🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 13 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A company runs a payroll web app on an on-prem Linux host listening on TCP 8443; the same server also hosts a public site on TCP 80. Policy allows only the HR subnet 192.168.10.0/24 to reach payroll, while any internal subnet may view the public site. No extra hardware or third-party software may be added. Which method best enforces this policy with least privilege?

  • Create host-based firewall ACL rules that allow TCP 8443 only from 192.168.10.0/24, allow TCP 80 from all internal networks, and drop all other inbound traffic.

  • Place the HR subnet in its own VLAN and configure inter-VLAN routing to block other subnets from reaching TCP 8443 on the server.

  • Require users to authenticate with client certificates when accessing the payroll URL over HTTPS on port 8443.

  • Set discretionary file permissions so only HR group members can read payroll files while leaving all network ports open.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot