
Systems Security Certified Practitioner
Domain 2Objective 1
2.1 - Implement and Maintain Authentication Methods SSCP Practice Questions (Page 4)
Part of the Access Controls domain, which accounts for 15% of the SSCP exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
7concepts
15%of the exam
Questions 16–20
- 16
A company is establishing a federation with a partner. The partner uses SAML 2.0, and the company uses OpenID Connect. The company wants to enable SSO for its users to access the partner's application. The company also needs to pass a custom attribute (e.g., department) to the partner for authorization decisions. Which approach should they use?
Select an answer first - 17
A hospital deploys new laptops to its nursing staff. The security policy requires that only these specific, company-issued devices can access the electronic health record (EHR) system, even if a user's username and password are compromised. The devices have TPM 2.0 chips. Which approach should the security team implement to meet this requirement?
Select an answer first - 18
An organization wants to add a second authentication factor that does NOT require users to carry a separate physical token and works even when the user is offline. Which MFA method best fits this requirement?
Select an answer first - 19
Which of the following is an example of an inherence authentication factor?
Select an answer first - 20
Which statement accurately describes the use of MAC addresses for device authentication?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “SSCP” is a trademark of its owner, used for identification only.