HomeSSCP Security Exam PrepQuestions 21–30
SSCP Security Exam PrepPart 3 of 3

SSCP Security Exam Prep Exam Questions & Answers 2026 (21–30)

SSCP Security Exam Prep practice questions and answers 2026. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.

Practise SSCP Security Exam Prep questions free, download the PDF, or unlock timed mock exams when you are ready.
Multiple choice — pick the best answer, then reveal it
  1. Q21When a courier service provides a delivery option that requires the recipient to sign upon receipt, what type of security control is being implemented?

    • ANonrepudiation
    • BConfidentiality
    • CPrivacy
    • DIntegrity
    Show answer

    ✓ Correct answer: A. Nonrepudiation

    Nonrepudiation is ensured when the recipient signs upon receiving a package from a courier service, making it infeasible for the recipient to deny having received it.

  2. Q22Which of the following IP address types might indicate a security issue if observed frequently on an internal network?

    • A10.x.x.x
    • B192.168.x.x
    • C169.254.x.x
    • D172.16.x.x
    Show answer

    ✓ Correct answer: C. 169.254.x.x

    The correct answer is 169.254.x.x. This range is used for Automatic Private IP Addressing (APIPA), which means the device could not obtain an IP address from the DHCP server, indicating a possible network configuration or connectivity issue. The ranges 192.168.x.x, 10.x.x.x, and 172.16.x.x are private IP address ranges typically used in corporate networks.

  3. Q23Which of the following protocols does NOT run over UDP?

    • ATFTP
    • BDNS
    • CSNMP
    • DFTP
    Show answer

    ✓ Correct answer: D. FTP

    Answer: FTP FTP is a protocol that runs over TCP, which ensures reliable data transfer. DNS, SNMP, and TFTP are protocols that run over UDP, which is a lighterweight protocol.

  4. Q24Which of the following is NOT a core component of network segmentation?

    • AVirtual LANs (VLANs)
    • BFirewalls
    • CDecryption
    • DAccess Control Lists (ACLs)
    Show answer

    ✓ Correct answer: C. Decryption

    Answer: Decryption. Network segmentation primarily involves components such as firewalls, Virtual LANs (VLANs), and Access Control Lists (ACLs) to control and manage network traffic, but not decryption.

  5. Q25Which type of wireless attack might be used to inject malicious data packets into a Wi-Fi network?

    • AMan-in-the-middle
    • BPacket injection
    • CWar driving
    • DSignal jamming
    Show answer

    ✓ Correct answer: B. Packet injection

    Answer: Packet injection. Packet injection involves inserting malicious packets into a Wi-Fi network. Man-in-the-middle attacks intercept and potentially alter the communication between two parties. War driving involves searching for Wi-Fi networks while driving around. Signal jamming disrupts wireless communication by overwhelming the network with noise or other signals.

  6. Q26Which of the following standards defines a security protocol for wireless networks?

    • AIEEE 802.11i
    • BIEEE 802.3
    • CIEEE 802.16
    • DIEEE 802.15
    Show answer

    ✓ Correct answer: A. IEEE 802.11i

    Answer: IEEE 802.11i IEEE 802.11i is a standard that defines a security protocol for wireless networks, commonly known as WPA2, which provides robust security mechanisms for wireless communication. IEEE 802.3 is an Ethernet standard that governs wired LAN technologies. IEEE 802.16, also known as WiMAX, defines wireless broadband standards. IEEE 802.15 focuses on wireless personal area networks (WPANs).

  7. Q27Which of the following network intrusion detection techniques is specifically designed for detecting attacks based on predefined patterns?

    • AHeuristic-Based Detection
    • BAnomaly-Based Detection
    • CSignature-Based Detection
    • DBehavior-Based Detection
    Show answer

    ✓ Correct answer: C. Signature-Based Detection

    Answer: Signature-Based Detection Network Intrusion Detection Systems (NIDS) can utilize various methods to identify potential attacks, including: Technique Description Signature-Based Detection Uses predefined patterns or rules to identify known threats. Anomaly-Based Detection Establishes a baseline of normal network behavior and identifies deviations that may indicate attacks. Heuristic-Based Detection Uses algorithms to detect suspicious activity by examining behaviors and assessing their potential threats. Behavior-Based Detection Monitors the behavior of system components to identify actions that deviate from expected norms.

  8. Q28Which of the following does NOT specify disallowed traffic on a network?

    • ABlocklisting
    • BAllowlisting
    • CDisallowed IP ranges
    • DNegative control
    Show answer

    ✓ Correct answer: B. Allowlisting

    Answer: Allowlisting Negative control or blocklisting specifies what should be blocked, creating a "default deny" policy. Examples of common negative controls include: 1. IP blocklists 2. Disallowed URLs 3. Malware signatures Positive control or allowlisting specifies what should be allowed through, creating a "default deny" policy by assuming all other traffic is disallowed unless stated otherwise. Examples of common positive controls include: 1. Network allowlists 2. IP whitelists 3. Application control lists

  9. Q29Which type of network attack can propagate without requiring any user interaction?

    • AWorm
    • BVirus
    • CSpyware
    • DAdware
    Show answer

    ✓ Correct answer: A. Worm

    Answer: Worm Worms are capable of spreading themselves across networks without any user interaction. Viruses typically require some kind of user action to propagate, such as opening an infected file. Spyware is used to gather information from a user's system without their knowledge, often requiring some form of user action for initial infection. Adware generates revenue by displaying ads to users, often requiring user action to install the software that displays these ads.

  10. Q30Which of the following mechanisms is BEST suited to identifying an attacker attempting to exfiltrate sensitive data from a compromised system?

    • AEndpoint Behavioral Modeling
    • BUser Behavioral Modeling
    • CAccess Control
    • DSecurity Logs
    Show answer

    ✓ Correct answer: C. Access Control

    Answer: Access Control Malicious activity on a system could be detected in a few different ways, such as: User Behavioral Modeling: User behavioral modeling attempts to identify what is "normal" for a user. Based on this definition of "normal," it can identify potential attacks as deviations from "normal" behavior. For example, unusual data transfer activities (especially without authorization) may indicate a compromised account. Endpoint Behavioral Modeling: Endpoints also have "normal" and "abnormal" behavior that can be used to detect attacks. For example, a program generating large amounts of outbound traffic could be a sign of an exfiltration event. Access Control: Attackers commonly attempt to abuse the access of a compromised account and potentially exfiltrate sensitive data without authorization. Access control systems can alert on anomalous or unauthorized data transfer attempts that point to a compromised account. Security Logs: Endpoints, security solutions, and other tools will generate log files that record important events that occurred on the system. This could include events that point to data exfiltration attempts or other security events. Exfiltration of sensitive data commonly involves abusing an account's permissions or compromising new accounts to gain access to valuable information. Access control systems can help to detect and prevent these exfiltration attempts.

Free practice here. Timed mocks when you are ready.

Use the free SSCP Security Exam Prep sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.