Cyber AB CCP Practice Test Questions and Exam Dumps Part17 Q321-340

View Full Cyber AB CCP Exam Dumps and Practice Test Dumps

 

Question 321

What is spyware primarily designed to do?

  1. Secretly collect information from a user’s device
  2. Restore damaged operating-system files
  3. Improve wireless network performance
  4. Manage backup schedules

Correct Answer: 1

Explanation:

Spyware is malicious software designed to monitor activity or collect information from a device without appropriate user knowledge or authorization. Depending on its capabilities, spyware may capture browsing activity, credentials, keystrokes, screenshots, or other information. It can create significant privacy and security risks because its activity may remain hidden while information is collected. Organizations can reduce exposure through endpoint protection, application controls, timely updates, least privilege, and security awareness. Detection may involve behavioral monitoring, endpoint telemetry, or analysis of suspicious processes and connections. Removing spyware should also include investigating whether credentials or other sensitive information were exposed.

Question 322

What is a keylogger designed to capture?

  1. Network routing tables
  2. User keystrokes
  3. Backup encryption keys only
  4. Physical access badge locations

Correct Answer: 3

Explanation:

A keylogger records keystrokes entered by a user and can potentially capture usernames, passwords, messages, search terms, or other sensitive information. Keyloggers may operate through malicious software or, in some cases, specialized hardware. Because captured information can include authentication credentials, organizations should combine endpoint security with strong authentication methods that reduce reliance on passwords alone. Monitoring for suspicious processes, unauthorized software, unusual system behavior, and unexpected hardware can also help. If a keylogger is discovered, affected credentials should be considered potentially exposed and appropriate incident response procedures should be followed.

Question 323

What is a botnet?

  1. A collection of compromised devices controlled by an attacker
  2. A secure group of backup servers
  3. A centralized employee directory
  4. A collection of approved security policies

Correct Answer: 4

Explanation:

A botnet is a group of compromised devices that can be controlled by an attacker or criminal operation. The compromised devices, often called bots or zombies, may be used for activities such as distributed denial-of-service attacks, spam distribution, credential attacks, or additional malware delivery. Devices can become part of a botnet after exploitation, malicious software installation, or abuse of weak credentials. Organizations can reduce exposure through timely patching, secure authentication, endpoint protection, network monitoring, and restricting unnecessary services. Detecting command activity or unusual outbound communication can also help identify compromised devices.

Question 324

What is fileless malware notable for?

  1. It always requires removable media
  2. It can operate using legitimate system tools or memory rather than traditional files
  3. It cannot execute on modern operating systems
  4. It is limited to physical security systems

Correct Answer: 2

Explanation:

Fileless malware refers to malicious activity that can operate without relying primarily on conventional malicious executable files stored on disk. Attackers may abuse legitimate operating-system utilities, scripts, interpreters, memory, or other trusted mechanisms to execute their activity. This approach can make traditional file-based detection more challenging. Organizations can improve detection through behavioral monitoring, script controls, endpoint telemetry, application restrictions, and monitoring of unusual use of administrative tools. Fileless techniques do not mean that absolutely no artifacts are created; related activity may still appear in memory, logs, command histories, or other telemetry sources.

Question 325

What is a honeypot designed to provide?

  1. A deliberately attractive environment for detecting or studying suspicious activity
  2. A permanent replacement for production systems
  3. A method for encrypting employee records
  4. A backup repository for critical databases

Correct Answer: 4

Explanation:

A honeypot is a deliberately configured system, service, or environment intended to attract or detect unauthorized activity. Because legitimate users generally have little reason to interact with it, unexpected access can provide a useful signal for security monitoring or investigation. Honeypots can also help security teams study attacker behavior under controlled conditions. They should be isolated appropriately so that compromise does not create unnecessary risk to production environments. Organizations should establish clear monitoring and response procedures before deploying them. A honeypot complements normal defensive controls rather than replacing endpoint security, access controls, or network monitoring.

Question 326

What is a denial-of-service attack intended to affect?

  1. Data classification accuracy
  2. Availability of a service or resource
  3. Employee identity proofing
  4. Encryption key rotation

Correct Answer: 1

Explanation:

A denial-of-service attack attempts to make a system, application, network service, or resource unavailable or significantly degraded for legitimate users. Attackers may overwhelm resources with traffic, requests, computational demands, or exploitation of weaknesses. A distributed denial-of-service attack uses multiple sources to generate the malicious load. Organizations can prepare through capacity planning, traffic filtering, rate controls, resilient architecture, monitoring, and suitable service-provider protections. Response procedures should identify critical services, escalation contacts, and traffic-management options. Availability attacks can affect business operations even when confidentiality and integrity of the underlying information remain intact.

Question 327

What is an attack surface?

  1. The collection of exposed points through which a system could potentially be attacked
  2. The physical size of a security operations center
  3. The number of employees in an IT department
  4. The amount of storage assigned to backups

Correct Answer: 3

Explanation:

An attack surface consists of the exposed interfaces, services, applications, devices, identities, configurations, and other elements that could potentially provide an attacker with an opportunity to interact with an environment. Reducing unnecessary exposure can lower the number of opportunities available to attackers. Organizations can manage attack surface through asset discovery, service minimization, access restrictions, secure configurations, vulnerability management, and removal of unnecessary accounts or interfaces. Because environments change continuously, attack-surface management should be ongoing rather than performed only during a one-time assessment. Unknown assets can create particularly difficult security visibility gaps.

Question 328

What is a security control compensating measure expected to address?

  1. An unrelated business objective
  2. The risk created by a limitation in the primary control
  3. Employee payroll processing
  4. Software licensing costs

Correct Answer: 2

Explanation:

A compensating measure is intended to reduce risk when the primary security control cannot be implemented fully or as originally required. The alternative safeguard should address the relevant threat or exposure rather than simply provide a convenient substitute. For example, additional monitoring, restricted connectivity, or stronger procedural oversight may reduce risk when a technical control is unavailable. The organization should document the limitation, residual risk, alternative protection, responsible owner, and review requirements. Compensating measures should be periodically reassessed because technology and business conditions can change, potentially making the original limitation unnecessary or altering the effectiveness of the alternative safeguard.

Question 329

What is a risk acceptance authority responsible for?

  1. Approving acceptance of identified risk within delegated authority
  2. Performing every vulnerability scan
  3. Configuring all employee devices
  4. Maintaining physical access badges

Correct Answer: 1

Explanation:

A risk acceptance authority is the person or body authorized to formally accept a defined level of risk on behalf of the organization. Acceptance should occur within established governance limits and should be supported by documented information about the risk, potential impact, treatment options, and rationale. The authority should have sufficient organizational responsibility to make the decision. Risk acceptance does not make the underlying risk disappear; it represents a conscious decision to operate with the identified exposure. Accepted risks should have appropriate review dates because changes in threats, business priorities, or controls may require a new decision.

Question 330

What is a risk tolerance threshold used to indicate?

  1. The number of security products an organization owns
  2. The maximum amount of deviation considered acceptable for a defined risk
  3. The age of an organization’s servers
  4. The number of employees attending training

Correct Answer: 4

Explanation:

A risk tolerance threshold establishes a boundary indicating how much variation or exposure the organization is prepared to tolerate for a particular risk or objective. Thresholds help translate broad risk expectations into conditions that can trigger action, escalation, or additional treatment. For example, an organization may establish a threshold for system downtime, unresolved critical findings, or exposure of sensitive services. Thresholds should be based on business impact and organizational risk decisions rather than arbitrary numbers. Monitoring should identify when thresholds are approached or exceeded so that responsible personnel can evaluate whether corrective action is necessary.

Question 331

What is the purpose of a security gap analysis?

  1. Compare current capabilities with desired requirements
  2. Replace all security monitoring
  3. Encrypt every organizational document
  4. Assign network addresses to devices

Correct Answer: 2

Explanation:

A security gap analysis compares the organization’s current security capabilities, processes, or controls with a defined target state or requirement. The target may come from internal policies, contractual obligations, regulatory expectations, industry frameworks, or organizational objectives. The analysis can reveal missing controls, incomplete processes, capability weaknesses, or areas requiring improvement. Findings should be documented and prioritized according to risk and business importance. A gap analysis is different from simply listing vulnerabilities because it evaluates the difference between the present condition and a defined expectation. Results can support remediation planning, investment decisions, and governance discussions.

Question 332

What is a key performance indicator used to measure?

  1. The physical distance between data centers
  2. Progress or performance against a defined objective
  3. The number of encryption algorithms available
  4. The age of an employee account

Correct Answer: 3

Explanation:

A key performance indicator, or KPI, measures progress or performance against a defined organizational objective. In security programs, KPIs might examine areas such as training completion, remediation performance, service availability, or response-process efficiency. A useful KPI should have a clear relationship to the objective it represents and should be measured consistently. KPIs differ from key risk indicators, which are designed to signal changing exposure or risk conditions. Security teams should avoid collecting metrics simply because they are easy to obtain. Measurements are most useful when they support meaningful decisions and reveal whether intended outcomes are being achieved.

Question 333

What is a security metric most useful when it is?

  1. Connected to a meaningful security objective or decision
  2. Collected without any defined purpose
  3. Changed randomly each reporting period
  4. Based solely on the number of security products purchased

Correct Answer: 4

Explanation:

A security metric becomes useful when it provides information relevant to a defined objective, risk, control, or decision. Meaningful metrics can help organizations evaluate performance, identify trends, detect deteriorating conditions, and determine whether corrective actions are producing results. A large volume of measurements does not necessarily improve decision-making. Metrics should therefore have clear definitions, reliable data sources, appropriate measurement periods, and known audiences. Organizations should also distinguish between activity counts and outcome-oriented measures. For example, counting completed scans may provide operational information, while measuring the timely remediation of significant findings may provide stronger insight into security performance.

Question 334

What is privacy by default intended to encourage?

  1. Maximum information sharing for every user
  2. Automatic use of the most privacy-protective reasonable settings
  3. Permanent retention of all personal information
  4. Public disclosure of user activity

Correct Answer: 1

Explanation:

Privacy by default means that systems and processes should use privacy-protective settings without requiring individuals to take additional action whenever appropriate. For example, an application may limit unnecessary data collection, sharing, visibility, or retention unless a legitimate purpose requires otherwise. The concept supports privacy protection as a normal system condition rather than making users responsible for discovering and changing every setting themselves. Appropriate defaults depend on the service, legal requirements, business purpose, and user expectations. Privacy by default works alongside broader privacy-by-design practices that incorporate privacy considerations throughout system development and operation.

Question 335

What is data accuracy important for in privacy management?

  1. Ensuring personal information remains correct and fit for its intended use
  2. Increasing the number of collected data fields
  3. Extending retention periods indefinitely
  4. Removing all access controls

Correct Answer: 2

Explanation:

Data accuracy is important because incorrect or outdated personal information can lead to inappropriate decisions, failed communications, incorrect records, or other harmful consequences. Organizations should establish reasonable processes for identifying and correcting inaccurate information when appropriate. Accuracy requirements depend on the purpose for which the data is processed; information used for important decisions may require stronger validation than information with limited impact. Data quality can be supported through validation at collection, reconciliation with reliable sources, correction mechanisms, and appropriate review processes. Maintaining accurate information should be balanced with data minimization and the legitimate purpose for which the information is processed.

Question 336

What is consent withdrawal intended to allow?

  1. A person to revoke previously provided consent where withdrawal is applicable
  2. An organization to retain every record permanently
  3. A security team to disable all authentication
  4. A provider to ignore privacy obligations

Correct Answer: 3

Explanation:

Consent withdrawal allows an individual to revoke consent when processing is based on consent and the applicable requirements provide such a right. Organizations should provide an understandable mechanism for withdrawal and should not make the process unnecessarily difficult compared with giving consent. Withdrawal does not necessarily erase all information automatically because other legal or operational requirements may apply to particular data. Organizations should identify what processing will stop, what information may remain for another lawful reason, and how the change affects related services. Privacy processes should document consent status and ensure that systems can honor valid withdrawal requests appropriately.

Question 337

What is a data protection impact assessment used to evaluate?

  1. Potential privacy risks associated with a processing activity
  2. The physical strength of server cabinets
  3. The performance of network switches
  4. The cost of office electricity

Correct Answer: 2

Explanation:

A data protection impact assessment, or DPIA, evaluates potential privacy risks associated with processing personal information, particularly where processing may create significant risks to individuals. The assessment can examine the purpose of processing, types of information involved, affected individuals, processing methods, potential impacts, existing safeguards, and additional measures needed to reduce risk. DPIAs help organizations identify privacy concerns before or during the design of higher-risk processing activities. Requirements vary by jurisdiction and organization, so the assessment process should reflect applicable legal and governance obligations. Findings should be documented and addressed rather than treated as a purely administrative exercise.

Question 338

What is a privacy notice primarily intended to explain?

  1. How an organization handles personal information
  2. How to configure a network firewall
  3. How to perform a server rebuild
  4. How to conduct a penetration test

Correct Answer: 4

Explanation:

A privacy notice explains how an organization collects, uses, shares, retains, and otherwise handles personal information. Depending on applicable requirements, it may describe processing purposes, categories of information, rights available to individuals, recipients, contact information, retention practices, or international transfer considerations. A clear notice helps individuals understand relevant processing practices and supports organizational transparency. The content should accurately reflect actual operations because a notice that describes practices the organization does not follow can create legal, compliance, and trust concerns. Privacy notices should be reviewed when processing activities, technologies, services, or applicable requirements change.

Question 339

What is privacy risk reduction through data minimization intended to achieve?

  1. Collecting only information necessary for an identified purpose
  2. Retaining every available data element indefinitely
  3. Expanding access to personal information
  4. Publishing personal information by default

Correct Answer: 3

Explanation:

Data minimization limits collection and processing to information that is relevant and necessary for a defined purpose. Collecting less information can reduce the potential impact of unauthorized disclosure, misuse, accidental exposure, or unnecessary retention. Organizations should first identify the legitimate purpose for processing and then determine what information is genuinely required. Minimization can also simplify storage, access management, retention, and disposal responsibilities. It does not mean that organizations should remove useful information indiscriminately; rather, collection should be proportionate to the purpose. Regular reviews can identify data fields that are no longer needed.

Question 340

What is the purpose of a legal hold?

  1. Preserve potentially relevant information despite normal retention or deletion schedules
  2. Increase the speed of routine backups
  3. Replace all privacy notices
  4. Automatically remove expired records

Correct Answer: 1

Explanation:

A legal hold instructs an organization to preserve potentially relevant information when litigation, investigation, or another legal matter requires preservation. Information subject to a hold may need to be retained even if normal retention schedules would otherwise permit deletion. The hold process should identify relevant information, responsible custodians, systems, and preservation requirements while preventing routine deletion from removing potentially relevant records. Once the legal need ends, the organization should follow appropriate procedures for releasing the hold and returning to normal retention practices. Legal holds should be coordinated with relevant legal, records-management, privacy, and technical personnel.