nerdexam
(ISC)2

SSCP · Question #177

Which of the following questions is less likely to help in assessing identification and authentication controls?

The correct answer is D. Is there a process for reporting incidents? Questions A, B, and C are all directly relevant to assessing identification and authentication (I&A) controls: maintaining an authorized user list (A), enforcing password expiration policies (B), and disabling inactive accounts (C) are core I&A control activities. Incident…

Submitted by fatema_kw· Apr 18, 2026Access Controls

Question

Which of the following questions is less likely to help in assessing identification and authentication controls?

Options

  • AIs a current list maintained and approved of authorized users and their access?
  • BAre passwords changed at least every ninety days or earlier if needed?
  • CAre inactive user identifications disabled after a specified period of time?
  • DIs there a process for reporting incidents?

How the community answered

(57 responses)
  • A
    4% (2)
  • B
    4% (2)
  • C
    11% (6)
  • D
    82% (47)

Explanation

Questions A, B, and C are all directly relevant to assessing identification and authentication (I&A) controls: maintaining an authorized user list (A), enforcing password expiration policies (B), and disabling inactive accounts (C) are core I&A control activities. Incident reporting (D) is a separate security domain - it belongs to incident response management, not I&A controls. While important to overall security, it does not directly assess how users are identified or authenticated.

Topics

#Identification#Authentication#Access Control Assessment#Security Controls

Community Discussion

No community discussion yet for this question.

Full SSCP Practice