SSCP Certification SSCP Security Operations 4 — Questions and Answers
Question 1: When classifying a security incident, which factor PRIMARILY determines the severity level assigned?
- The number of security tools that generated alerts
- The potential business impact and scope of systems affected (Correct answer)
- The geographic location of the attacker
- The time of day the incident was detected
Correct answer: The potential business impact and scope of systems affected
Incident severity is driven by the actual or potential impact to business operations, data, and affected system scope.
Question 2: A security team is implementing network segmentation. Which benefit does this provide during an incident?
- It speeds up network throughput during high traffic periods
- It limits the blast radius of a compromise by containing lateral movement (Correct answer)
- It eliminates the need for intrusion detection systems
- It provides automatic encryption of inter-segment traffic
Correct answer: It limits the blast radius of a compromise by containing lateral movement
Segmentation creates boundaries that restrict an attacker's ability to move freely between systems after gaining initial access.
Question 3: Which of the following BEST describes the role of a Security Operations Center (SOC) Tier 1 analyst?
- Performing digital forensics investigations on compromised systems
- Monitoring alerts, triaging events, and escalating confirmed incidents (Correct answer)
- Developing threat hunting queries and detection rules
- Managing security tool procurement and vendor relationships
Correct answer: Monitoring alerts, triaging events, and escalating confirmed incidents
Tier 1 analysts are responsible for initial alert triage, distinguishing true positives from false positives, and escalating as needed.
Question 4: What is the purpose of a lessons learned meeting after a security incident is resolved?
- To assign blame to individuals responsible for the breach
- To document findings and improve processes to prevent recurrence (Correct answer)
- To satisfy legal disclosure obligations to regulators
- To decommission systems that were involved in the incident
Correct answer: To document findings and improve processes to prevent recurrence
Lessons learned meetings capture what worked and what failed so processes, controls, and training can be improved before the next incident.
Question 5: An analyst is implementing patch management for a fleet of servers. Which priority order is MOST appropriate?
- Alphabetical order by server name
- Critical vulnerabilities with known exploits first, then high, medium, and low (Correct answer)
- Oldest patches first regardless of severity
- Patches that require the least downtime first
Correct answer: Critical vulnerabilities with known exploits first, then high, medium, and low
Prioritizing by exploitability and severity ensures the highest-risk vulnerabilities are addressed before attackers can leverage them.
Question 6: Which security control is MOST effective at preventing unauthorized physical access to a server room?
- Biometric access control combined with mantrap entry (Correct answer)
- Strong password policy for server login accounts
- Network-based intrusion detection sensors
- Full-disk encryption on all servers
Correct answer: Biometric access control combined with mantrap entry
A biometric mantrap uses two-factor physical authentication and a controlled entry zone that prevents tailgating into the server room.
Question 7: In the context of security operations, what does Mean Time to Detect (MTTD) measure?
- The average time to fully remediate a vulnerability after patching
- The average time between when an attack occurs and when it is identified by the security team (Correct answer)
- The average time to restore services after a system outage
- The average time for a threat actor to return after being blocked
Correct answer: The average time between when an attack occurs and when it is identified by the security team
MTTD is a key SOC performance metric representing the dwell time gap — the shorter the MTTD, the faster threats are found.
When classifying a security incident, which factor PRIMARILY determines the severity level assigned?