A practitioner must implement a requirement mandating encryption of a database column, but the legacy application cannot handle ciphertext in that field. Management approves strict network isolation, restricted access, and enhanced monitoring instead. What has been implemented, and what obligation remains?
Systems Security Certified Practitioner
ISC2_SSCPReady to test yourself?
A timed, blueprint-proportional exam drawn fresh from this bank โ with a per-domain score report.
๐ Free preview: showing 10 of 125 questions. Unlock the full bank โ every question, explanation, and reference.
Unlock all 125 questions โ10 questions across 7 topics. Choose an answer for each question, then check it to see the correct answer and explanation.
Filter by topic
All 10 questions
Security Concepts and Practices
10 questions in topicCIA and supporting principles, governance documents, control categories and functions, change and configuration management, and professional ethics.
Two teams disagree about a proposed configuration change: security says it weakens a control, operations says the current setting causes outages. The change advisory board asks the SSCP practitioner for input. What is the MOST professional contribution?
An organization's policy requires quarterly firewall rule reviews. During a review the practitioner finds a permissive any-any rule added eight months ago with an expired change ticket referencing a completed migration. The BEST action is to:
Which sequence correctly orders these artifacts from broadest mandate to most specific implementation detail?
A practitioner is told to grant a developer temporary production database write access to resolve an urgent defect. Which approach BEST preserves both the fix timeline and control integrity?
During onboarding, an SSCP discovers that a business unit has been storing customer national ID numbers in a spreadsheet on a shared drive readable by all staff. What is the MOST appropriate FIRST action?
Which statement BEST characterizes the relationship between accountability and the use of shared service accounts for administrative automation?
An auditor notes that the organization's security awareness program achieves 100% completion but phishing simulation click rates have not improved over two years. The MOST likely deficiency is that the program:
Which pairing of control function to example is CORRECT?
A practitioner must classify a dataset that combines non-sensitive product identifiers with a field indicating whether each customer has an unpaid balance. What is the correct approach?