Cyber AB CCP Practice Test Questions and Exam Dumps Part18 Q341-360

View Full Cyber AB CCP Exam Dumps and Practice Test Dumps

 

Question 341

Which activity represents security governance rather than security management?

  1. Approving organizational security direction
  2. Configuring endpoint protection policies
  3. Investigating suspicious login events
  4. Applying operating-system patches

Correct Answer: 1

Explanation:

Security governance establishes direction, accountability, and oversight for an organization’s security program. Approving the overall security direction is therefore a governance responsibility because it determines how security aligns with organizational objectives and risk expectations. Security management focuses on executing that direction through operational activities. Configuring endpoint controls, investigating suspicious events, and applying patches are examples of management or operational work. Governance helps ensure that security decisions receive appropriate leadership oversight and remain aligned with business requirements. Keeping governance separate from day-to-day management can improve accountability and make it easier to determine who establishes expectations and who is responsible for implementing them.

Question 342

What is the primary purpose of control design?

  1. To document historical audit findings
  2. To establish how a control should address a defined risk
  3. To calculate annual security spending
  4. To identify individual system administrators

Correct Answer: 2

Explanation:

Control design determines whether a control is appropriately structured to address a specific risk or requirement. A well-designed control identifies what needs to be prevented, detected, or corrected and establishes an appropriate mechanism for achieving that objective. This differs from operating effectiveness, which evaluates whether the control actually functions as intended over time. Historical findings, budget calculations, and administrator identification may support security activities but do not define the fundamental purpose of control design. Organizations should establish clear control objectives and mechanisms before testing performance. Good design provides a foundation for effective implementation and helps ensure that security resources are directed toward meaningful risk reduction.

Question 343

What does control operating effectiveness primarily evaluate?

  1. Whether the control has a formal owner
  2. Whether the control appears in a policy document
  3. Whether the implemented control works consistently as intended
  4. Whether the control received executive approval

Correct Answer: 3

Explanation:

Operating effectiveness examines whether an implemented control actually performs as intended during the period being evaluated. A control may be well designed and formally approved yet fail operationally because procedures are not followed, systems are misconfigured, or required evidence is missing. Evaluators therefore examine actual performance rather than relying only on documentation or ownership assignments. Consistent operation is particularly important for recurring controls such as access reviews, monitoring activities, or security checks. Testing operating effectiveness provides evidence about whether the organization is genuinely carrying out the control rather than merely having a documented requirement. This distinction is important when assessing the reliability of a security program.

Question 344

Why should control dependencies be identified?

  1. To eliminate every manual procedure
  2. To replace security policies with technical standards
  3. To assign identical owners to all controls
  4. To understand how one control relies on another activity or safeguard

Correct Answer: 4

Explanation:

A control dependency exists when one control relies on another process, technology, source of information, or safeguard to operate properly. Identifying these dependencies helps organizations understand potential weaknesses within the broader control structure. For example, an access-review control may depend on accurate identity records and reliable account inventories. If the supporting process fails, the dependent control may also become ineffective even when its own procedure appears correct. Dependency analysis therefore helps organizations identify single points of failure, improve control testing, and determine where additional safeguards may be needed. It also provides a clearer understanding of how individual controls work together as part of an integrated security environment.

Question 345

Which situation is most appropriately classified as a control deficiency?

  1. A required safeguard does not adequately address the associated risk
  2. A security team completed an approved review early
  3. A control owner submitted evidence before the deadline
  4. An audit sample contained sufficient records

Correct Answer: 1

Explanation:

A control deficiency occurs when a control does not adequately prevent, detect, or address a relevant risk or requirement. This may result from poor design, ineffective operation, insufficient scope, or another weakness that reduces the control’s ability to achieve its objective. Completing reviews early, providing evidence on time, and obtaining sufficient audit samples are generally positive control-related outcomes rather than deficiencies. Identifying deficiencies allows organizations to determine whether remediation, redesign, additional monitoring, or management attention is necessary. Deficiency analysis should focus on the underlying control weakness and its relationship to risk rather than simply recording that an isolated administrative issue occurred.

Question 346

What should influence the frequency of security control testing?

  1. The number of employees in unrelated departments
  2. The color scheme of security dashboards
  3. The control’s risk significance and rate of change
  4. The physical size of the security office

Correct Answer: 3

Explanation:

Control testing frequency should reflect factors such as risk significance, control criticality, environmental changes, previous findings, and regulatory expectations. A high-risk control or one operating in a rapidly changing environment may require more frequent testing than a stable, lower-risk control. Using unrelated organizational characteristics, dashboard appearance, or office size provides no meaningful basis for determining testing frequency. A risk-based testing schedule allows organizations to concentrate assurance activities where failures could have greater consequences. Testing intervals can also be adjusted when new technology, processes, threats, or control changes are introduced. This approach supports efficient assurance while maintaining appropriate oversight of important safeguards.

Question 347

Which behavior best demonstrates professional cybersecurity ethics?

  1. Sharing confidential findings with friends
  2. Accessing systems beyond assigned authorization
  3. Ignoring a known security concern
  4. Protecting sensitive information while performing authorized duties

Correct Answer: 4

Explanation:

Professional cybersecurity ethics require practitioners to act responsibly, respect authorization boundaries, protect confidential information, and avoid causing unnecessary harm. Protecting sensitive information while performing authorized duties demonstrates these principles in practice. Accessing systems without permission violates authorization requirements, while sharing confidential findings with friends can expose sensitive information. Ignoring a known security concern may also conflict with professional responsibilities when appropriate reporting channels are available. Ethical conduct is important because cybersecurity professionals often have access to privileged systems and sensitive organizational information. Trust depends not only on technical competence but also on responsible decision-making, confidentiality, accountability, and respect for established authorization.

Question 348

What is a key principle of responsible vulnerability disclosure?

  1. Publicizing technical details immediately
  2. Giving the affected organization an appropriate opportunity to address the issue
  3. Selling the vulnerability to unauthorized parties
  4. Concealing the issue indefinitely

Correct Answer: 2

Explanation:

Responsible vulnerability disclosure generally involves communicating a security weakness through an appropriate process while allowing the affected organization reasonable time to investigate and remediate it. The goal is to reduce unnecessary exposure while supporting coordinated risk reduction. Immediate publication of detailed exploitation information can increase risk before a fix is available, while selling vulnerabilities to unauthorized parties does not represent responsible coordination. Indefinite concealment is also problematic because affected parties may remain exposed. A structured disclosure process can define reporting channels, communication expectations, remediation coordination, and possible public disclosure timelines. Such processes help researchers and organizations handle vulnerability information in a controlled and constructive manner.

Question 349

What is one purpose of cyber insurance?

  1. To transfer some financial consequences of specified cyber risks
  2. To replace every preventive security control
  3. To guarantee that incidents cannot occur
  4. To remove the organization’s responsibility for security

Correct Answer: 1

Explanation:

Cyber insurance can provide financial protection against certain covered losses associated with cybersecurity incidents. Depending on the policy, coverage may address expenses such as incident response, recovery, legal services, or other defined consequences. Insurance does not eliminate the need for preventive and detective controls, nor does it guarantee that incidents will not happen. Organizations also retain responsibilities concerning security practices, policy conditions, and applicable requirements. Insurance is therefore generally considered one component of a broader risk-management strategy rather than a substitute for cybersecurity safeguards. Organizations should understand policy exclusions, coverage conditions, limits, and required security measures before relying on insurance as part of their overall risk treatment approach.

Question 350

Which metric can help evaluate the effectiveness of phishing simulations?

  1. Number of security policies published
  2. Number of physical access badges issued
  3. Percentage of participants who report simulated messages
  4. Amount of storage assigned to email accounts

Correct Answer: 3

Explanation:

Phishing simulations can measure user behavior by observing how participants respond to controlled simulated messages. The percentage of participants who correctly report suspicious simulated messages can provide useful evidence about awareness and reporting behavior. Other measurements, such as the number of published policies, physical badges, or email storage capacity, do not directly evaluate phishing-response behavior. Organizations can use simulation results to identify training needs, compare trends over time, and assess whether awareness initiatives are producing behavioral improvements. Metrics should be interpreted carefully because a single exercise may not represent all user behavior. Repeated measurements across controlled campaigns generally provide more useful information about awareness trends.

Question 351

Which physical attack involves following an authorized person through a secured entrance?

  1. Tailgating
  2. Dumpster diving
  3. Shoulder surfing
  4. Lock picking

Correct Answer: 1

Explanation:

Tailgating occurs when an unauthorized individual follows an authorized person through a controlled physical entry point without independently authenticating. The attacker may exploit courtesy, distraction, or employee unfamiliarity with access procedures. Dumpster diving instead involves searching discarded materials for useful information, while shoulder surfing involves observing someone entering or viewing sensitive information. Lock picking is a different physical intrusion technique. Organizations can reduce tailgating through access-controlled doors, security awareness training, visitor procedures, security personnel, and physical designs that require each person to authenticate separately. Recognizing social aspects of physical security is important because strong technical access controls can still be undermined by weaknesses in human behavior.

Question 352

What is the primary objective of dumpster diving by an attacker?

  1. Disrupting wireless communication
  2. Recovering useful information from discarded materials
  3. Blocking network ports
  4. Circumventing encryption mathematically

Correct Answer: 2

Explanation:

Dumpster diving is the practice of searching discarded materials for information that could support unauthorized activity. Attackers may look for printed records, labels, organizational details, contact information, credentials, diagrams, or other sensitive material that was improperly discarded. The technique does not require sophisticated exploitation of a network or cryptographic algorithm. Organizations can reduce this risk by establishing secure disposal procedures, using appropriate shredding or destruction methods, and training personnel on information-handling requirements. Disposal controls should apply not only to paper records but also to storage media and other materials that may contain sensitive information. Proper disposal is therefore an important part of information lifecycle management.

Question 353

Which attack relies on observing a person entering sensitive information?

  1. Tailgating
  2. Dumpster diving
  3. Shoulder surfing
  4. Network scanning

Correct Answer: 3

Explanation:

Shoulder surfing involves observing another person while they enter or view sensitive information. Attackers may watch passwords, authentication codes, account details, or confidential documents from nearby locations. The technique can occur in offices, public transportation, airports, cafes, or other areas where screens and keyboards are visible. Privacy screens, careful positioning, secure authentication practices, and user awareness can reduce exposure. Tailgating is a physical-entry technique, dumpster diving involves discarded materials, and network scanning targets technical systems. Shoulder surfing demonstrates that information security can be compromised through simple physical observation even when the underlying application uses strong technical controls.

Question 354

What characterizes an evil twin attack?

  1. A fraudulent wireless network impersonates a legitimate one
  2. A backup server creates duplicate recovery images
  3. Two administrators share one privileged account
  4. A firewall applies two filtering policies

Correct Answer: 1

Explanation:

An evil twin attack involves creating a malicious wireless access point designed to resemble a legitimate network. Users may connect to the fraudulent network because its name appears familiar or trustworthy. Once connected, an attacker may attempt to capture information, redirect traffic, or conduct additional attacks depending on the environment and security controls. Organizations can reduce this risk through secure wireless configurations, certificate validation, user awareness, network monitoring, and strong authentication mechanisms. The attack differs from ordinary wireless interference because the attacker is attempting to imitate a trusted network identity. Recognizing suspicious wireless networks is particularly important when users connect from public or unfamiliar locations.

Question 355

What is a rogue access point?

  1. An authorized wireless controller
  2. An intentionally isolated guest network
  3. An unauthorized wireless device connected to an organization’s environment
  4. A replacement for a wired switch

Correct Answer: 3

Explanation:

A rogue access point is an unauthorized wireless access device connected to or operating within an organization’s environment. It can create an unintended pathway into the network and may bypass established wireless security controls. Rogue access points can appear because of malicious activity or because employees install unauthorized wireless equipment without understanding the security implications. Organizations can address this risk through wireless monitoring, network access controls, asset inventories, physical inspections, and clear policies governing network-connected devices. Identifying unauthorized wireless infrastructure is important because even well-configured authorized access points cannot protect against every unmanaged device introduced into the environment.

Question 356

What does ARP spoofing primarily attempt to manipulate?

  1. Domain registration records
  2. Local network address-resolution information
  3. Password expiration settings
  4. File compression metadata

Correct Answer: 2

Explanation:

ARP spoofing manipulates Address Resolution Protocol information on a local network so that devices associate an attacker’s hardware address with another system’s IP address. This can allow an attacker positioned on the same network segment to intercept, redirect, or disrupt traffic. The technique takes advantage of weaknesses in the trust model of traditional ARP rather than modifying domain registration records or authentication policies. Organizations can reduce exposure through network segmentation, monitoring, secure switching features, and appropriate endpoint protections. Understanding ARP spoofing is important because an attacker may use it as an intermediate step toward traffic interception or other network-based activity.

Question 357

What is a common goal of DHCP spoofing?

  1. Providing clients with attacker-controlled network configuration
  2. Increasing disk capacity
  3. Encrypting database backups
  4. Rotating certificate keys

Correct Answer: 1

Explanation:

DHCP spoofing occurs when an unauthorized DHCP server responds to client requests and provides malicious or incorrect network configuration information. Depending on the environment, an attacker-controlled DHCP response may influence gateway, DNS, or other network settings. This can redirect traffic or interfere with normal network communication. Network protections such as DHCP snooping can help identify and restrict unauthorized DHCP responses on managed switches. Proper network segmentation and monitoring can provide additional protection. DHCP spoofing illustrates why basic network services require security controls: even though DHCP is normally used for routine configuration, manipulating its responses can influence how devices communicate across the network.

Question 358

Which control can help prevent unauthorized devices from using a switch port?

  1. Port security
  2. Screen locking
  3. Database indexing
  4. Email filtering

Correct Answer: 1

Explanation:

Switch port security can restrict which devices are permitted to use a particular network switch port. Depending on the configuration, it may limit the number of learned MAC addresses or specify permitted device addresses. This can reduce certain forms of unauthorized network access, including attempts to connect unmanaged devices to protected switch ports. Screen locking, database indexing, and email filtering address different security or operational concerns. Port security should be implemented carefully because overly restrictive configurations can disrupt legitimate devices. It is most effective when combined with broader network access controls, asset management, monitoring, and appropriate physical protection of network infrastructure.

Question 359

What security function does Secure Boot provide?

  1. It validates trusted software during the system startup process
  2. It encrypts every network packet automatically
  3. It removes all administrator accounts
  4. It increases processor clock speed

Correct Answer: 1

Explanation:

Secure Boot helps protect the startup process by allowing a device to verify that boot components are trusted before execution. The mechanism is designed to reduce the risk of unauthorized or modified boot software being loaded during system startup. This can help defend against certain forms of boot-level tampering. Secure Boot does not automatically encrypt network traffic, remove administrator accounts, or change processor performance. Its security value depends on proper platform configuration, trusted keys, and appropriate operating-system support. It is particularly useful as part of a layered endpoint-security strategy where firmware, boot components, operating systems, and applications are protected through complementary controls.

Question 360

What is the primary security role of a Trusted Platform Module (TPM)?

  1. Providing hardware-based support for protected cryptographic operations
  2. Replacing the organization’s firewall
  3. Filtering unsolicited email
  4. Managing employee vacation schedules

Correct Answer: 1

Explanation:

A Trusted Platform Module, or TPM, is a hardware-based security component that can support protected storage and cryptographic operations. It can securely hold cryptographic material and participate in platform integrity mechanisms, depending on the device and configuration. TPM technology can therefore support features such as device authentication, disk-encryption key protection, and trusted boot measurements. It does not replace network firewalls or perform email filtering. Organizations benefit from understanding the distinction between hardware-backed security functions and software-based security controls. When properly configured, a TPM can provide stronger protection for sensitive cryptographic material than relying exclusively on general-purpose storage accessible to the operating system.