
Systems Security Certified Practitioner
Domain 1Objective 7
1.7 - Support And/or Implement Security Awareness and Training (e.g., Social Engineering/phishing/tabletop Exercises/awareness Communications) SSCP Practice Questions (Page 7)
Part of the Security Concepts and Practices domain, which accounts for 16% of the SSCP exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
9concepts
16%of the exam
Questions 31–33
- 31
What is the first step you should take when you suspect an email is a phishing attempt?
Select an answer first - 32
A security manager is planning a tabletop exercise to test the incident response plan for a ransomware attack. The exercise must not disrupt normal business operations, but it must be realistic enough to challenge the participants. The manager has a limited budget and cannot use a third-party facilitator. What is the MOST appropriate approach for this exercise?
Select an answer first - 33
A security team is reviewing the results of its latest phishing simulation. The click rate is 10%, but the reporting rate is only 15%. The team is concerned that employees are not reporting phishing attempts. Which of the following is the MOST likely reason for the low reporting rate, and what is the BEST action to address it?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SSCP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “SSCP” is a trademark of its owner, used for identification only.