View Full Cyber AB CCP Exam Dumps and Practice Test Dumps
Question 241
What is the main purpose of a control self-assessment?
- Allow control owners to evaluate their own control environment
- Replace every independent security audit
- Calculate equipment depreciation
- Approve employee promotions
Correct Answer: 1
Explanation:
A control self-assessment allows personnel responsible for business or security processes to evaluate whether controls are appropriately designed and operating as expected. It can help identify weaknesses, documentation issues, process deviations, and areas requiring remediation before an independent assessment occurs. Self-assessments are valuable because control owners have direct knowledge of how processes operate in practice. However, they should not automatically replace independent testing because self-assessment can involve limited objectivity. Organizations may use structured questionnaires, evidence reviews, interviews, or sampling to perform these assessments. Results can then feed into corrective action and broader security improvement activities.
Question 242
Why is separation of duties important when approving security exceptions?
- It guarantees that exceptions never expire
- It reduces the chance that one person can approve and conceal an inappropriate exception
- It eliminates the need for documentation
- It prevents all policy changes
Correct Answer: 2
Explanation:
Separation of duties divides sensitive responsibilities among different individuals or roles so that one person does not have excessive control over an important process. For security exceptions, separating the request, review, and approval responsibilities can reduce the opportunity for inappropriate exceptions to be granted without scrutiny. The exact arrangement depends on organizational size and risk. Smaller organizations may use compensating oversight when complete separation is impractical. Separation of duties does not remove the need for documentation, expiration dates, or periodic review. Instead, it adds an accountability mechanism that makes sensitive decisions more difficult to manipulate without detection.
Question 243
What is a preventive control designed to do?
- Stop or reduce the likelihood of an unwanted event before it occurs
- Record evidence after a security incident
- Restore systems following a disaster
- Calculate annual security spending
Correct Answer: 1
Explanation:
Preventive controls are designed to stop an unwanted event or reduce its likelihood before it occurs. Examples include access restrictions, secure configuration requirements, network segmentation, authentication mechanisms, and application allowlisting. Preventive controls differ from detective controls, which identify events or conditions after or while they occur, and corrective controls, which address problems after identification. No preventive control is guaranteed to stop every threat, so organizations typically use multiple layers of protection. Their effectiveness should also be tested periodically because changes in technology, user behavior, and attack methods can reduce the protection originally expected.
Question 244
What is a detective control primarily intended to accomplish?
- Prevent users from accessing every external website
- Identify suspicious or unauthorized activity
- Restore deleted information automatically
- Establish annual procurement budgets
Correct Answer: 2
Explanation:
Detective controls are intended to identify suspicious events, unauthorized activity, or deviations from expected conditions. Examples include security monitoring, intrusion detection, audit-log review, file integrity monitoring, and alerting mechanisms. Detective controls are particularly important because preventive measures may fail or be bypassed. Once suspicious activity is identified, organizations can initiate investigation, containment, and corrective actions. Effective detective controls depend on appropriate data sources, meaningful detection logic, and timely response. Simply collecting large amounts of information does not guarantee effective detection. Monitoring should focus on events that are relevant to the organization’s risks and security objectives.
Question 245
Why is control evidence retained during an audit?
- To demonstrate that required controls were implemented or operated
- To increase the number of security policies
- To replace employee background checks
- To eliminate all audit findings
Correct Answer: 3
Explanation:
Control evidence provides objective support for determining whether a control exists, was implemented, or operated during a relevant period. Evidence may include system records, approval records, configuration outputs, review logs, tickets, reports, or other documented information. Auditors use appropriate evidence to support their conclusions rather than relying solely on verbal claims. The quality and relevance of evidence matter because incomplete or unreliable records may not adequately demonstrate control operation. Evidence should also be protected from unauthorized alteration and retained according to applicable requirements. Maintaining organized evidence can make assessments more efficient and improve accountability for control owners.
Question 246
What is audit sampling used to accomplish?
- Review every transaction without exception
- Select representative items for testing
- Remove the need for audit evidence
- Approve security policies automatically
Correct Answer: 4
Explanation:
Audit sampling involves selecting a subset of items from a larger population for testing. Instead of examining every transaction, access record, or control instance, an auditor can use an appropriate sampling method to obtain evidence about the broader population. The sample should be selected using a defensible methodology that considers factors such as population size, risk, expected error rates, and required confidence. Poor sampling can produce misleading conclusions if the selected items are not representative. Sampling does not eliminate evidence requirements; the selected items still need to be examined and documented appropriately.
Question 247
What is an audit trail primarily intended to provide?
- A chronological record of relevant activities or transactions
- A list of future software purchases
- A replacement for access controls
- A schedule of employee holidays
Correct Answer: 1
Explanation:
An audit trail records activities or transactions in a way that supports later review and investigation. Depending on the environment, it may capture user actions, system changes, approvals, transactions, or access events. Audit trails can help establish what happened, when it happened, and sometimes which account or system performed the action. Their usefulness depends on accurate timestamps, appropriate event coverage, protection against unauthorized alteration, and suitable retention. Audit trails support accountability and investigations but should not be confused with preventive controls. Organizations should determine which activities require logging based on security, operational, legal, and compliance requirements.
Question 248
What is log normalization intended to improve?
- The physical storage capacity of a server
- The consistency of data formats across log sources
- The strength of user passwords
- The speed of software compilation
Correct Answer: 2
Explanation:
Log normalization converts information from different log sources into a more consistent structure or format. Different applications, operating systems, and security devices may record similar events using different field names, timestamp formats, or representations. Normalization makes it easier for monitoring platforms to correlate and analyze events across those sources. For example, user identity, source address, destination, event type, and timestamp can be represented consistently. Normalization does not itself determine whether an event is malicious. Instead, it improves the ability of security tools and analysts to process information consistently and build useful detection or correlation rules.
Question 249
Why should audit logs be protected from unauthorized modification?
- Altered logs can undermine their reliability as evidence
- Modified logs always improve system performance
- Unprotected logs eliminate network latency
- Changing logs automatically fixes security incidents
Correct Answer: 1
Explanation:
Audit logs are valuable for accountability, investigation, troubleshooting, and compliance, so their integrity must be protected. If unauthorized individuals can modify or delete records, important evidence may be concealed or misleading information may be introduced. Organizations can protect logs through access restrictions, centralized collection, integrity controls, write-protected storage, appropriate retention, and monitoring of administrative activity. Time synchronization also improves the usefulness of records from multiple systems. Log protection should cover both the collection process and the storage environment. Reliable logs can provide important evidence when reconstructing events or determining whether security controls operated as expected.
Question 250
What is alert fatigue in a security operations environment?
- Reduced analyst effectiveness caused by excessive or low-value alerts
- A hardware failure caused by excessive cooling
- A method for encrypting monitoring data
- A procedure for restoring archived files
Correct Answer: 2
Explanation:
Alert fatigue occurs when security personnel receive so many alerts, particularly low-value or repetitive ones, that distinguishing genuinely important events becomes difficult. Excessive alerts can consume analyst attention and increase the risk that a serious event is overlooked. Organizations can reduce alert fatigue by tuning detection rules, prioritizing alerts using risk context, removing unnecessary notifications, improving correlation, and regularly reviewing detection performance. The goal is not simply to reduce the number of alerts but to improve their usefulness. Effective alert management combines technology with clear triage procedures and escalation criteria.
Question 251
What is an escalation matrix used for during incident handling?
- Define who should be notified or involved at different severity levels
- Determine the encryption algorithm for backups
- Assign permanent workstation locations
- Replace the organization’s asset inventory
Correct Answer: 1
Explanation:
An escalation matrix defines which individuals, teams, managers, or specialized functions should become involved when an incident reaches particular severity or impact levels. It can identify technical contacts, management authorities, legal personnel, privacy teams, communications staff, or external parties where appropriate. A clear matrix reduces uncertainty during high-pressure situations and helps ensure that significant incidents receive timely attention. Escalation criteria should be based on factors such as business impact, affected information, scope, regulatory considerations, and operational disruption. The matrix should be reviewed periodically because organizational roles and contact information can change.
Question 252
What should an incident communication plan establish?
- Approved communication channels, responsibilities, and notification procedures
- The maximum size of email attachments
- A list of employee performance ratings
- The physical dimensions of the security office
Correct Answer: 2
Explanation:
An incident communication plan establishes how information will be communicated during and after a security incident. It can identify authorized communicators, internal and external audiences, approved channels, notification requirements, escalation paths, and procedures for handling sensitive information. Clear communication helps prevent contradictory messages and ensures that relevant stakeholders receive appropriate information. Plans should account for situations in which normal communication systems are unavailable or compromised. Communication responsibilities should also be tested during exercises so participants understand their roles. The plan should complement technical incident response procedures rather than attempt to replace containment, investigation, or recovery activities.
Question 253
What is a warm site in disaster recovery?
- A partially prepared alternate facility requiring some additional setup
- A completely inactive location with no equipment
- A fully operational duplicate used without preparation
- A secure archive for paper documents
Correct Answer: 3
Explanation:
A warm site is an alternate recovery facility that has some infrastructure and equipment prepared but may require additional configuration, data restoration, or other work before normal operations can resume. It generally provides a balance between recovery speed and cost compared with other alternate-site approaches. A hot site is typically more immediately operational, while a cold site generally requires more extensive preparation. Organizations select recovery-site strategies according to business impact, recovery objectives, budget, and operational requirements. A warm site’s effectiveness depends on keeping equipment, connectivity, procedures, and recovery information sufficiently current.
Question 254
What does geographic redundancy provide?
- A method for assigning user permissions
- Additional resilience by maintaining resources in separate locations
- A replacement for vulnerability scanning
- A technique for compressing log files
Correct Answer: 4
Explanation:
Geographic redundancy places systems, services, data, or infrastructure in separate physical locations so that a localized disruption does not necessarily affect all copies simultaneously. Separation can help reduce exposure to events such as regional power failures, natural disasters, major network outages, or facility incidents. The appropriate degree of geographic separation depends on business requirements and threat scenarios. Redundant locations must also be considered from a security, synchronization, dependency, and recovery perspective. Simply having multiple copies in the same geographic area may not provide meaningful protection against a regional event.
Question 255
Why are recovery runbooks useful?
- They provide documented steps for performing recovery activities
- They eliminate the need to test recovery procedures
- They replace all backup technologies
- They guarantee that every recovery will succeed
Correct Answer: 3
Explanation:
Recovery runbooks provide documented, ordered instructions for restoring systems or services after a disruption. They can identify prerequisites, responsible roles, dependencies, commands, validation steps, and escalation points. Detailed runbooks reduce reliance on individual memory during stressful recovery situations and can help teams perform activities consistently. However, documentation can become inaccurate if systems change, so runbooks should be reviewed and exercised periodically. Testing can reveal missing steps, outdated dependencies, or unclear responsibilities. A runbook supports recovery but does not replace backups, redundancy, trained personnel, or appropriate continuity planning.
Question 256
What is replication primarily used to accomplish in a resilient architecture?
- Create additional copies of data or services across systems
- Restrict users from accessing applications
- Detect phishing messages
- Replace physical security controls
Correct Answer: 4
Explanation:
Replication creates additional copies of data, services, or system state across different systems or locations. It can support availability, disaster recovery, and continuity by allowing operations to continue or be restored when a primary resource becomes unavailable. Replication methods vary in timing and architecture, including synchronous and asynchronous approaches. Organizations must consider consistency, network dependencies, security, and recovery requirements when designing replication. Replication is not the same as a complete backup strategy because replicated changes, including accidental deletion or corruption, may also propagate. Appropriate recovery points and independent recovery mechanisms remain important.
Question 257
What is a snapshot commonly used for?
- Capture the state of a system or data set at a particular point in time
- Approve new employee accounts
- Authenticate wireless devices
- Monitor physical temperature sensors
Correct Answer: 1
Explanation:
A snapshot captures the state of a system, volume, virtual machine, or data set at a particular point in time. Snapshots can support rapid rollback, testing, recovery from certain changes, and operational troubleshooting. However, snapshot implementations vary, and many depend on the underlying storage system or infrastructure. A snapshot should not automatically be considered an independent backup because it may remain within the same failure domain as the original data. Organizations should evaluate whether snapshots meet their recovery requirements and maintain separate backup mechanisms when necessary. Security controls should also protect snapshots because they may contain sensitive information.
Question 258
What is a business continuity plan primarily concerned with?
- Maintaining or restoring critical business functions during disruption
- Configuring individual employee laptops
- Ranking software vulnerabilities
- Managing application source-code branches
Correct Answer: 2
Explanation:
A business continuity plan focuses on maintaining or restoring critical business functions when disruptive events affect normal operations. It considers essential processes, dependencies, personnel, facilities, technology, communications, and alternative operating arrangements. Business continuity is broader than technical disaster recovery because many disruptions involve people, suppliers, facilities, or business processes rather than technology alone. Plans should identify priorities and responsibilities and should be exercised periodically. Testing can reveal unrealistic assumptions or missing dependencies. A continuity plan should also be updated when important business processes, organizational structures, technology platforms, or external dependencies change.
Question 259
What is the primary focus of disaster recovery planning?
- Restoring technology and services after a disruptive event
- Designing employee compensation packages
- Selecting office furniture
- Creating product advertising campaigns
Correct Answer: 3
Explanation:
Disaster recovery planning focuses on restoring technology, systems, applications, and supporting services after a disruptive event. It typically addresses recovery priorities, dependencies, backup resources, recovery procedures, responsibilities, communication, and validation. Disaster recovery is closely related to business continuity but generally emphasizes restoration of technology and operational capabilities. Recovery plans should reflect defined recovery objectives and business priorities. Regular testing is essential because procedures that appear correct on paper may fail when dependencies, credentials, configurations, or contact information have changed. Lessons from exercises and real incidents should be incorporated into subsequent revisions.
Question 260
What is a recovery validation step intended to confirm?
- That restored systems are functioning correctly and securely
- That every employee has changed jobs
- That all archived files have been deleted
- That physical office space has increased
Correct Answer: 4
Explanation:
Recovery validation confirms that restored systems or services are actually functioning as required after recovery activities. Validation may include checking application availability, data integrity, authentication, network connectivity, security controls, configuration settings, and business functionality. Simply bringing a server online does not prove that the service has been successfully recovered. Validation should therefore involve appropriate technical and business stakeholders who can confirm that critical functions operate correctly. Any discovered problems should be documented and addressed before the recovery is considered complete. These checks help prevent organizations from declaring recovery successful while important dependencies or security controls remain impaired.