Cyber AB CCP Practice Test Questions and Exam Dumps Part4 Q61-80

View Full Cyber AB CCP Exam Dumps and Practice Test Dumps

 

Question 61

Which process determines whether a security event requires formal incident response?

  1. Capacity forecasting
  2. Data archiving
  3. Incident triage
  4. Hardware procurement

Correct Answer: 4

Explanation:

Incident triage is the process of evaluating reported security events to determine their significance, urgency, scope, and required response. Security teams may examine available evidence, affected assets, indicators, user activity, and potential business impact. The objective is to distinguish routine events from situations that require escalation into formal incident handling. Effective triage helps organizations use response resources efficiently while reducing the chance that serious activity is overlooked. Triage should follow documented procedures and escalation criteria. It may also involve assigning severity levels so that incidents receive an appropriate response based on organizational priorities and established risk thresholds.

Question 62

Which incident response activity focuses on limiting an attacker’s ability to continue causing harm?

  1. Containment
  2. Validation
  3. Procurement
  4. Classification

Correct Answer: 2

Explanation:

Containment is an incident response activity intended to limit the spread or impact of an ongoing security incident. Depending on circumstances, responders may isolate an endpoint, block malicious communication, disable compromised accounts, or restrict access to affected resources. Containment should be performed carefully because aggressive actions can sometimes disrupt legitimate operations or destroy useful evidence. The appropriate approach depends on incident severity, business requirements, and response procedures. Containment is distinct from eradication, which focuses on removing the underlying cause or malicious artifacts. After containment, responders can proceed with deeper investigation and remediation while reducing immediate operational exposure.

Question 63

What is the primary objective of eradication during incident response?

  1. Restore normal business operations immediately
  2. Remove the cause and malicious artifacts of the incident
  3. Notify every employee about the event
  4. Create a new asset inventory

Correct Answer: 1

Explanation:

Eradication focuses on removing the threat and its underlying presence from affected systems. Activities can include deleting malicious software, removing unauthorized accounts, addressing exploited vulnerabilities, resetting compromised credentials, and eliminating persistence mechanisms. The exact actions depend on the nature of the incident and evidence gathered during investigation. Eradication should occur after responders understand enough about the compromise to avoid leaving hidden attacker access behind. Simply restoring a system without addressing the cause may allow the incident to recur. Once eradication is completed and appropriate validation occurs, affected systems can move toward controlled recovery.

Question 64

Which activity confirms that recovered systems are functioning securely before returning them to normal service?

  1. Credential harvesting
  2. Recovery validation
  3. Threat introduction
  4. Uncontrolled deployment

Correct Answer: 3

Explanation:

Recovery validation involves checking restored systems to ensure they are operational, correctly configured, and sufficiently secure before normal business use resumes. Validation can include reviewing security settings, confirming that malicious artifacts have been removed, testing functionality, checking monitoring coverage, and verifying that required controls are operating. This step reduces the chance of returning a compromised or incorrectly restored system to production. Recovery should be based on documented procedures and business requirements rather than assumptions that restoration automatically means the environment is safe. Appropriate stakeholders should confirm that recovery objectives have been met before services are considered fully restored.

Question 65

Why is preserving forensic evidence important during a security investigation?

  1. It supports reliable analysis of what occurred
  2. It guarantees that an attacker will be identified
  3. It eliminates the need for documentation
  4. It automatically restores affected systems

Correct Answer: 2

Explanation:

Forensic evidence preservation helps investigators maintain information that may explain how an incident occurred, what systems were affected, what actions were performed, and when relevant activity took place. Evidence can include logs, disk images, memory captures, network records, or other artifacts. Investigators should handle evidence carefully to minimize alteration and maintain appropriate documentation. Preserving evidence can support internal investigations, regulatory processes, legal proceedings, or lessons-learned activities when applicable. Evidence preservation does not guarantee that every question will be answered, but poor handling can make later analysis more difficult and reduce confidence in investigative findings.

Question 66

What does chain of custody primarily document?

  1. The organization’s backup schedule
  2. The history of evidence handling and possession
  3. The sequence of employee promotions
  4. The configuration of wireless access points

Correct Answer: 4

Explanation:

Chain of custody documents the handling, transfer, storage, and possession of evidence from collection through subsequent examination or disposition. Maintaining this record helps establish that evidence was controlled appropriately and that its history can be explained. Documentation may identify who collected an item, when it was obtained, where it was stored, and who subsequently accessed or transferred it. Strong chain-of-custody procedures are especially important when evidence could be used in legal or regulatory contexts. Organizations should follow established procedures and ensure that personnel handling evidence understand documentation and preservation requirements.

Question 67

Which recovery facility is generally maintained with systems and connectivity prepared for rapid operational use?

  1. Cold site
  2. Archive center
  3. Hot site
  4. Storage warehouse

Correct Answer: 3

Explanation:

A hot site is an alternate facility that is maintained with significant infrastructure and technology readiness so that critical operations can be restored relatively quickly after a disruption. Depending on the organization, a hot site may have computing resources, network connectivity, power arrangements, and other capabilities needed for continuity. Because maintaining such readiness can be expensive, organizations should evaluate the cost against business recovery requirements. A cold site typically requires considerably more setup before operations can resume. Recovery-site selection should therefore be based on factors such as RTO, business criticality, geographic considerations, and available resources.

Question 68

Which continuity concept identifies the longest period a business function can remain unavailable before unacceptable consequences occur?

  1. Maximum tolerable downtime
  2. Encryption lifespan
  3. Authentication interval
  4. Patch deployment window

Correct Answer: 1

Explanation:

Maximum tolerable downtime, or MTD, represents the longest period that an organization can tolerate the unavailability of a business function before the resulting consequences become unacceptable. It is a business-oriented measure used in continuity planning. MTD can help organizations determine recovery priorities and establish appropriate recovery objectives. It is related to, but distinct from, RTO, which specifies a target for restoring a service or process. Understanding acceptable downtime requires consideration of financial impact, legal obligations, customer expectations, operational dependencies, and other consequences. These requirements should guide continuity and recovery strategies.

Question 69

Which backup strategy maintains multiple copies across different media and includes an offsite copy?

  1. Single-copy retention
  2. 3-2-1 backup strategy
  3. Continuous deletion
  4. Local-only mirroring

Correct Answer: 4

Explanation:

The 3-2-1 backup strategy is a commonly used approach for improving resilience of recovery data. It traditionally involves maintaining at least three copies of data, storing those copies on at least two different types of media, with at least one copy kept offsite. The approach reduces dependence on a single storage location or technology. Modern organizations may add protections such as immutable storage, offline copies, or geographically separated facilities. Backup strategies should also be tested through restoration exercises. A backup that exists but cannot be successfully restored may provide little practical value during a major disruption.

Question 70

What is the purpose of a recovery time objective?

  1. To define the maximum number of administrators
  2. To establish a target for restoring a service after disruption
  3. To identify the age of an application
  4. To measure password complexity

Correct Answer: 2

Explanation:

A recovery time objective, or RTO, specifies the targeted amount of time within which a business process or technology service should be restored following a disruption. RTOs help organizations determine how much recovery capability is required and can influence architecture, staffing, backup methods, redundancy, and alternate-site planning. A shorter RTO may require greater investment because rapid recovery often depends on additional infrastructure or automation. RTO should be established according to business requirements rather than simply choosing the shortest possible duration. It works alongside other objectives, including RPO, to define broader recovery expectations.

Question 71

Which governance document normally establishes mandatory high-level security direction for an organization?

  1. Security policy
  2. Troubleshooting note
  3. Temporary chat message
  4. Equipment invoice

Correct Answer: 3

Explanation:

A security policy establishes high-level organizational direction, expectations, and requirements concerning information security. It can define responsibilities, acceptable security principles, compliance expectations, and management commitments. More detailed standards, procedures, and guidelines can then translate those requirements into operational practices. Policies should be approved by appropriate authority and communicated to relevant personnel. They should also be reviewed periodically because changes in business operations, technology, threats, or regulatory obligations may require updates. A policy is different from an informal troubleshooting note because it establishes an organizational requirement rather than documenting a single technical activity.

Question 72

What is the main difference between a standard and a security guideline?

  1. A guideline is always legally binding
  2. A standard defines mandatory requirements while a guideline generally provides recommended direction
  3. A standard applies only to physical security
  4. A guideline replaces organizational policies

Correct Answer: 1

Explanation:

A security standard normally establishes specific, mandatory requirements that must be followed within the scope defined by the organization. A guideline generally provides recommended practices or advice that helps personnel make appropriate security decisions without necessarily imposing the same mandatory requirements. For example, a password standard might specify required technical characteristics, while a guideline could offer recommendations for protecting credentials during travel. The exact terminology can differ between organizations, so governance frameworks should clearly define how their documents are used. Maintaining a logical hierarchy between policies, standards, guidelines, and procedures improves consistency and accountability.

Question 73

Which role is primarily responsible for determining the business value and classification of information?

  1. Data owner
  2. Network engineer
  3. Facilities technician
  4. Application tester

Correct Answer: 2

Explanation:

The data owner is typically responsible for determining how information should be classified and what protection requirements apply based on its business value and sensitivity. The owner may establish access requirements, retention expectations, and acceptable uses of the information. Technical custodians then implement and operate controls that support those requirements. Clear separation between ownership and custody prevents technology operators from independently deciding business requirements. Classification decisions can affect encryption, access restrictions, handling procedures, retention, and disposal. Organizations should define ownership clearly so that sensitive information does not become unmanaged simply because it is stored across multiple systems.

Question 74

Which physical security measure is specifically designed to verify visitors before granting access to controlled areas?

  1. Visitor management process
  2. Cooling system
  3. Lightning protection
  4. Power distribution unit

Correct Answer: 4

Explanation:

A visitor management process establishes controls for identifying, authorizing, recording, and monitoring individuals who are not regular authorized personnel. Depending on the facility, the process may involve identity verification, temporary badges, host confirmation, escort requirements, entry logs, and defined visitor restrictions. These measures help prevent unauthorized individuals from moving through controlled areas without appropriate oversight. Visitor management is especially important in facilities containing sensitive systems, records, or infrastructure. Physical security should use layered controls rather than relying on a single mechanism. Procedures should also address visitor badge return and the handling of unusual or unauthorized access attempts.

Question 75

Why are environmental monitoring controls used in critical facilities?

  1. To detect conditions that could damage equipment or disrupt operations
  2. To approve software licenses
  3. To authenticate remote users
  4. To classify employee records

Correct Answer: 1

Explanation:

Environmental monitoring controls help identify physical conditions that could negatively affect equipment, facilities, or business operations. Depending on the environment, monitoring may include temperature, humidity, smoke, water leakage, power conditions, or other relevant factors. Early detection can allow personnel to respond before conditions cause significant damage or service interruption. Critical facilities often combine monitoring with alarms, cooling systems, fire protection, backup power, and other safeguards. The specific environmental requirements depend on the equipment and facility design. Monitoring data should also be reviewed and connected to appropriate response procedures so alerts lead to meaningful action.

Question 76

Which technology provides temporary electrical power during a short interruption to allow systems to remain operational?

  1. Firewall appliance
  2. Data diode
  3. Uninterruptible power supply
  4. Network tap

Correct Answer: 3

Explanation:

An uninterruptible power supply, or UPS, provides temporary electrical power when the primary power source fails or becomes unstable. A UPS can help protect critical equipment from abrupt shutdowns and may provide enough runtime for systems to continue operating briefly or for an orderly shutdown to occur. Depending on the design, UPS systems can also help address certain power-quality issues. They are not equivalent to long-duration generators, which can sustain operations for much longer periods when appropriately fueled. Critical environments often combine UPS systems with generators and monitoring to create layered power-resilience capabilities.

Question 77

What security objective is supported by synchronized system clocks across an enterprise?

  1. More accurate event correlation
  2. Higher disk capacity
  3. Faster software compilation
  4. Larger network packets

Correct Answer: 4

Explanation:

Accurate and synchronized system clocks improve the reliability of security logs and make it easier to correlate events across multiple systems. When timestamps differ significantly, investigators may struggle to determine the actual sequence of actions during an incident. Network Time Protocol, or NTP, is commonly used to synchronize clocks with trusted time sources. Time synchronization supports incident investigation, monitoring, authentication mechanisms, compliance activities, and operational troubleshooting. Organizations should protect their time infrastructure and establish appropriate sources and configuration standards. Consistent timestamps are particularly valuable when analyzing events collected from endpoints, servers, network devices, and security platforms.

Question 78

Which monitoring practice helps identify suspicious relationships among events from different security sources?

  1. Manual file renaming
  2. Event correlation
  3. Printer maintenance
  4. Storage formatting

Correct Answer: 2

Explanation:

Event correlation analyzes multiple security events to identify relationships or patterns that may indicate suspicious activity. For example, an unusual authentication event followed by privilege changes and unexpected network communication may be more significant when considered together than when each event is viewed independently. Correlation rules are commonly implemented within centralized monitoring platforms such as SIEM systems. Effective correlation requires useful data sources, accurate timestamps, appropriate detection logic, and ongoing tuning. Poorly designed rules can create excessive false positives or overlook meaningful activity. Analysts should therefore regularly evaluate detection quality and adjust rules as environments change.

Question 79

Which metric is most useful for measuring how quickly a security team acknowledges reported incidents?

  1. Mean time to acknowledge
  2. Number of office chairs
  3. Total storage capacity
  4. Annual hardware count

Correct Answer: 3

Explanation:

Mean time to acknowledge, or MTTA, measures the average time taken for a security team or designated responder to recognize and acknowledge reported alerts or incidents. Tracking this metric can help organizations evaluate responsiveness and identify delays in monitoring or escalation processes. MTTA should be interpreted alongside other measurements because fast acknowledgment does not necessarily mean an incident was investigated or resolved effectively. Organizations may also track metrics such as mean time to detect, contain, or recover. Useful security metrics should connect operational activity with meaningful objectives and should be reviewed in context rather than treated as isolated performance numbers.

Question 80

What is the primary purpose of conducting a post-incident lessons-learned review?

  1. To assign blame without analysis
  2. To identify improvements for future prevention and response
  3. To permanently disable monitoring
  4. To remove all incident records

Correct Answer: 1

Explanation:

A lessons-learned review examines what happened during an incident, how the organization responded, what worked well, and where improvements are needed. The goal is to strengthen future prevention, detection, response, and recovery rather than simply assigning blame. Findings may lead to changes in technical controls, procedures, training, architecture, communication processes, or response plans. Reviews should be based on evidence and involve relevant stakeholders. Documenting improvement actions is important because identifying a weakness without assigning ownership or follow-up may not produce meaningful change. Lessons learned therefore help turn individual incidents into broader organizational security improvements.