
Systems Security Certified Practitioner
Domain 2Objective 1
2.1 - Implement and Maintain Authentication Methods SSCP Practice Questions (Page 1)
Part of the Access Controls domain, which accounts for 15% of the SSCP exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
7concepts
15%of the exam
Questions 1–5
- 1
A company's partners need to access an internal web portal. The company wants to use federated identity so partners authenticate with their own organization's credentials. The partner organizations use a variety of identity providers, including ADFS, Azure AD, and Google. Which approach should the company use to support this heterogeneous environment?
Select an answer first - 2
A financial services firm requires users to authenticate to a high-value internal portal. The security team has implemented a policy requiring two different authentication factors. Users currently authenticate with a username and password, and then receive a one-time passcode (OTP) via SMS to their registered mobile phone. Which additional change would MOST effectively strengthen the authentication process while still meeting the two-factor requirement?
Select an answer first - 3
A company is migrating from an on-premises ADFS deployment to Azure AD for SSO. The company has a legacy application that only supports SAML 2.0 and a modern application that supports OpenID Connect. The company wants to minimize user disruption and maintain a single sign-on experience. Which migration strategy should they use?
Select an answer first - 4
A small business wants to implement multi-factor authentication for its remote workers. The workers use company-issued laptops and personal smartphones. The business wants a solution that does not require additional hardware and is resistant to phishing. Which MFA method should they choose?
Select an answer first - 5
A manufacturing company has a fleet of IoT sensors that send data to a central server. The security team needs to ensure that only genuine company sensors can connect, and that the data is not intercepted. The sensors have a TPM chip. Which method should the security team use to authenticate the sensors?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “SSCP” is a trademark of its owner, used for identification only.