Cyber AB CCP Practice Test Questions and Exam Dumps Part14 Q261-280

View Full Cyber AB CCP Exam Dumps and Practice Test Dumps

 

Question 261

What is identity proofing intended to establish?

  1. That a person is the legitimate individual they claim to be
  2. That an account has unlimited privileges
  3. That a device has no vulnerabilities
  4. That a network connection is encrypted

Correct Answer: 1

Explanation:

Identity proofing is the process of establishing confidence that an individual is genuinely the person they claim to be before an identity or credential is issued. Organizations may use government-issued documents, trusted records, biometric checks, knowledge-based information, or other verification methods depending on the required assurance level. Identity proofing is different from authentication, which verifies an identity during access. Strong proofing helps prevent fraudulent identities from entering an organization’s identity system. The appropriate process depends on risk, regulatory obligations, privacy considerations, and the sensitivity of the resources the identity may eventually access.

Question 262

What does a joiner-mover-leaver process manage?

  1. Network bandwidth allocation
  2. User access throughout employment or affiliation changes
  3. Encryption key mathematics
  4. Physical server cooling

Correct Answer: 3

Explanation:

A joiner-mover-leaver process manages access as a person’s relationship with an organization changes. When someone joins, appropriate accounts and permissions should be provisioned. When responsibilities change, unnecessary privileges should be removed and new access should be granted according to the person’s role. When someone leaves, accounts, credentials, tokens, and other access mechanisms should be disabled or revoked promptly. This lifecycle approach reduces the chance of orphaned accounts and excessive privileges. Effective processes require coordination between human resources, managers, IT, security, and other relevant functions so that access changes occur consistently and are supported by reliable records.

Question 263

What is a compensating measure used for?

  1. Provide alternative protection when a required control cannot be implemented as intended
  2. Remove the need to identify security risks
  3. Increase the number of privileged accounts
  4. Replace every security policy with a guideline

Correct Answer: 4

Explanation:

A compensating measure provides alternative protection when the preferred or required control cannot be implemented because of technical, operational, or business constraints. For example, if a legacy application cannot support a required authentication mechanism, additional network restrictions, monitoring, or other safeguards might reduce the associated risk. A compensating measure should be appropriate to the risk and documented with clear ownership and review requirements. It should not simply be used as a permanent excuse to ignore security requirements. Organizations should periodically reassess whether the original limitation still exists and whether the alternative protection remains effective.

Question 264

What does control effectiveness testing evaluate?

  1. Whether a control exists in documentation
  2. Whether a control operates as intended
  3. Whether employees prefer the control
  4. Whether the control has the lowest possible cost

Correct Answer: 2

Explanation:

Control effectiveness testing evaluates whether a security or compliance control operates as intended and provides the expected protection. Testing may examine configuration settings, transaction samples, system records, approvals, interviews, observations, or other evidence. A control can be well designed but ineffective in practice if it is not consistently performed or if implementation differs from its documented requirements. Testing therefore considers actual operation rather than documentation alone. Results can identify deficiencies that require remediation, additional monitoring, or changes to the control design. Testing frequency should generally reflect the importance and risk associated with the control.

Question 265

What is continuous control monitoring designed to support?

  1. Ongoing visibility into control operation
  2. Permanent suspension of security testing
  3. Automatic removal of audit requirements
  4. Elimination of all manual oversight

Correct Answer: 4

Explanation:

Continuous control monitoring uses automated or recurring techniques to provide ongoing visibility into whether important controls continue to operate as expected. Examples include monitoring configuration states, access settings, security events, compliance conditions, or system changes. Unlike a periodic assessment that examines a point in time, continuous monitoring can identify deviations more quickly. It does not necessarily eliminate human oversight because unusual conditions often require investigation and judgment. Effective monitoring depends on meaningful control indicators, reliable data sources, suitable thresholds, and defined response procedures. Organizations should also review monitoring logic periodically to ensure that it remains aligned with current risks.

Question 266

Why is asset criticality useful when prioritizing security activities?

  1. It identifies which resources could cause greater business impact if disrupted
  2. It determines employee vacation schedules
  3. It eliminates the need for asset ownership
  4. It guarantees that every vulnerability receives identical treatment

Correct Answer: 1

Explanation:

Asset criticality helps organizations understand which systems, applications, information repositories, or services are particularly important to business operations. A highly critical asset may support essential services, contain sensitive information, or have significant operational dependencies. Knowing asset criticality allows security teams to prioritize protection, monitoring, vulnerability remediation, recovery planning, and other activities according to potential impact. Criticality should be determined using business context rather than technical characteristics alone. Organizations should also review classifications when business processes change. A system that was previously considered moderate in importance may become critical after new dependencies or business functions are introduced.

Question 267

What is a configuration management database commonly used to maintain?

  1. Marketing campaign statistics
  2. Employee attendance records
  3. Information about configuration items and their relationships
  4. Password recovery questions

Correct Answer: 3

Explanation:

A configuration management database, or CMDB, stores information about configuration items and can document relationships among them. Configuration items may include servers, applications, databases, network devices, services, or other technology components. Understanding these relationships can help organizations assess the potential impact of changes, outages, vulnerabilities, and dependencies. A CMDB is only useful when its information is reasonably accurate and maintained as the environment changes. It should not be confused with a simple hardware inventory because configuration management can include logical services and relationships. Organizations may integrate CMDB information with change management, incident management, and asset processes.

Question 268

What is a security exception register used to track?

  1. Approved deviations from established security requirements
  2. Routine software license purchases
  3. Employee training attendance only
  4. Unrelated business meeting schedules

Correct Answer: 2

Explanation:

A security exception register records approved deviations from established security requirements, policies, standards, or controls. It can capture the affected system or process, business justification, risk assessment, compensating measures, responsible owner, approval authority, and expiration or review date. Maintaining such a register prevents exceptions from becoming invisible or permanent by default. Security exceptions should be reviewed periodically because circumstances can change and the original justification may no longer apply. A well-managed register also provides useful information during audits and risk reviews by showing where the organization has consciously accepted or mitigated deviations from its normal security requirements.

Question 269

What is a security charter primarily intended to establish?

  1. The authority, responsibilities, and scope of a security function
  2. A list of software bugs
  3. A schedule for replacing office furniture
  4. A method for compressing databases

Correct Answer: 1

Explanation:

A security charter formally establishes the purpose, authority, responsibilities, and scope of a security function or program. It can clarify leadership responsibilities, reporting relationships, decision-making authority, and the organization’s expectations for security activities. A clear charter helps reduce ambiguity about who is accountable for security governance and what the security function is authorized to perform. The charter should align with organizational objectives and existing governance structures. It is different from a detailed security policy because it generally defines the mandate and authority of the function rather than specifying operational requirements for individual controls.

Question 270

Why might an organization establish a security steering committee?

  1. To manage employee payroll calculations
  2. To coordinate strategic security decisions across business functions
  3. To replace every technical security team
  4. To approve individual vacation requests

Correct Answer: 4

Explanation:

A security steering committee can provide cross-functional coordination for significant security decisions. Participants may include representatives from security, technology, legal, privacy, risk, compliance, and business leadership. Such a committee can help align security priorities with organizational objectives, review major risks, resolve competing priorities, and provide governance over significant initiatives. Its responsibilities should be clearly defined so that it complements rather than duplicates operational security teams. The committee should focus on appropriate strategic or governance matters rather than becoming a substitute for day-to-day technical operations.

Question 271

What is a control objective?

  1. A desired condition that a control is intended to achieve
  2. A list of employees authorized to enter a building
  3. A schedule for replacing network cables
  4. A record of completed help-desk tickets

Correct Answer: 2

Explanation:

A control objective describes the desired condition or outcome that a control is intended to achieve. For example, an objective may be to ensure that access to sensitive information is restricted to authorized users. Specific controls can then be designed and implemented to support that objective. Distinguishing objectives from individual controls helps organizations evaluate whether their security measures address the intended risk. Control objectives may be derived from organizational requirements, risk assessments, contractual obligations, regulations, or internal policies. Effective testing should consider whether implemented controls actually support the stated objective rather than merely checking whether a procedure exists.

Question 272

What is an indicator of attack intended to identify?

  1. A completed disaster recovery exercise
  2. A potential sign that malicious activity is occurring
  3. An employee’s annual performance review
  4. A routine software installation

Correct Answer: 3

Explanation:

An indicator of attack, or IOA, focuses on behavior or activity that may suggest an attack is taking place. Examples can include unusual process execution, suspicious privilege use, unexpected command activity, or other behaviors associated with attack techniques. IOAs differ from traditional indicators of compromise, which often focus on artifacts left behind by an attack, such as malicious files or known addresses. Behavioral indicators can be valuable because attackers may change specific tools or artifacts while continuing to use similar techniques. Security teams can use IOAs as part of detection, threat hunting, and investigation activities.

Question 273

Which malware type commonly disguises itself as legitimate software?

  1. Trojan
  2. Worm
  3. Boot sector virus
  4. Adware

Correct Answer: 4

Explanation:

A Trojan is malware that commonly presents itself as legitimate or useful software to persuade a user or administrator to execute it. Unlike worms, which are characterized by their ability to propagate between systems without requiring the same type of user deception, Trojans primarily rely on appearing trustworthy or useful. Once executed, a Trojan may perform different malicious activities depending on its design, including credential theft, remote access, or additional malware delivery. Security awareness, application controls, endpoint protection, and software provenance checks can help reduce exposure to Trojan-based attacks.

Question 274

What distinguishes a worm from many other malware types?

  1. It requires a physical security guard to spread
  2. It is designed only to encrypt backup tapes
  3. It can propagate across systems without requiring the same direct user action for each infection
  4. It can operate only inside removable media

Correct Answer: 1

Explanation:

A worm is malware capable of propagating from one system to another, often by exploiting vulnerabilities, weak credentials, or network-accessible services. A key characteristic is its ability to spread without requiring the same direct user action for each new infection. This can allow a worm outbreak to expand rapidly across interconnected environments. Organizations can reduce this risk through timely vulnerability remediation, network segmentation, access controls, endpoint protection, and monitoring for unusual propagation behavior. Because worms can move quickly, early detection and containment are especially important when multiple systems begin exhibiting related suspicious activity.

Question 275

What is vishing?

  1. A physical theft of network equipment
  2. A voice-based social engineering attempt
  3. A method for encrypting voice recordings
  4. A backup synchronization technique

Correct Answer: 2

Explanation:

Vishing is a form of social engineering that uses voice communication to deceive targets. An attacker may impersonate a bank employee, technical support representative, manager, or another trusted party and attempt to obtain credentials, payment information, authentication codes, or other sensitive details. Attackers may create urgency or use information gathered from other sources to make the conversation appear credible. Organizations can reduce exposure through awareness training, verification procedures, caller authentication practices, and policies that prohibit disclosure of sensitive information based solely on an unexpected call. Suspicious requests should be independently verified through trusted communication channels.

Question 276

What is QR phishing commonly intended to do?

  1. Direct users toward a fraudulent destination through a QR code
  2. Improve the resolution of security camera footage
  3. Encrypt a database backup
  4. Measure wireless signal strength

Correct Answer: 3

Explanation:

QR phishing, sometimes called quishing, uses QR codes as part of a phishing attempt. A malicious or deceptive QR code can direct a user to a fraudulent website, credential-harvesting page, or other attacker-controlled destination. Because users may scan codes using mobile devices, the destination can sometimes receive less scrutiny than a conventional web link. Security awareness should encourage users to verify unexpected QR codes and inspect destinations before providing credentials or sensitive information. Organizations can also use technical controls to detect malicious domains and strengthen authentication so that stolen passwords alone are less useful to attackers.

Question 277

What is pharming designed to accomplish?

  1. Redirect users from legitimate destinations toward fraudulent ones
  2. Increase database transaction speed
  3. Prevent all malware execution
  4. Generate stronger encryption keys

Correct Answer: 2

Explanation:

Pharming is an attack technique that redirects users from an intended legitimate destination to a fraudulent one. This can involve manipulation of name-resolution mechanisms, compromised infrastructure, or other techniques that cause a user to reach an attacker-controlled destination even when the user believes they entered the correct address. Strong DNS protections, secure endpoint configurations, certificate validation, and awareness can reduce exposure. Pharming differs from ordinary phishing because the redirection can occur through manipulated technical mechanisms rather than relying entirely on persuading a user to select a deceptive link.

Question 278

What is a cloud shared responsibility model intended to clarify?

  1. Which security responsibilities belong to the provider and which remain with the customer
  2. Which employees may work remotely
  3. Which applications require annual licensing
  4. Which office supplies should be purchased

Correct Answer: 4

Explanation:

A cloud shared responsibility model clarifies how security responsibilities are divided between a cloud service provider and its customer. The provider may be responsible for aspects of the underlying infrastructure, while the customer may remain responsible for identities, configurations, data, applications, or other components depending on the service model. Exact responsibilities vary among providers and services, so organizations must review the applicable service documentation rather than assuming that the provider handles all security matters. Understanding the division of responsibility helps prevent gaps caused by assuming another party is protecting a resource that remains under organizational control.

Question 279

What is cloud misconfiguration a security concern because it can?

  1. Automatically improve application security
  2. Expose resources or information unintentionally
  3. Prevent every unauthorized login
  4. Eliminate the need for identity management

Correct Answer: 3

Explanation:

Cloud misconfiguration occurs when cloud resources, permissions, network settings, storage, or other services are configured in an insecure or unintended manner. Examples can include excessive permissions, publicly accessible storage, exposed management interfaces, or improperly configured security groups. Because cloud environments can be highly dynamic, configuration errors may be introduced during deployment or change activities. Organizations can reduce this risk through secure baselines, automated configuration checks, infrastructure-as-code controls, continuous monitoring, least privilege, and regular reviews. Cloud security responsibilities remain shared, so customers must understand and manage the settings that fall within their responsibility.

Question 280

What does cloud security posture management primarily help organizations do?

  1. Monitor cloud configurations and identify security or compliance weaknesses
  2. Manufacture physical data-center hardware
  3. Replace all identity providers
  4. Design employee compensation plans

Correct Answer: 1

Explanation:

Cloud security posture management, or CSPM, helps organizations continuously assess cloud environments for configuration weaknesses, policy violations, and certain security or compliance issues. CSPM capabilities can identify resources that deviate from established requirements and may provide visibility across multiple cloud services or accounts. Organizations can use findings to prioritize remediation based on risk and business impact. CSPM does not automatically solve every cloud security problem and should complement identity controls, vulnerability management, logging, workload protection, and other security measures. Effective use also requires well-defined configuration expectations so that detected deviations can be evaluated appropriately.