Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Systems Security Certified Practitioner

Domain 2Objective 1

2.1 - Implement and Maintain Authentication Methods SSCP Practice Questions (Page 1)

Part of the Access Controls domain, which accounts for 15% of the SSCP exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
7concepts
15%of the exam

Questions 1–5

  1. 1application · medium

    A company's partners need to access an internal web portal. The company wants to use federated identity so partners authenticate with their own organization's credentials. The partner organizations use a variety of identity providers, including ADFS, Azure AD, and Google. Which approach should the company use to support this heterogeneous environment?

    Select an answer first
  2. 2application · medium

    A financial services firm requires users to authenticate to a high-value internal portal. The security team has implemented a policy requiring two different authentication factors. Users currently authenticate with a username and password, and then receive a one-time passcode (OTP) via SMS to their registered mobile phone. Which additional change would MOST effectively strengthen the authentication process while still meeting the two-factor requirement?

    Select an answer first
  3. 3expert · medium

    A company is migrating from an on-premises ADFS deployment to Azure AD for SSO. The company has a legacy application that only supports SAML 2.0 and a modern application that supports OpenID Connect. The company wants to minimize user disruption and maintain a single sign-on experience. Which migration strategy should they use?

    Select an answer first
  4. 4application · medium

    A small business wants to implement multi-factor authentication for its remote workers. The workers use company-issued laptops and personal smartphones. The business wants a solution that does not require additional hardware and is resistant to phishing. Which MFA method should they choose?

    Select an answer first
  5. 5application · medium

    A manufacturing company has a fleet of IoT sensors that send data to a central server. The security team needs to ensure that only genuine company sensors can connect, and that the data is not intercepted. The sensors have a TPM chip. Which method should the security team use to authenticate the sensors?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “SSCP” is a trademark of its owner, used for identification only.