Cyber AB CCP Practice Test Questions and Exam Dumps Part20 Q381-400

View Full Cyber AB CCP Exam Dumps and Practice Test Dumps

 

Question 381

What is the main purpose of security control mapping?

  1. To connect controls with applicable requirements
  2. To assign passwords to every employee
  3. To increase network bandwidth
  4. To replace asset inventories

Correct Answer: 1

Explanation:

Security control mapping connects organizational controls with applicable requirements, frameworks, policies, or other obligations. This helps organizations determine which safeguards address particular requirements and can reduce duplicated assessment work. A control may support several requirements, while one requirement may require multiple controls. Mapping also helps identify areas where no suitable control exists, allowing gaps to be evaluated and addressed. Password administration, bandwidth management, and asset inventory are separate security activities. Effective control mapping should remain current when regulations, standards, systems, or organizational processes change. It can also make compliance evidence easier to organize because control activities are linked to specific requirements.

Question 382

Which activity best demonstrates regulatory mapping?

  1. Selecting a new antivirus vendor
  2. Linking legal obligations to relevant organizational controls
  3. Replacing outdated monitors
  4. Increasing wireless coverage

Correct Answer: 2

Explanation:

Regulatory mapping involves connecting applicable legal or regulatory obligations to organizational processes and controls. This allows an organization to understand how requirements are addressed and where additional safeguards or evidence may be necessary. Mapping can support compliance assessments, control reviews, audit preparation, and remediation planning. Selecting security products, replacing hardware, or improving wireless coverage may support security operations but do not themselves constitute regulatory mapping. Organizations should identify the relevant requirements, determine which controls address them, document evidence, and periodically review the mapping for changes. This approach helps prevent compliance activities from becoming disconnected from actual operational security practices.

Question 383

What is a compliance attestation?

  1. A network device configuration file
  2. A vulnerability scanning technique
  3. A formal statement that specified requirements or controls have been met
  4. A method for encrypting removable media

Correct Answer: 3

Explanation:

A compliance attestation is a formal statement or declaration that specified requirements, controls, or conditions have been satisfied based on an applicable assessment or assurance process. The exact meaning depends on the governing framework or program. An attestation may require supporting evidence and may be provided by an organization or an authorized independent party. It is different from a network configuration, vulnerability scan, or encryption mechanism. Organizations should understand what was actually assessed, the scope and time period covered, and any limitations associated with an attestation. An attestation should not automatically be interpreted as proof that every aspect of an organization’s security environment is risk-free.

Question 384

Why is evidence management important during a security assessment?

  1. It guarantees that every vulnerability is fixed
  2. It helps organize and preserve material supporting control conclusions
  3. It eliminates the need for security policies
  4. It prevents all future audit requests

Correct Answer: 2

Explanation:

Evidence management helps organizations collect, organize, protect, and retrieve material used to demonstrate that controls operate as required. Useful evidence may include system records, approval records, configuration information, review results, logs, or other documented artifacts. Proper evidence handling supports efficient assessments and makes conclusions easier to substantiate. Evidence management does not guarantee vulnerability remediation or eliminate future audits. Organizations should define evidence ownership, retention periods, access restrictions, and handling procedures. Evidence should also be sufficiently relevant and reliable for the conclusion being supported. A structured approach reduces the likelihood of missing documentation when auditors, assessors, or internal reviewers request proof of control operation.

Question 385

Which practice can reduce risks from tailgating?

  1. Requiring each individual to authenticate independently at secure entrances
  2. Disabling all visitor procedures
  3. Allowing unrestricted door sharing
  4. Publishing employee badge numbers publicly

Correct Answer: 1

Explanation:

Requiring each person to authenticate independently at a secured entrance makes it more difficult for an unauthorized individual to enter by simply following an authorized employee. This approach can be supported by badge readers, turnstiles, mantraps, security personnel, or other physical controls. Visitor procedures and employee awareness can provide additional protection. Disabling visitor controls or allowing unrestricted door sharing would increase exposure. Publishing badge numbers could also create unnecessary security risk. Physical access controls should be designed around the sensitivity of the protected area and should be periodically reviewed to ensure that they continue to support organizational security requirements.

Question 386

Which wireless attack attempts to impersonate a trusted access point?

  1. MAC flooding
  2. Evil twin
  3. Port scanning
  4. DHCP exhaustion

Correct Answer: 2

Explanation:

An evil twin attack uses a fraudulent wireless access point that imitates a legitimate network. The attacker may use a familiar network identifier to encourage users to connect to the malicious infrastructure. Once connected, the attacker may attempt to observe traffic, capture information, or redirect users depending on the surrounding controls. MAC flooding targets switch behavior, port scanning identifies network services, and DHCP exhaustion attempts to consume address resources. Organizations can reduce wireless impersonation risks through secure authentication, certificate validation, wireless monitoring, user awareness, and careful configuration of authorized access points. Users should also be cautious when connecting to networks with familiar names in unfamiliar locations.

Question 387

What does NAC primarily help an organization enforce?

  1. Physical document retention
  2. Network access based on device or user conditions
  3. Database backup schedules
  4. Software licensing costs

Correct Answer: 2

Explanation:

Network Access Control, or NAC, helps organizations determine whether users or devices should receive network access based on defined conditions. These conditions may include identity, device posture, authentication status, security configuration, or other organizational requirements. NAC can therefore help prevent unmanaged or noncompliant devices from gaining unrestricted access to protected network resources. Document retention, database backups, and software licensing address different operational concerns. NAC can be integrated with authentication systems, endpoint-management platforms, and network infrastructure. Its effectiveness depends on accurate policy definitions and reliable information about connected devices. Proper deployment can improve visibility and reduce exposure from unauthorized or poorly secured endpoints.

Question 388

What is the primary security purpose of a host-based firewall?

  1. To filter network connections at an individual endpoint
  2. To manage employee payroll
  3. To create physical backups
  4. To issue digital certificates

Correct Answer: 1

Explanation:

A host-based firewall runs on an individual endpoint and controls network connections according to configured rules. It can restrict inbound or outbound traffic based on factors such as ports, protocols, addresses, applications, or connection profiles. Because the control operates directly on the host, it can provide protection even when the device is outside the organization’s traditional network perimeter. Host firewalls do not manage payroll, create physical backups, or issue certificates. Organizations should configure them according to security requirements and monitor policy changes. Host-based filtering is most effective when combined with other endpoint, identity, network, and application security controls.

Question 389

What does application control primarily restrict?

  1. Which approved software is allowed to execute
  2. Which employees may enter the building
  3. Which databases require backups
  4. Which cables connect network switches

Correct Answer: 1

Explanation:

Application control restricts software execution according to organizational policy. Depending on the implementation, it may allow approved applications while blocking unknown, unauthorized, or prohibited programs. This can reduce the opportunity for malicious or unapproved software to execute on protected systems. Application control differs from physical access controls, backup procedures, and network cabling management. Organizations should maintain an accurate understanding of approved software and establish processes for legitimate exceptions. Application-control policies require maintenance because software environments change over time. When combined with endpoint monitoring and appropriate administrative restrictions, application control can provide an additional layer against unauthorized code execution.

Question 390

What is the purpose of secure boot measurements?

  1. To record information about trusted components involved in startup
  2. To increase internet connection speed
  3. To delete unused applications
  4. To manage employee identities

Correct Answer: 1

Explanation:

Secure boot measurements provide information about components involved in the system startup process and can support verification of platform integrity. Trusted hardware mechanisms may record measurements of firmware, boot components, or other elements so that their expected state can be evaluated. This differs from simply increasing network performance or managing user identities. Integrity measurements can help detect unexpected changes to the startup environment and support stronger device trust decisions. Organizations should understand how their platform implements measurement, where the information is stored, and how verification occurs. Such mechanisms are most valuable when integrated into a broader endpoint-security architecture.

Question 391

What does a certificate revocation list (CRL) provide?

  1. A list of certificates that should no longer be trusted
  2. A catalog of authorized software licenses
  3. A record of employee vacation dates
  4. A schedule for database maintenance

Correct Answer: 1

Explanation:

A Certificate Revocation List is a published list of digital certificates that a certificate authority has revoked before their normal expiration. Systems that rely on certificate trust can use revocation information when determining whether a certificate should still be accepted. Certificates may be revoked because of key compromise, incorrect issuance, changes in authorization, or other security reasons. A CRL is different from a software-license catalog or operational schedule. Organizations using certificate-based authentication should understand how revocation information is distributed, refreshed, and checked. Appropriate certificate lifecycle management helps reduce the risk of continuing to trust credentials that should no longer be considered valid.

Question 392

What is a certificate authority responsible for in a PKI?

  1. Issuing and managing trusted digital certificates
  2. Filtering physical mail
  3. Assigning network VLAN numbers
  4. Performing database compression

Correct Answer: 1

Explanation:

A Certificate Authority, or CA, is a trusted entity within a Public Key Infrastructure that issues and manages digital certificates according to defined policies and procedures. The CA validates required information before issuing certificates and can also support lifecycle functions such as renewal and revocation. Certificates help establish cryptographic identities for systems, services, or users. VLAN assignment, physical mail handling, and database compression are unrelated functions. The security of a PKI depends heavily on protecting the CA, controlling certificate issuance, safeguarding private keys, and maintaining accurate trust relationships. Compromise of a trusted CA can have significant consequences because relying systems may accept certificates issued by that authority.

Question 393

Why is symmetric encryption generally efficient for large amounts of data?

  1. It uses separate keys for every byte
  2. It eliminates the need for cryptographic keys
  3. It typically requires less computational overhead than asymmetric encryption
  4. It can only protect public information

Correct Answer: 3

Explanation:

Symmetric encryption typically uses the same secret key for encryption and decryption and is generally computationally efficient for processing large volumes of data. This efficiency makes symmetric algorithms suitable for bulk data protection in many systems. Asymmetric cryptography, by contrast, generally involves greater computational overhead and is often used for functions such as key establishment or digital signatures. Symmetric encryption still requires secure key management because anyone possessing the relevant secret key may be able to decrypt protected information. It does not eliminate the need for keys or restrict protection to public information. Secure systems often combine symmetric and asymmetric cryptographic techniques for different purposes.

Question 394

What is a nonce used for in cryptographic protocols?

  1. To provide a value intended for one-time or limited reuse
  2. To permanently store user passwords
  3. To replace all encryption keys
  4. To identify physical security guards

Correct Answer: 1

Explanation:

A nonce is a value intended to be used in a particular cryptographic operation, often only once or within a narrowly defined context. Its purpose can include helping prevent replay or ensuring that otherwise similar cryptographic operations produce distinct results. The exact requirements depend on the protocol and algorithm because improper nonce reuse can weaken certain cryptographic constructions. A nonce is not a replacement for encryption keys and does not function as a password database or physical identification mechanism. Developers and security professionals should understand the specific uniqueness requirements of the cryptographic system being used rather than assuming that every nonce has identical properties.

Question 395

What is a secrets vault designed to protect?

  1. Sensitive credentials and machine-access secrets
  2. Public marketing materials
  3. Office furniture inventories
  4. Network cable lengths

Correct Answer: 1

Explanation:

A secrets vault is designed to securely store and manage sensitive information such as passwords, API credentials, tokens, private keys, and other machine-access secrets. Centralized secret management can reduce the need to place credentials directly in source code, configuration files, scripts, or other locations where they may be exposed. A vault can also support controlled access, auditing, rotation, and lifecycle management depending on the implementation. Public documents and physical inventory information generally do not require the same type of secret-management infrastructure. Organizations should carefully define who or what may retrieve secrets and should monitor access to sensitive credential stores.

Question 396

What does API key management primarily address?

  1. Secure issuance, storage, rotation, and use of API credentials
  2. Physical destruction of hard drives
  3. Temperature monitoring in server rooms
  4. Employee attendance tracking

Correct Answer: 1

Explanation:

API key management addresses the lifecycle and protection of credentials used by applications or services to access APIs. Effective management may include controlled issuance, secure storage, expiration or rotation, access restrictions, monitoring, and revocation when keys are no longer required. Poorly managed API keys can be exposed through source code, logs, configuration files, or repositories and may provide unauthorized access if misused. Physical media destruction, environmental monitoring, and attendance tracking address unrelated concerns. Organizations should treat API keys as sensitive credentials and avoid embedding them unnecessarily in publicly accessible code or other locations where unauthorized parties could obtain them.

Question 397

What security benefit can OAuth scopes provide?

  1. They limit what an issued authorization token is permitted to access
  2. They guarantee that users choose strong passwords
  3. They physically isolate application servers
  4. They prevent every phishing attempt

Correct Answer: 1

Explanation:

OAuth scopes allow an authorization system to define the permissions associated with an issued token. Instead of granting unrestricted access, a token can be limited to specific resources or operations supported by the application. This supports the principle of limiting authorization to what is required. Scopes do not guarantee strong passwords, physically isolate servers, or prevent every phishing attack. Organizations should carefully design scopes so that applications receive only the permissions necessary for their intended functions. Excessively broad scopes can increase the consequences of token compromise, while appropriately restricted scopes can reduce the amount of access available to an attacker using a stolen authorization credential.

Question 398

What does CORS primarily control for web applications?

  1. Which origins may make certain cross-origin requests
  2. How physical badges are printed
  3. When backup tapes are destroyed
  4. Which employees receive laptops

Correct Answer: 1

Explanation:

Cross-Origin Resource Sharing, or CORS, provides a mechanism through which web applications can specify which origins are permitted to make certain cross-origin requests. Proper configuration can help prevent unintended browser-based access to resources from unauthorized origins. CORS is not a general replacement for authentication or authorization, and incorrect configurations can expose resources more broadly than intended. Physical badge production, backup destruction, and laptop assignment are unrelated functions. Security teams should understand which origins, methods, headers, and credentials are permitted and should avoid overly permissive configurations when sensitive resources are involved.

Question 399

What is a Content Security Policy (CSP) primarily intended to help mitigate?

  1. Certain browser-based content injection risks
  2. Physical theft of servers
  3. Failure of backup generators
  4. Unauthorized building entry

Correct Answer: 1

Explanation:

Content Security Policy is a browser-enforced security mechanism that allows websites to define which sources of content and scripts browsers should trust. A carefully designed CSP can reduce the impact of certain content-injection attacks by restricting where executable resources may originate or how content can be loaded. CSP does not physically protect servers, provide electrical backup, or control building access. Its effectiveness depends on accurate policy design and deployment because overly permissive directives may provide limited protection. CSP should complement secure development practices such as output handling, input validation, authentication controls, and vulnerability testing rather than serve as the sole defense against web attacks.

Question 400

Which practice best supports secure webhook design?

  1. Authenticating webhook requests and validating their integrity
  2. Accepting every incoming request without verification
  3. Publishing secret signing keys in documentation
  4. Disabling all request logging

Correct Answer: 1

Explanation:

Webhooks allow one system to send event-driven requests to another system, so receiving applications should verify that incoming requests originate from an expected source and have not been altered. Authentication mechanisms, request signatures, timestamp checks, replay protections, and appropriate authorization controls can help strengthen webhook security. Accepting every request without verification creates unnecessary exposure, while publishing signing secrets defeats their protective purpose. Disabling logging can also make suspicious webhook activity harder to investigate. Webhook endpoints should be treated as externally reachable interfaces when appropriate and should receive the same careful security design, validation, monitoring, and credential-management practices applied to other application interfaces.