View Full Cyber AB CCP Exam Dumps and Practice Test Dumps
Question 21
Which risk concept describes the amount of uncertainty an organization is willing to pursue while achieving its objectives?
- Risk appetite
- Risk register
- Risk ownership
- Risk treatment
Correct Answer: 1
Explanation:
Risk appetite is the broad amount and type of risk an organization is willing to accept in pursuit of its strategic and operational objectives. It provides direction for making decisions when security risks could affect business goals. Senior leadership typically establishes the organization’s overall appetite, while individual risk decisions should remain consistent with it. A risk appetite statement can influence investments, controls, and approval thresholds. It differs from risk tolerance, which normally defines more specific boundaries around acceptable variation. Understanding appetite helps cybersecurity professionals determine whether proposed activities align with the organization’s broader willingness to take risk.
Question 22
What is the primary purpose of maintaining a formal risk register?
- To authorize employee access
- To document identified risks and their treatment status
- To replace security policies
- To record software licenses
Correct Answer: 2
Explanation:
A risk register provides a structured record of identified organizational risks and relevant information about them. Depending on the organization’s process, entries may include risk descriptions, affected assets, likelihood, impact, assigned owners, treatment decisions, and current status. The register helps management maintain visibility into outstanding exposures and track whether planned responses are progressing. It is not intended to replace policies or function as an access-management system. A well-maintained register also supports periodic risk reviews because changes in technology, business operations, or threats can alter previously documented risk conditions.
Question 23
Who is normally accountable for deciding how a specific business risk should be handled?
- Help desk technician
- Network administrator
- Designated risk owner
- External software vendor
Correct Answer: 3
Explanation:
The risk owner is the individual or organizational role accountable for managing a particular risk within an established governance framework. This person typically understands the affected business activity and has sufficient authority to make or approve decisions concerning treatment, acceptance, transfer, avoidance, or mitigation. Security specialists can provide technical analysis and recommendations, but they do not automatically become the business risk owner. Assigning ownership prevents risks from becoming organizationally invisible or remaining without accountability. Clear ownership also makes follow-up easier because someone is responsible for monitoring the risk and ensuring agreed actions are addressed.
Question 24
Which assessment focuses on determining how the loss of a business function could affect organizational operations?
- Configuration review
- Business impact analysis
- Password audit
- Source-code inspection
Correct Answer: 2
Explanation:
A business impact analysis, or BIA, examines the potential consequences of disruption to important business functions and processes. It helps organizations understand operational dependencies and determine which activities require timely restoration. A BIA may consider financial losses, regulatory consequences, customer effects, operational disruption, and reputational consequences. Its findings can support business continuity and disaster recovery planning. A BIA is different from a technical configuration review because its primary focus is business impact rather than identifying insecure settings. Understanding business priorities allows recovery resources and restoration objectives to be aligned with organizational needs.
Question 25
Which risk response involves moving a financial consequence to another party through an agreement or insurance arrangement?
- Risk avoidance
- Risk acceptance
- Risk transfer
- Risk elimination
Correct Answer: 3
Explanation:
Risk transfer involves shifting some financial or contractual consequences of a risk to another party. Common mechanisms include insurance policies, contractual agreements, and outsourcing arrangements with defined responsibilities. Transfer does not necessarily remove the underlying risk itself. For example, an organization may purchase cyber insurance to reduce certain financial consequences associated with an incident, while still needing technical and administrative safeguards. Risk acceptance means knowingly retaining the exposure, whereas avoidance generally involves deciding not to perform the activity that creates the risk. Selecting a treatment depends on business objectives, available controls, cost, and organizational risk criteria.
Question 26
What distinguishes residual risk from inherent risk?
- Residual risk exists before controls are applied
- Residual risk represents exposure remaining after controls are considered
- Residual risk only applies to physical security
- Residual risk is always completely eliminated
Correct Answer: 1
Explanation:
Residual risk refers to the level of exposure that remains after risk treatments and controls have been implemented or considered. Inherent risk describes exposure before accounting for those controls. The distinction helps organizations determine whether implemented safeguards have reduced risk to a level that management is willing to tolerate. Residual risk can still exist even when extensive controls are deployed because no practical control environment eliminates every possible threat. Organizations should periodically reassess residual risk as threats, technologies, vulnerabilities, and business processes change. The remaining exposure may then be accepted, further reduced, transferred, or otherwise treated.
Question 27
Which principle limits collected personal information to what is necessary for a defined purpose?
- Data minimization
- Privilege escalation
- Network segmentation
- Configuration inheritance
Correct Answer: 3
Explanation:
Data minimization is the privacy principle of collecting, processing, and retaining only the personal information that is reasonably necessary for a legitimate and defined purpose. Limiting unnecessary information can reduce privacy exposure and decrease the consequences of a potential compromise. For example, an application should avoid collecting sensitive attributes when those attributes have no meaningful role in delivering its service. Data minimization can also simplify retention and disposal activities because fewer unnecessary records are maintained. It should be considered during system design rather than treated solely as a requirement after information has already been collected.
Question 28
What role does a data custodian typically perform?
- Establishing corporate risk appetite
- Managing and protecting data according to the owner’s requirements
- Approving organizational mergers
- Defining business revenue targets
Correct Answer: 2
Explanation:
A data custodian is generally responsible for the operational handling and protection of data according to requirements established by the data owner and organizational policies. Custodial responsibilities may include maintaining storage systems, implementing safeguards, managing backups, and supporting access controls. The data owner remains responsible for determining appropriate classification, access requirements, or business use of the information. Separating ownership from custody creates clearer accountability. A custodian therefore does not automatically decide the business value or classification of information simply because the custodian operates the technology that stores or processes it.
Question 29
Which practice helps ensure information is removed when its approved retention period expires?
- Data disposal
- Threat hunting
- Packet filtering
- Identity federation
Correct Answer: 1
Explanation:
Data disposal is the controlled removal of information when it is no longer required under applicable business, legal, regulatory, or contractual requirements. Secure disposal can involve different methods depending on the storage medium and sensitivity of the information. Examples include secure deletion, cryptographic erasure, or physical destruction of storage media. Disposal should be performed according to documented retention schedules rather than arbitrary individual decisions. Effective disposal reduces unnecessary data exposure and limits the quantity of information an organization must protect. Organizations should also consider legal holds and other requirements that may temporarily prevent otherwise scheduled destruction.
Question 30
Which control helps prevent unauthorized personnel from entering a restricted facility by requiring verification at the entrance?
- Visitor escort log
- Environmental temperature sensor
- Mantrap entry system
- Backup generator
Correct Answer:4
Explanation:
A mantrap is a physical access-control arrangement consisting of two interlocking doors that regulate movement into a protected area. Typically, one door must close before the other can open, helping prevent unauthorized individuals from simply following an authorized person through an entrance. Mantraps can be combined with badges, biometric verification, cameras, or security personnel. They are particularly useful in locations requiring stronger physical access restrictions. A generator addresses power continuity, while a temperature sensor monitors environmental conditions. Physical controls should be selected according to the sensitivity of the facility and the organization’s assessment of unauthorized-entry risks.
Question 31
What is the main purpose of establishing a secure configuration baseline?
- To define an approved starting configuration for systems
- To calculate insurance premiums
- To replace incident investigations
- To determine employee salaries
Correct Answer: 2
Explanation:
A secure configuration baseline defines an approved set of technical settings that systems should maintain. It can specify requirements such as unnecessary service restrictions, authentication settings, logging configuration, permissions, and other security-related parameters. Baselines provide a consistent reference for deployment and configuration assessment. When systems drift away from the approved state, administrators can investigate and correct the deviation. Baselines should be appropriate for the technology and business purpose rather than copied blindly between systems. Regular review is also important because emerging threats, software changes, and organizational requirements can make an older baseline unsuitable.
Question 32
Which process prioritizes fixing weaknesses in systems according to their assessed severity and business exposure?
- Asset disposal
- Vulnerability management
- Document archiving
- Personnel onboarding
Correct Answer: 3
Explanation:
Vulnerability management is the ongoing process of identifying, evaluating, prioritizing, remediating, and monitoring security weaknesses. Effective programs do not necessarily treat every vulnerability identically because severity, exploitability, affected assets, exposure, and business importance can differ substantially. Organizations may use vulnerability assessments and scoring information to establish remediation priorities. After fixes are applied, verification helps confirm that the weakness has actually been addressed. Vulnerability management is therefore more than simply running a scanner. It is a continuing operational discipline that connects technical findings with business risk and remediation activities.
Question 33
What does a CVE identifier primarily provide for a publicly documented software vulnerability?
- A standardized reference identifier
- A guaranteed remediation deadline
- A replacement encryption key
- A hardware inventory number
Correct Answer: 4
Explanation:
A CVE identifier provides a standardized reference for a publicly disclosed cybersecurity vulnerability. Common Vulnerabilities and Exposures, or CVE, identifiers make it easier for security teams, vendors, researchers, and tools to refer to the same vulnerability consistently. A CVE identifier itself does not determine how quickly an organization must remediate the issue. Remediation priority can depend on factors such as exploitability, affected systems, exposure, business criticality, and organizational policy. CVE references are therefore useful for vulnerability tracking and communication, but organizations normally need additional information to determine appropriate treatment.
Question 34
Which technique attempts to identify security weaknesses by safely simulating attacks against a system?
- Log aggregation
- Penetration testing
- Data classification
- Capacity planning
Correct Answer: 1
Explanation:
Penetration testing involves controlled attempts to exploit security weaknesses in systems, applications, networks, or other environments. The goal is to demonstrate how identified weaknesses could potentially be used and to provide evidence that supports remediation. Testing should be authorized, scoped, and performed under defined rules to avoid unintended operational disruption. Penetration testing differs from vulnerability scanning because a scanner primarily identifies potential weaknesses, while penetration testing can attempt to validate exploitability and understand attack paths. Organizations should document findings and ensure discovered weaknesses are addressed according to established risk-management processes.
Question 35
Which activity uses information about adversaries and emerging threats to improve defensive decisions?
- Threat intelligence
- Media sanitization
- Business archiving
- Facilities maintenance
Correct Answer: 2
Explanation:
Threat intelligence involves collecting, analyzing, and applying information about threats, threat actors, attack techniques, vulnerabilities, and other relevant security developments. Useful intelligence can help organizations understand which threats may affect their environment and adjust defensive priorities accordingly. Intelligence may come from internal observations, trusted external sources, industry groups, or security research. Simply collecting large quantities of threat information does not automatically create useful intelligence; analysis and contextualization are important. Security teams can use relevant intelligence to improve detection rules, vulnerability priorities, incident preparation, and broader risk decisions.
Question 36
What does an indicator of compromise most commonly represent?
- A sign suggesting that a security compromise may have occurred
- A contractual service-level target
- A planned equipment replacement date
- A business continuity budget
Correct Answer: 4
Explanation:
An indicator of compromise, or IOC, is an observable artifact or condition that may indicate malicious activity or a security compromise. Examples can include suspicious file hashes, unusual network destinations, malicious domains, unexpected account activity, or known attacker artifacts. Security teams can use IOCs in monitoring and investigation processes to identify potentially affected systems. An IOC does not necessarily prove that an attack occurred because legitimate activity can sometimes resemble malicious behavior. Analysts therefore evaluate indicators alongside additional evidence and context. Maintaining useful IOC information can improve detection and support incident investigation.
Question 37
Which attack technique attempts authentication with many accounts using a small number of commonly used passwords?
- Password spraying
- Credential encryption
- Tokenization
- Certificate pinning
Correct Answer: 1
Explanation:
Password spraying is an authentication attack in which an attacker tries a small set of commonly used passwords against many different accounts. This approach differs from traditional brute-force attacks, which may repeatedly attempt many passwords against a single account. Spraying can help attackers avoid account lockout thresholds that are designed to detect repeated failures against one account. Defensive measures include strong password policies, multifactor authentication, monitoring authentication failures, and detecting unusual login patterns. Organizations should also identify and address weak or commonly used credentials because password spraying relies heavily on predictable authentication secrets.
Question 38
What is the primary security benefit of network segmentation?
- It increases every user’s privileges
- It limits communication between defined network zones
- It removes the need for authentication
- It guarantees that malware cannot spread
Correct Answer: 3
Explanation:
Network segmentation separates systems or services into distinct network zones and controls communication between them. The objective is to reduce unnecessary connectivity and limit the potential movement of an attacker after an initial compromise. Segmentation can be implemented using technologies such as firewalls, virtual networks, access-control mechanisms, and other network enforcement points. It does not guarantee that malware cannot spread because compromised systems may still communicate through permitted paths. Effective segmentation is based on business and security requirements and should be reviewed as applications, dependencies, and network architectures change.
Question 39
Which security technology is primarily designed to collect and correlate events from multiple systems for centralized analysis?
- Hardware security module
- Security information and event management platform
- Network address translator
- File compression utility
Correct Answer: 2
Explanation:
A security information and event management, or SIEM, platform centralizes security-related events from multiple sources and can correlate those events to identify suspicious patterns. Sources may include servers, endpoints, network devices, applications, authentication systems, and security controls. Centralized analysis can help security teams investigate incidents and prioritize alerts. A SIEM is not simply a storage location for logs; its value comes from aggregation, analysis, correlation, alerting, and investigation capabilities. Effective SIEM operations depend on appropriate data sources, useful detection logic, accurate time synchronization, and processes for reviewing and responding to generated alerts.
Question 40
Which recovery objective specifies the maximum acceptable amount of data loss measured in time?
- Recovery point objective
- Recovery time objective
- Maximum tolerable downtime
- Service restoration threshold
Correct Answer: 4
Explanation:
The recovery point objective, or RPO, defines the maximum acceptable amount of data loss expressed as a period of time. For example, an organization with an RPO of 30 minutes aims to ensure that recoverable data is no more than approximately 30 minutes behind the point of disruption. RPO influences backup frequency, replication strategies, and recovery architecture. It differs from RTO, which focuses on how quickly a service or process should be restored. Organizations establish recovery objectives according to business requirements, dependencies, acceptable disruption, and the consequences associated with losing data.