SSCP Exam Prep Free practice test →

Free SSCP Practice Questions

10 free, exam-style Systems Security Certified Practitioner (SSCP) practice questions with answers and explanations. No signup required. Work through them below, then take the full free SSCP practice test to study every exam domain.

Question 1

A security practitioner at Meridian Health discovers that their employer has been concealing a breach affecting thousands of patient records. The practitioner's manager instructs them to remain silent. According to the ISC2 Code of Ethics, the practitioner should:

  1. Follow the manager's instructions, as Canon III requires diligent service to principals
  2. Report the breach through appropriate channels, as protecting society takes precedence over service to principals
  3. Resign from the position to avoid personal liability
  4. Privately notify affected patients without informing the employer
Show answer & explanation

Correct answer: B - Report the breach through appropriate channels, as protecting society takes precedence over service to principals

Question 2

A defense contractor requires that analysts with 'Secret' clearance can read documents classified at their level or below but cannot write information to any document at a lower classification level. Which security model enforces these restrictions?

  1. Bell-LaPadula
  2. Clark-Wilson
  3. Biba
  4. Brewer-Nash
Show answer & explanation

Correct answer: A - Bell-LaPadula

Question 3

A database server is valued at $500,000. A risk assessment determines that a ransomware attack would damage 30% of the asset's value and is expected to occur approximately twice every five years. What is the Annualized Loss Expectancy (ALE)?

  1. $150,000
  2. $75,000
  3. $300,000
  4. $60,000
Show answer & explanation

Correct answer: D - $60,000

Question 4

A forensic analyst arrives at the scene of a suspected data exfiltration and must collect digital evidence from the compromised workstation. The workstation is still powered on. Following the order of volatility, which evidence should be collected FIRST?

  1. Hard disk image using a write-blocker
  2. Contents of RAM, including running processes and network connections
  3. Remote syslog entries from the centralized log server
  4. Backup tapes stored in the offsite vault
Show answer & explanation

Correct answer: B - Contents of RAM, including running processes and network connections

Question 5

An organization needs to verify that a software update received from a vendor has not been altered during transit AND confirm the identity of the vendor. Which cryptographic mechanism satisfies BOTH requirements?

  1. SHA-256 hash published on the vendor's website
  2. AES-256 encryption of the update package
  3. A digital signature applied by the vendor
  4. An HMAC generated with a pre-shared key
Show answer & explanation

Correct answer: C - A digital signature applied by the vendor

Question 6

A network administrator is configuring authentication for both wireless network access and router management. For wireless authentication, the team selects RADIUS. For router administration, a protocol that encrypts the entire session and allows granular control over which commands each administrator can execute is preferred. Which protocol meets the router administration requirement?

  1. TACACS+
  2. RADIUS with EAP-TLS
  3. Kerberos
  4. LDAPS
Show answer & explanation

Correct answer: A - TACACS+

Question 7

A company migrates its email to a SaaS provider and its virtual servers to an IaaS platform. A junior analyst claims the cloud providers are now fully responsible for securing all data. Which statement BEST corrects this misunderstanding?

  1. The IaaS provider manages operating system patching, so the customer only manages applications
  2. The SaaS provider is responsible for data classification since they host the application
  3. Both providers are responsible for physical data center security, but the customer bears no security responsibility
  4. The customer remains responsible for data classification and access management regardless of the service model
Show answer & explanation

Correct answer: D - The customer remains responsible for data classification and access management regardless of the service model

Question 8

Verity Financial performs a full backup every Sunday night and incremental backups Monday through Saturday. A server failure occurs on Thursday afternoon. To perform a complete restoration, which combination of backups is required?

  1. Sunday's full backup and Wednesday's incremental backup only
  2. Sunday's full backup plus Monday's, Tuesday's, Wednesday's, and Thursday's incremental backups
  3. Sunday's full backup only
  4. Sunday's full backup and Thursday's incremental backup only
Show answer & explanation

Correct answer: B - Sunday's full backup plus Monday's, Tuesday's, Wednesday's, and Thursday's incremental backups

Question 9

A security team deploys a device that monitors a copy of network traffic via a SPAN port and generates alerts when it detects patterns matching known attack signatures. The device does NOT sit inline with traffic. This device is BEST described as a:

  1. Network-based Intrusion Detection System (NIDS)
  2. Network-based Intrusion Prevention System (NIPS)
  3. Stateful inspection firewall
  4. Web Application Firewall (WAF)
Show answer & explanation

Correct answer: A - Network-based Intrusion Detection System (NIDS)

Question 10

An organization discovers that a system administrator who recently transferred from the IT department to the marketing department still has root access to all production servers. This situation is a failure of which security principle?

  1. Separation of duties
  2. Defense in depth
  3. Least privilege
  4. Due diligence
Show answer & explanation

Correct answer: C - Least privilege

Ready for the real thing?

Practice hundreds more SSCP questions with instant scoring, weak-area drills, and full exam simulations.

Start the free practice test See pricing