critical requirement is to remove all malicious code and persistence mechanisms, which may be achieved through multiple methods. Reformatting does not guarantee removal of all persistence if not done thoroughly, and it is a more drastic measure than typically necessary.
    • C. Correct. The most critical step in eradication is removing all malware, backdoors, and persistence mechanisms to ensure the threat actor cannot regain access or re-infect the system. This aligns with the NIST incident response framework, which emphasizes eliminating artifacts of the incident before recovery.
    • D. Incorrect. Updating endpoint detection signatures improves future prevention and detection, but it does not eradicate the current infection. This action is part of the lessons learned or preparation phase, not the eradication phase. Best practices require removing the active threat from affected systems first.

    Subdomain 4.3: Understand and support business continuity plan (BCP) and disaster recovery plan (DRP) activities

    21.Which of the following BEST defines Recovery Time Objective (RTO)?

    1. A.The maximum tolerable period in which data might be lost due to a disaster.
    2. B.The maximum time allowed to restore a system after a disaster to avoid unacceptable impact.
    3. C.The point in time to which data must be recovered to resume business operations.
    4. D.The duration a system can be unavailable before the organization declares a disaster.
    Show answer & explanation

    Correct answer: BThe maximum time allowed to restore a system after a disaster to avoid unacceptable impact.

    • A. Incorrect. This describes Recovery Point Objective (RPO), which is the maximum tolerable period of data loss measured in time. RPO defines how far back in time data must be restored, not how quickly a system must be recovered.
    • B. Correct. RTO is the maximum acceptable amount of time a system or service can be down after a disruption before the impact becomes unacceptable. It defines the target time to restore operations and avoid unacceptable impact on business.
    • C. Incorrect. This also describes Recovery Point Objective (RPO), which focuses on the last recoverable point in time for data. It does not define how long recovery should take.
    • D. Incorrect. This describes a threshold for declaring a disaster or a maximum outage tolerance, which relates to business continuity planning but is not the standard definition of RTO. RTO is specifically about the time to restore operations.

    Domain 5: Cryptography

    Subdomain 5.3: Understand and implement secure protocols

    22.What is the primary function of DKIM (DomainKeys Identified Mail)?

    1. A.Encrypts the email content for confidentiality.
    2. B.Verifies the integrity and domain of the email message.
    3. C.Prevents spoofing by checking the sender's IP address.
    4. D.Encrypts SMTP traffic between email servers.
    Show answer & explanation

    Correct answer: BVerifies the integrity and domain of the email message.

    • A. Incorrect. DKIM does not encrypt email content; it is designed for authentication and integrity verification, not confidentiality. Encryption of email content is typically handled by protocols like S/MIME or PGP.
    • B. Correct. DKIM uses a digital signature to verify that the message was authorized by the domain owner and that the content was not altered in transit. This verifies the integrity and domain of the email message, helping to prevent spoofing.
    • C. Incorrect. While DKIM helps prevent spoofing, it does not check the sender's IP address. IP address verification is more closely associated with SPF (Sender Policy Framework).
    • D. Incorrect. DKIM does not encrypt SMTP traffic between email servers. Encryption of SMTP traffic is typically handled by TLS (Transport Layer Security).

    Subdomain 5.1: Understand reasons and requirements for cryptography

    23.Which of the following types of information would most likely require encryption to protect confidentiality?(Select 2)

    1. A.Public financial reports accessible to anyone.
    2. B.Daily work schedules and staff attendance logs.
    3. C.Proprietary research findings and trade secrets.
    4. D.Personal data of data subjects under GDPR.
    Show answer & explanation

    Correct answers: C, DProprietary research findings and trade secrets.; Personal data of data subjects under GDPR.

    • A. Incorrect. Public financial reports are intended for open distribution and accessible to anyone, so confidentiality is not a primary concern. Encryption is unnecessary for such public data.
    • B. Incorrect. Daily work schedules and staff attendance logs are typically internal but not highly sensitive. While some protection may be applied, they generally do not require strong encryption for confidentiality.
    • C. Correct. Proprietary research findings and trade secrets are highly sensitive and valuable. Encryption is commonly used to protect their confidentiality, as unauthorized disclosure could cause competitive harm or financial loss.
    • D. Correct. Personal data of data subjects under GDPR is legally protected and requires appropriate technical measures. Encryption is a key measure to ensure confidentiality and compliance with data protection regulations.

    Subdomain 5.2: Apply cryptography concepts

    24.Which of the following is the most effective control for preserving an immutable archival record of document approval actions?

    1. A.Digital signatures using the approver's private key to sign each document.
    2. B.A trusted timestamp authority to record the exact time of each approval action.
    3. C.Encrypting the document with AES-256 before transmission to protect confidentiality.
    4. D.An immutable audit trail logging all approval actions, modifications, and timestamps.
    5. E.Computing a SHA-256 hash of the document to verify that it has not been altered.
    Show answer & explanation

    Correct answer: DAn immutable audit trail logging all approval actions, modifications, and timestamps.

    • A. Digital signatures provide non-repudiation for individual approvals by linking the signer's identity to the document. However, they do not by themselves create a complete, immutable record of all actions, modifications, and timestamps, making them insufficient for a comprehensive archival record.
    • B. A trusted timestamp authority records the exact time an action occurred, which supports temporal evidence but does not prove the identity of the approver or capture the full history of approval actions and changes.
    • C. Encrypting the document with AES-256 protects confidentiality during transmission or storage, but it does not provide integrity, non-repudiation, or an audit trail of approval actions.
    • D. An immutable audit trail logs all approval actions, modifications, and timestamps in a tamper-evident manner. This provides the most comprehensive record for accountability and long-term archival integrity, making it the best control for preserving an archival record of approval actions.
    • E. A SHA-256 hash verifies that a document has not been altered after a specific point, but it does not identify who approved the document or maintain a chronological history of actions.

    Subdomain 5.4: Understand and support public key infrastructure (PKI) systems

    25.Which of the following are best practices for cryptographic key management in a PKI system?(Select 3)

    1. A.Schedule automated key rotation to periodically replace keys and limit exposure from compromise.
    2. B.Store private keys in an encrypted file on a shared network location for administrator convenience.
    3. C.Protect high-value private keys in a FIPS 140-2 validated hardware security module (HSM).
    4. D.Disable key revocation capabilities to avoid service interruptions and simplify lifecycle management.
    5. E.Formally decommission and securely destroy unused cryptographic keys to prevent unauthorized data access.
    6. F.Standardize on a single symmetric key across all applications to reduce cost and streamline encryption.
    Show answer & explanation

    Correct answers: A, C, ESchedule automated key rotation to periodically replace keys and limit exposure from compromise.; Protect high-value private keys in a FIPS 140-2 validated hardware security module (HSM).; Formally decommission and securely destroy unused cryptographic keys to prevent unauthorized data access.

    • A. Correct. Automated key rotation is a best practice that limits the exposure window if a key is compromised. Regularly replacing keys reduces the risk of long-term misuse and is a standard key management control.
    • B. Incorrect. Storing private keys in an encrypted file on a shared network location increases the attack surface and risk of unauthorized access. Private keys should be stored securely, such as in an HSM or with restricted access controls.
    • C. Correct. Using a FIPS 140-2 validated HSM provides tamper-resistant hardware protection for high-value private keys. HSMs are designed for secure key generation, storage, and cryptographic operations, making this a strong best practice.
    • D. Incorrect. Key revocation is a critical PKI control that allows revoking compromised or untrusted keys. Disabling revocation would create security risks and undermine trust in the PKI, as compromised keys remain valid.
    • E. Correct. Properly decommissioning and securely destroying unused cryptographic keys reduces the attack surface and prevents unauthorized decryption of encrypted data. This is an essential part of the cryptographic key lifecycle.
    • F. Incorrect. Using a single symmetric key across all applications creates a single point of failure and increases the blast radius if the key is compromised. Best practice is to use unique, scoped keys for different systems and data sets.

    Domain 6: Network and Communications Security

    Subdomain 6.1: Understand and apply fundamental concepts of networking

    26.Which protocol provides connectionless communication at the Transport layer of the TCP/IP model, offering low-latency data delivery without error recovery or flow control?

    1. A.TCP
    2. B.UDP
    3. C.IP
    4. D.ICMP
    Show answer & explanation

    Correct answer: BUDP

    • A. Incorrect. TCP is a connection-oriented Transport layer protocol that establishes a session before data transfer and provides reliability through acknowledgments, retransmissions, sequencing, and flow control, which adds overhead and latency.
    • B. Correct. UDP (User Datagram Protocol) is a connectionless Transport layer protocol designed for fast, low-overhead delivery. It does not provide error recovery, retransmission, or flow control, making it suitable for time-sensitive applications where low latency is prioritized over reliability.
    • C. Incorrect. IP (Internet Protocol) operates at the Internet layer (Network layer) of the TCP/IP model, not the Transport layer. It handles addressing and routing of packets but does not provide transport services such as connection management or port-based communication.
    • D. Incorrect. ICMP (Internet Control Message Protocol) is a Network layer protocol used for diagnostic and control purposes (e.g., ping and error reporting). It is not a Transport layer protocol and does not offer connectionless data delivery for general applications.

    Subdomain 6.5: Operate and configure network-based security appliances and services

    27.A financial institution needs to prevent sensitive customer data from being transmitted outside the corporate network via email or USB drives. The security team deploys a data loss prevention (DLP) solution. Which DLP policy component should be configured to accurately identify and block credit card numbers in outbound emails?

    1. A.Define a content detection rule using regular expressions to match credit card number formats like 16-digit sequences, and apply a block action.
    2. B.Implement document fingerprinting to detect partial matches of known sensitive financial forms and quarantine the emails.
    3. C.Use statistical analysis to identify anomalies in outbound email volume that may indicate data exfiltration attempts.
    4. D.Apply a pre-built classifier that leverages machine learning to recognize credit card numbers based on contextual usage.
    Show answer & explanation

    Correct answer: ADefine a content detection rule using regular expressions to match credit card number formats like 16-digit sequences, and apply a block action.

    • A. Correct. Regular expressions (regex) provide precise pattern matching for structured data like credit card numbers, which follow predictable formats (e.g., 16-digit sequences). Pairing regex detection with a block action effectively prevents such data from leaving the network via email.
    • B. Incorrect. Document fingerprinting is designed to detect exact or near-exact matches of entire documents or forms, not individual data elements like credit card numbers embedded in arbitrary email text.
    • C. Incorrect. Statistical analysis monitors volume or behavioral anomalies, which may indicate exfiltration, but it does not inspect content for specific sensitive data patterns like credit card numbers.
    • D. Incorrect. While ML classifiers can identify contextual patterns, credit card numbers are best detected with deterministic pattern matching (regex) for accuracy and reliability. ML is less precise for well-defined structured data.

    Subdomain 6.2: Understand network attacks (e.g., distributed denial of service (DDoS), man-in-the-middle (MITM), Domain Name System (DNS) cache poisoning)

    28.Which of the following accurately describes the difference between an IDS and an IPS?

    1. A.An IDS monitors traffic and generates alerts, while an IPS can also automatically block malicious traffic.
    2. B.An IDS is deployed inline in the network traffic flow, whereas an IPS is typically placed out-of-band as a passive sensor.
    3. C.An IPS relies solely on signature-based detection methods, while an IDS exclusively uses anomaly-based techniques.
    4. D.An IDS is designed to detect external threats, and an IPS is optimized for identifying internal threats.
    Show answer & explanation

    Correct answer: AAn IDS monitors traffic and generates alerts, while an IPS can also automatically block malicious traffic.

    • A. Correct. An IDS passively monitors network traffic and generates alerts when suspicious activity is detected, but does not take action. An IPS, however, is deployed inline and can automatically block or mitigate malicious traffic in real-time.
    • B. Incorrect. This reverses the typical deployment models. An IDS is usually placed out-of-band as a passive sensor, while an IPS is deployed inline to actively prevent attacks.
    • C. Incorrect. Both IDS and IPS can use a combination of signature-based, anomaly-based, and other detection methods. Neither is limited to a single technique.
    • D. Incorrect. IDS and IPS are not defined by whether they protect against external versus internal threats. Both can detect and respond to malicious activity from either source.

    Subdomain 6.7: Secure and monitor Internet of Things (IoT) (e.g., configuration, network isolation, firmware updates, End of Life (EOL) management)

    29.Which of the following is the most effective method to mitigate the security risk of hard-coded credentials in IoT devices?

    1. A.Replace the hard-coded credentials with a Public Key Infrastructure (PKI) using device-specific certificates for authentication.
    2. B.Encrypt all communications using IPsec to protect credentials in transit from interception.
    3. C.Implement a multi-factor authentication solution that requires a one-time password in addition to the credential.
    4. D.Establish an automated process to remotely rotate the hard-coded passwords on a regular schedule.
    Show answer & explanation

    Correct answer: AReplace the hard-coded credentials with a Public Key Infrastructure (PKI) using device-specific certificates for authentication.

    • A. Correct. Replacing hard-coded credentials with PKI-based device certificates eliminates static secrets, providing each device with a unique identity. This is a stronger and more scalable approach for IoT authentication and reduces the risk of credential compromise.
    • B. Incorrect. Encrypting communications with IPsec protects credentials in transit, but does not address the underlying problem of hard-coded credentials stored on the device. The credentials remain vulnerable if the device is compromised or if secrets are extracted locally.
    • C. Incorrect. Multi-factor authentication adds a security layer but does not resolve the issue of hard-coded embedded credentials. It is often difficult to implement on IoT devices, and the fixed secret remains a vulnerability.
    • D. Incorrect. Automated password rotation may reduce exposure for ordinary accounts, but hard-coded credentials are typically embedded in firmware or configuration and cannot be easily rotated. The proper remediation is to eliminate the hard-coded secret entirely.

    Subdomain 6.3: Manage network access controls

    30.A university wants to ensure that only student laptops with current patches and antivirus software can access the campus network. Which of the following approaches best implements this requirement?

    1. A.Install a NAC agent on each student laptop that evaluates compliance and sends results to a policy server, with RADIUS used to enforce access decisions.
    2. B.Deploy a VPN concentrator at the network edge that intercepts traffic and uses deep packet inspection to verify patch levels and antivirus status.
    3. C.Configure a firewall rule to permit access only for devices whose MAC addresses are on a pre-approved list, assuming those devices are compliant.
    4. D.Set up a captive web portal that redirects unauthenticated users and asks them to confirm that their laptop is patched and running antivirus.
    Show answer & explanation

    Correct answer: AInstall a NAC agent on each student laptop that evaluates compliance and sends results to a policy server, with RADIUS used to enforce access decisions.

    • A. Correct. Network Access Control (NAC) agents evaluate endpoint compliance (e.g., patch levels, antivirus status) and relay results to a policy server, which then enforces access decisions via RADIUS. This is a robust and automated method for ensuring compliance before granting network access, providing real enforcement based on device health rather than relying on user confirmation.
    • B. Incorrect. A VPN concentrator is designed for secure remote access, not for endpoint posture assessment in a NAC implementation. Deep packet inspection cannot reliably verify patch levels or antivirus status on a host; it is more suited for content inspection rather than compliance checks.
    • C. Incorrect. MAC address filtering is a static and easily spoofed method. It does not verify actual compliance (e.g., patch levels or antivirus status) and is not scalable or secure for dynamic environments like a university network. It assumes devices are compliant without validation.
    • D. Incorrect. A captive web portal relies on user self-reporting, which is not trustworthy for ensuring compliance. Users may lie or be unaware of their device's status, making this method ineffective for enforcing security policies. It does not provide real device posture validation or enforce access based on verified security state.

    Subdomain 6.4: Manage network security

    31.What is the most effective method to inspect and control traffic between virtual machines on the same hypervisor?

    1. A.Installing the virtual firewall as a guest VM with dedicated virtual NICs in promiscuous mode
    2. B.Placing the firewall inline in the virtual switch via a bridge or traffic steering
    3. C.Configuring the virtual firewall in passive mode using a SPAN port on the virtual switch
    4. D.Routing all VM traffic through a physical firewall via default gateway settings
    Show answer & explanation

    Correct answer: BPlacing the firewall inline in the virtual switch via a bridge or traffic steering

    • A. Incorrect. Installing the virtual firewall as a guest VM with dedicated virtual NICs in promiscuous mode allows it to see traffic but does not reliably place it in the traffic path. Promiscuous mode may allow visibility, but it does not enforce inline inspection unless traffic is explicitly steered through the firewall. This method does not guarantee all traffic is inspected or controlled.
    • B. Correct. Placing the firewall inline in the virtual switch via a bridge or traffic steering positions it directly in the path of both east-west and north-south VM traffic. This ensures all traffic must pass through the firewall for inspection and enforcement of security policies, making it the most effective method for traffic inspection and control.
    • C. Incorrect. Configuring the virtual firewall in passive mode using a SPAN port on the virtual switch allows monitoring and detection but does not enforce security policies or inspect traffic in real-time. Since the requirement is to inspect and control traffic, passive mode is insufficient; inline enforcement is needed.
    • D. Incorrect. Routing all VM traffic through a physical firewall via default gateway settings may work for north-south traffic but is less efficient for same-host east-west traffic, which can bypass the physical network entirely. This approach introduces latency and does not leverage the benefits of a virtual firewall placed inline within the host.

    Domain 7: Systems and Application Security

    Subdomain 7.4: Understand and configure cloud security

    32.Which cloud deployment model is designed for use by a group of organizations that have shared concerns, such as specific security or compliance requirements?

    1. A.Public
    2. B.Private
    3. C.Hybrid
    4. D.Community
    Show answer & explanation

    Correct answer: DCommunity

    • A. Incorrect. A public cloud is owned and operated by a third-party provider and delivers services to the general public or large industry groups. It does not specifically cater to organizations with shared concerns; it is a multi-tenant environment open to anyone.
    • B. Incorrect. A private cloud is dedicated to a single organization and is not shared with other entities, even if they have shared concerns. It focuses on exclusive use and control by one organization.
    • C. Incorrect. A hybrid cloud combines two or more distinct cloud deployment models (e.g., public and private) to allow data and application portability. It does not inherently imply sharing among multiple organizations with shared concerns; it is an architectural composition rather than a model for shared governance.
    • D. Correct. A community cloud is a deployment model where the infrastructure is shared by several organizations that have common concerns, such as mission, security requirements, policy, or compliance considerations. It is designed to meet the specific needs of a group with aligned objectives.

    Subdomain 7.2: Implement and operate endpoint device security

    33.Which of the following endpoint security controls primarily monitors host activity and alerts administrators to potential threats, but does not automatically block or prevent malicious actions?

    1. A.Host-based intrusion detection system (HIDS)
    2. B.Host-based intrusion prevention system (HIPS)
    3. C.Host-based firewall for traffic filtering
    4. D.Application whitelisting to block unapproved software
    Show answer & explanation

    Correct answer: AHost-based intrusion detection system (HIDS)

    • A. Correct. A Host-based Intrusion Detection System (HIDS) monitors and analyzes system activity, logs, and events on an endpoint to detect signs of malicious behavior or policy violations. It does not take automated actions but alerts administrators, making it a detective control.
    • B. Incorrect. A Host-based Intrusion Prevention System (HIPS) also monitors host activity, but its primary function is to actively prevent or block detected threats in real time. It is a preventive control, not solely a detective one.
    • C. Incorrect. A host-based firewall controls incoming and outgoing network traffic based on rules, focusing on traffic filtering rather than analyzing system activity for malicious behavior. It does not monitor host-level activity beyond network traffic.
    • D. Incorrect. Application whitelisting allows only pre-approved applications to execute, blocking unauthorized software. It is a preventive control and does not monitor or analyze system activity for ongoing threats.

    Subdomain 7.3: Endpoint detection and response (EDR)

    34.An organization is deploying an endpoint detection and response (EDR) solution. Which activity does EDR primarily enhance?

    1. A.Blocking all incoming network traffic at the perimeter
    2. B.Real-time endpoint monitoring and analysis for threats
    3. C.Encrypting sensitive data stored on endpoints
    4. D.Managing user access controls and authentication
    Show answer & explanation

    Correct answer: BReal-time endpoint monitoring and analysis for threats

    • A. Incorrect. Blocking all incoming network traffic at the perimeter is a firewall or network-based security function, not an EDR capability. EDR focuses on monitoring and responding to threats on endpoints, not on perimeter traffic filtering.
    • B. Correct. EDR solutions provide real-time monitoring, detection, and analysis of endpoint activity to identify threats and support response actions. They collect endpoint telemetry and help security teams investigate and contain malicious behavior.
    • C. Incorrect. Encrypting sensitive data on endpoints is a data protection function (e.g., full-disk encryption), not the primary purpose of EDR. EDR is centered on threat detection and response.
    • D. Incorrect. Managing user access controls and authentication is handled by IAM solutions (e.g., MFA, SSO), not EDR. EDR monitors endpoint behavior for signs of compromise rather than managing identities.

    Subdomain 7.5: Operate and maintain secure virtual environments

    35.Which of the following is the best approach for managing and securing corporate applications on employee-owned devices?

    1. A.Mobile Device Management (MDM) with full device encryption
    2. B.Mobile Application Management (MAM) with application-level policies
    3. C.Virtual Desktop Infrastructure (VDI) with thin client access
    4. D.Containerization using a Type 2 hypervisor on mobile devices
    Show answer & explanation

    Correct answer: BMobile Application Management (MAM) with application-level policies

    • A. Incorrect. Mobile Device Management (MDM) with full device encryption manages the entire device, including personal data, which is often undesirable for BYOD scenarios. While it provides device-wide encryption, it does not offer application-level isolation or a virtualized environment for specific applications.
    • B. Correct. Mobile Application Management (MAM) with application-level policies enables organizations to manage and secure specific corporate applications and their data on a user's personal device without controlling the entire device. It provides application-level isolation, policy enforcement, and aligns with secure virtual/containerized app environments, making it the best choice for operating and maintaining secure virtual environments on personal devices.
    • C. Incorrect. Virtual Desktop Infrastructure (VDI) with thin client access delivers a full remote desktop from a centralized server, but it does not address application-level management on a user's personal device. It is more suited for centralized desktop virtualization rather than managing individual applications on mobile or personal devices.
    • D. Incorrect. Containerization using a Type 2 hypervisor is not a typical approach for mobile device application isolation. Type 2 hypervisors run on top of a host operating system and are used for virtual machines, not for application containers. This option mixes technologies inaccurately and is not the best answer for secure virtual environments on personal devices.

    Want the full experience?

    These are just samples. Practice the full ISC2 Systems Security Certified Practitioner (SSCP) question bank in quiz mode — free, no signup, with domain practice and exam simulation.