View Full Cyber AB CCP Exam Dumps and Practice Test Dumps
Question 201
What is the primary purpose of a security gap analysis?
- Identify differences between current and desired security capabilities
- Calculate the resale value of retired equipment
- Determine employee payroll deductions
- Replace incident response procedures
Correct Answer: 1
Explanation:
A security gap analysis compares an organization’s current security capabilities with a defined target state, requirement, framework, or control objective. The purpose is to identify areas where existing practices do not adequately meet expectations. Findings may involve missing controls, insufficient documentation, outdated technology, unclear responsibilities, or weaknesses in operational processes. Once gaps are identified, the organization can prioritize remediation according to risk and business importance. A gap analysis is therefore useful for security improvement planning and compliance preparation. It does not itself implement controls; instead, it provides a structured view of where improvements may be necessary.
Question 202
What is a key characteristic of a key risk indicator (KRI)?
- It measures employee productivity
- It provides an early signal of increasing risk exposure
- It records every firewall configuration
- It determines application licensing costs
Correct Answer: 3
Explanation:
A key risk indicator, or KRI, is a metric used to provide visibility into changing levels of risk. Organizations can establish thresholds that indicate when exposure is increasing and may require management attention. For example, a rising number of unsupported systems or unresolved critical findings could serve as a risk indicator. KRIs differ from key performance indicators, which generally measure progress or performance against objectives. A useful KRI should be relevant to the risk being monitored and actionable when thresholds are exceeded. Regular review of KRIs can help organizations identify emerging concerns before they become significant incidents.
Question 203
What is a corrective action plan primarily intended to document?
- Completed employee training records
- Approved software purchases
- Steps and responsibilities for resolving identified deficiencies
- Physical locations of network cables
Correct Answer: 4
Explanation:
A corrective action plan documents how identified weaknesses or deficiencies will be addressed. It commonly identifies the issue, required remediation, responsible parties, expected completion dates, priorities, and validation activities. A well-managed plan provides accountability and allows security teams and management to track remediation progress. Corrective action plans may result from audits, assessments, incidents, vulnerability reviews, or control testing. Simply recording a deficiency does not resolve it. Organizations should monitor outstanding actions and verify completion rather than relying solely on self-reported status. This approach supports continuous improvement and helps prevent recurring security problems.
Question 204
What does continuous improvement in a security program emphasize?
- Replacing every security tool annually
- Repeatedly evaluating results and improving processes
- Avoiding all changes to established controls
- Removing measurement from security activities
Correct Answer: 2
Explanation:
Continuous improvement means regularly evaluating security processes, controls, results, and lessons learned to identify opportunities for improvement. Security environments change as technologies, threats, regulations, business operations, and organizational priorities evolve. A control that was appropriate previously may become less effective as circumstances change. Continuous improvement uses evidence from assessments, incidents, metrics, testing, and operational experience to refine the security program. It does not require replacing every technology or changing controls without justification. Instead, improvements should be based on observed needs and risk. This approach helps maintain security effectiveness over time rather than treating security as a one-time project.
Question 205
Why are security metrics useful to management?
- They provide measurable information about security performance or risk
- They eliminate the need for security policies
- They guarantee that incidents cannot occur
- They automatically approve risk exceptions
Correct Answer: 1
Explanation:
Security metrics provide measurable information that can help management understand security performance, control operation, trends, or risk exposure. Useful metrics should connect to meaningful objectives and support decisions rather than simply counting activity. Examples might include remediation times, control-test results, unresolved findings, or incident trends. Metrics should be interpreted in context because a single number rarely represents the complete security situation. Poorly selected metrics can encourage teams to optimize for measurement rather than actual security outcomes. Effective reporting combines relevant measurements with appropriate thresholds, trends, and explanations so decision-makers can understand what the information means.
Question 206
What is the purpose of a security maturity assessment?
- Measure the physical capacity of security equipment
- Evaluate how developed and consistent security capabilities are
- Identify employees with administrative privileges
- Determine the age of an organization’s network
Correct Answer: 2
Explanation:
A security maturity assessment evaluates how developed, repeatable, and consistently managed an organization’s security capabilities are. Rather than focusing only on whether an individual control exists, maturity assessments can examine governance, processes, measurement, automation, documentation, and continuous improvement. Results can help organizations identify areas where practices are informal, inconsistent, or insufficiently managed. Maturity should be evaluated against a defined model or set of criteria because expectations vary between organizations. The assessment can then support improvement planning and prioritization. It is not simply an inventory of technology or privileged accounts.
Question 207
What is the main purpose of privacy by design?
- Address privacy considerations during system and process development
- Delay privacy reviews until after deployment
- Remove privacy requirements from software specifications
- Store personal information indefinitely
Correct Answer: 3
Explanation:
Privacy by design incorporates privacy considerations into the planning and development of systems, products, and processes rather than treating privacy as an afterthought. Teams can consider data minimization, access, retention, transparency, purpose, and user impacts while requirements are still being defined. Addressing these issues early can reduce costly redesign and help prevent unnecessary collection or exposure of personal information. Privacy by design does not mean eliminating useful data processing; instead, it encourages organizations to build appropriate safeguards into normal operations. Security and privacy teams can collaborate with developers and business stakeholders to incorporate these considerations into system requirements.
Question 208
Which practice supports data minimization?
- Collecting every available customer attribute
- Gathering only information necessary for a defined purpose
- Retaining obsolete records without review
- Replicating personal information to every department
Correct Answer: 2
Explanation:
Data minimization means limiting the collection and processing of personal information to what is necessary for a defined and legitimate purpose. Organizations can apply this principle by identifying required data elements before designing forms, databases, and workflows. Collecting less information can reduce storage requirements, exposure, and the potential impact of a breach. Data minimization should be considered alongside retention, access, accuracy, and purpose requirements. It does not mean that organizations must avoid collecting all personal information; rather, the focus is on avoiding unnecessary data. Periodic reviews can determine whether previously collected information is still needed.
Question 209
What is consent management primarily concerned with?
- Recording and handling individuals’ permissions for specified data processing
- Configuring router firmware
- Measuring server processor utilization
- Scheduling physical security patrols
Correct Answer: 1
Explanation:
Consent management involves obtaining, recording, maintaining, and appropriately using an individual’s permission when consent is the applicable legal basis for processing personal information. A sound process should make the purpose understandable and maintain evidence of what was agreed to. Where applicable, individuals should also have mechanisms to withdraw consent, and systems should be able to reflect changes in permission. Consent is not automatically required for every type of processing because legal requirements vary by jurisdiction and circumstance. Organizations should therefore identify the appropriate legal basis and ensure that consent mechanisms accurately reflect the processing activities they govern.
Question 210
What is a data processing inventory used to document?
- Physical locations of security cameras
- How an organization collects, uses, stores, and shares personal information
- Employee performance rankings
- Software license expiration dates
Correct Answer: 4
Explanation:
A data processing inventory provides structured information about how an organization handles personal information. Depending on organizational and regulatory requirements, it may document categories of data, processing purposes, systems involved, recipients, retention periods, locations, and responsible parties. Maintaining this information helps organizations understand their privacy landscape and identify areas requiring additional safeguards or review. It can also support regulatory inquiries, privacy assessments, data-subject requests, and internal governance. The inventory should be maintained as processing activities change. Without accurate documentation, organizations may struggle to determine where personal information resides and how it moves through business processes.
Question 211
What is anonymization intended to accomplish?
- Make information permanently unavailable to administrators
- Remove or transform identifiers so individuals are no longer reasonably identifiable
- Convert all records into encrypted archives
- Restrict access to database administrators
Correct Answer: 2
Explanation:
Anonymization aims to process information so that individuals can no longer be reasonably identified from the resulting data, considering the means reasonably available for re-identification. This differs from pseudonymization, where identifying information is replaced but additional information may still allow the original identity to be recovered. Effective anonymization requires careful consideration of direct identifiers, indirect attributes, combinations of data, and external information that could enable re-identification. Organizations should evaluate whether the chosen technique actually achieves the intended level of anonymity. Simply removing names may not be sufficient when other attributes can still identify an individual.
Question 212
What is data accuracy primarily concerned with?
- Ensuring information remains correct and reliable for its intended use
- Increasing the number of stored copies
- Encrypting every network connection
- Limiting access to office buildings
Correct Answer: 3
Explanation:
Data accuracy concerns whether information is correct, reliable, and suitable for its intended purpose. Inaccurate personal or business information can lead to incorrect decisions, operational problems, customer issues, or compliance concerns. Organizations can support accuracy through validation, verification, update processes, error correction mechanisms, and appropriate ownership. Accuracy should be considered throughout the information lifecycle because data can become outdated or incorrect as circumstances change. Security controls such as access restrictions can reduce unauthorized modification, but they do not automatically guarantee that information is accurate. Organizations should establish processes for identifying and correcting inaccurate information.
Question 213
Why is a data retention schedule established?
- To define how long specific information should be retained
- To guarantee unlimited storage capacity
- To prevent employees from accessing current records
- To replace backup procedures
Correct Answer: 4
Explanation:
A data retention schedule defines how long particular categories of information should be retained and when they should be securely disposed of, subject to applicable legal, regulatory, contractual, and business requirements. Retaining information indefinitely can increase storage costs and exposure while potentially creating additional privacy and compliance risks. A retention schedule provides a structured approach for determining when information should remain available and when it should be deleted or destroyed. Retention requirements should be coordinated with legal holds, business needs, and backup practices. Secure disposal should occur when the approved retention period ends and no overriding requirement exists.
Question 214
What is a legal hold intended to prevent?
- Routine deletion of information that may be relevant to legal proceedings
- Unauthorized changes to firewall rules
- Loss of wireless connectivity
- Expiration of software subscriptions
Correct Answer: 1
Explanation:
A legal hold preserves potentially relevant information when litigation, investigation, or another legal matter requires that ordinary disposal processes be suspended. Information subject to a hold may otherwise be deleted automatically under normal retention schedules. Organizations may need to identify relevant systems, records, custodians, and data sources and ensure that preservation requirements are communicated and maintained. A legal hold can override routine retention-based deletion for the information within its scope. Because legal requirements differ by jurisdiction and case, organizations commonly coordinate legal, records-management, privacy, and technical teams when implementing preservation requirements.
Question 215
What is coordinated vulnerability disclosure intended to facilitate?
- Secret publication of vulnerabilities without vendor contact
- Structured communication between researchers and affected parties
- Permanent suppression of security findings
- Automatic exploitation of discovered weaknesses
Correct Answer: 2
Explanation:
Coordinated vulnerability disclosure provides a structured approach for reporting security weaknesses to affected vendors or organizations and working toward appropriate remediation or communication. A researcher can provide relevant technical information while the affected party investigates, develops a fix, and prepares suitable guidance. Coordination can reduce unnecessary exposure before a mitigation is available while still supporting responsible communication with the security community. Effective processes usually define reporting channels, response expectations, communication responsibilities, and disclosure timelines. Organizations should make reporting mechanisms accessible and should treat credible vulnerability reports as valuable security information rather than automatically dismissing them.
Question 216
What is the purpose of a vulnerability disclosure policy?
- Define how security researchers can report discovered weaknesses
- Specify employee parking assignments
- Determine daily server temperatures
- Establish accounting depreciation rates
Correct Answer: 3
Explanation:
A vulnerability disclosure policy explains how external or internal researchers can report suspected security weaknesses to an organization. It may identify approved reporting channels, expected information, communication procedures, scope, and organizational commitments concerning submitted reports. Providing a clear process can encourage responsible reporting and reduce uncertainty about how researchers should communicate security findings. Some organizations also establish rules describing systems or testing activities that fall within an authorized scope. A disclosure policy does not guarantee that every report is valid or immediately remediated, but it creates a structured mechanism for receiving and managing vulnerability information.
Question 217
What does supply-chain security primarily address?
- Risks introduced through suppliers, software, services, or external dependencies
- Risks caused only by office lighting
- Employee attendance tracking
- Internal document formatting
Correct Answer: 4
Explanation:
Supply-chain security addresses risks that can enter an organization through external providers, software components, hardware, managed services, contractors, and other dependencies. Organizations may rely on suppliers for critical technology or services, meaning a weakness at an external party can affect internal operations. Security measures can include supplier due diligence, contractual requirements, software component visibility, access restrictions, monitoring, incident notification clauses, and ongoing assessments. Supply-chain risk is broader than vendor reputation alone. Organizations should understand which dependencies are critical and what protections are expected from those providers. Strong supplier governance can reduce exposure created by external relationships.
Question 218
What is fourth-party risk?
- Risk created by an organization’s direct employees
- Risk arising from a supplier’s own suppliers or service providers
- Risk caused by outdated internal passwords
- Risk associated with office furniture
Correct Answer: 3
Explanation:
Fourth-party risk refers to risk introduced by entities further down an organization’s supply chain, such as a direct supplier’s subcontractors, cloud providers, software dependencies, or other external service providers. An organization may not have a direct contractual relationship with these parties, making visibility more difficult. Understanding critical downstream dependencies can help identify concentration, availability, privacy, security, and operational risks. Organizations can address fourth-party concerns through supplier requirements, contractual flow-down provisions, risk assessments, dependency inventories, and notification obligations. The importance of fourth-party oversight increases when critical services depend heavily on multiple layers of external providers.
Question 219
Why are security requirements often included in supplier contracts?
- To establish enforceable expectations for protecting organizational information and services
- To eliminate the supplier’s responsibility for security
- To prevent all future technology changes
- To guarantee that no security incident can ever occur
Correct Answer: 2
Explanation:
Security requirements in supplier contracts establish documented expectations that a provider must meet when handling organizational information, systems, or services. Contractual provisions may address access controls, confidentiality, incident notification, vulnerability management, data handling, audit rights, subcontractors, and secure disposal. Clearly written requirements make responsibilities more explicit and provide a basis for monitoring or addressing noncompliance. Contracts cannot guarantee that incidents will never occur, but they can establish obligations and response expectations. Organizations should also review whether suppliers continue meeting requirements throughout the relationship rather than assuming contractual language alone provides sufficient protection.
Question 220
What is a security addendum commonly used for in a supplier agreement?
- To document additional security obligations for the provider
- To replace the organization’s entire procurement process
- To approve employee vacation requests
- To define office seating arrangements
Correct Answer: 1
Explanation:
A security addendum supplements a primary supplier or service agreement with specific cybersecurity and information-protection requirements. It can define obligations related to authentication, data protection, incident reporting, vulnerability management, access controls, security assessments, subcontractors, and other safeguards relevant to the service. A security addendum is useful when standard commercial terms do not contain sufficient technical or security detail. The requirements should correspond to the nature and risk of the service being provided. Organizations should also ensure that responsibilities are understandable, measurable, and enforceable so security expectations are not left as informal assumptions between the parties.