TechNuggets Academy

Security Concepts and Practices

Free Systems Security Certified Practitioner practice — 6 questions on Security Concepts and Practices, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 1: Security Concepts and Practices
An SSCP holder discovers that a client's data handling practice, while technically legal and permitted under the signed confidentiality agreement, exposes the public to significant harm if exploited by a third party. Reporting the concern outside the engagement would violate the confidentiality clause, but staying silent leaves the public at risk. Per the (ISC2) Code of Ethics, which canon takes precedence when canons conflict?
The (ISC2) Code of Ethics canons are ordered, and when a genuine conflict arises the practitioner must resolve it in the order listed, with 'Protect society, the common good, necessary public trust and confidence, and the infrastructure' taking precedence over the other three.
Question 2 of 6 · Domain 1: Security Concepts and Practices
A legacy manufacturing control system cannot be patched for a known critical vulnerability because the vendor has not certified the patch and downtime would halt production. Which of the following BEST represents a compensating control for this situation?
A compensating control provides an alternative means of reducing risk when the primary control (patching) cannot be applied. Blocking exploit traffic via an IPS signature mitigates the specific threat without requiring the patch.
Question 3 of 6 · Domain 1: Security Concepts and Practices
An organization publishes a document stating: 'Administrators should consider enabling multi-factor authentication for remote access when operationally feasible.' This document is BEST classified as which governance element?
Guidelines are discretionary, recommendation-based statements ('should consider') that offer flexibility in implementation, distinguishing them from mandatory policies or standards.
Question 4 of 6 · Domain 1: Security Concepts and Practices
A Change Advisory Board (CAB) approves and documents a new firewall rule change, and the change is successfully deployed to production. Which activity is STILL required to ensure the organization's security posture remains accurately documented going forward?
Change management governs the approval and deployment process, but configuration management is responsible for maintaining an accurate, current baseline (e.g., in a CMDB) that reflects the system's approved state after the change.
Question 5 of 6 · Domain 1: Security Concepts and Practices
To prevent a single database administrator from both creating new privileged user accounts AND approving those same accounts' privilege escalation requests without independent oversight, which control should the organization implement?
Separation of duties splits critical functions (account creation and approval of privilege escalation) between two different individuals so that no single person can complete a sensitive process end-to-end unsupervised.
Question 6 of 6 · Domain 1: Security Concepts and Practices
The board of directors approves a formal statement defining the overall amount and type of risk the organization is willing to pursue and retain in order to achieve its strategic business objectives. This statement is BEST described as the organization's:
Risk appetite is the broad, strategic-level amount and type of risk an organization is willing to accept in pursuit of its objectives, typically set by senior leadership or the board.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →