Cyber AB CCP Practice Test Questions and Exam Dumps Part8 Q141-160

View Full Cyber AB CCP Exam Dumps and Practice Test Dumps

 

Question 141

What is the primary purpose of a security governance framework?

  1. Establish organizational security direction
  2. Configure endpoint antivirus software
  3. Restore deleted production files
  4. Scan applications for coding flaws

Correct Answer: 1

Explanation:

A security governance framework establishes the organizational direction for protecting information and technology resources. It defines how security decisions are made, who has authority, and how security objectives align with business requirements. Governance typically includes policies, accountability structures, oversight mechanisms, and decision-making principles. It differs from operational security activities, which focus on implementing and maintaining controls. A strong governance structure helps ensure that cybersecurity is treated as an organizational responsibility rather than only a technical function. It also provides a basis for measuring security performance and holding responsible parties accountable for agreed requirements.

Question 142

What does a risk tolerance statement primarily define?

  1. The systems requiring daily backups
  2. The amount of variation from objectives the organization can accept
  3. The employees authorized to approve invoices
  4. The software versions permitted on laptops

Correct Answer: 2

Explanation:

Risk tolerance describes the degree of variation from established objectives that an organization is willing to accept. It provides practical boundaries for managing uncertainty after risk appetite has established the broader level of risk the organization is prepared to pursue or retain. For example, an organization might define a very small tolerance for unauthorized disclosure of highly sensitive information. Risk tolerance can therefore guide decisions about controls, escalation, and risk treatment. It is not the same as a backup requirement, software standard, or financial approval process. Clearly defined tolerance levels help security teams determine when a risk requires additional attention.

Question 143

Who is normally responsible for ensuring a specific security control operates as intended?

  1. Control owner
  2. External customer
  3. Procurement analyst
  4. Facilities receptionist

Correct Answer: 1

Explanation:

The control owner is generally accountable for ensuring that a particular security control is appropriately implemented, maintained, and functioning as expected. This responsibility may include monitoring performance, coordinating testing, addressing deficiencies, and retaining evidence that demonstrates operation. The control owner is different from a data owner, who is responsible for decisions concerning particular information assets. Assigning ownership prevents security responsibilities from becoming unclear or overlooked. In larger organizations, the person accountable for a control may coordinate with several operational teams, but there should still be a clearly identified owner responsible for its effectiveness.

Question 144

What is a compensating control designed to accomplish?

  1. Replace every security policy with technical rules
  2. Eliminate the need for risk assessments
  3. Provide an alternative safeguard when the preferred control cannot be used
  4. Remove accountability from the original control owner

Correct Answer: 3

Explanation:

A compensating control provides an alternative safeguard when the primary or prescribed control cannot reasonably be implemented. For example, a legacy system might be unable to support a required authentication mechanism, so additional network isolation and monitoring could provide supplementary protection. A compensating control should address the relevant security objective rather than simply being a different technical mechanism. Its suitability should be documented and evaluated according to organizational requirements. Compensating controls do not eliminate the need for risk assessment or accountability. They are used to reduce exposure when the intended control is impractical, unavailable, or incompatible with an existing environment.

Question 145

What is the main objective of continuous control monitoring?

  1. Detect changes in control performance over time
  2. Approve employee vacation requests
  3. Replace organizational security policies
  4. Determine the market value of hardware

Correct Answer: 1

Explanation:

Continuous control monitoring focuses on observing security controls over time to identify changes, failures, or deviations from expected conditions. Instead of relying only on occasional assessments, organizations can use automated or recurring monitoring to detect issues sooner. Examples include checking whether required security settings remain enabled or whether privileged access continues to follow established rules. Continuous monitoring can improve visibility into control effectiveness and support faster corrective action. It does not replace governance documentation or policy requirements. Its value comes from providing ongoing evidence about whether controls continue to operate as designed as systems, configurations, and threats change.

Question 146

Why is an asset criticality rating useful during security planning?

  1. It identifies which assets are most important to business operations
  2. It determines the physical dimensions of equipment
  3. It assigns usernames to application accounts
  4. It measures employee training attendance

Correct Answer: 1

Explanation:

Asset criticality ratings help an organization distinguish systems and resources according to their importance to business operations. A system supporting essential services may require stronger protection, tighter recovery objectives, or greater monitoring than a nonessential asset. Criticality can also help prioritize vulnerability remediation and continuity planning when resources are limited. The rating should be based on factors such as operational dependency, business impact, regulatory importance, and recovery requirements. It is not simply a measure of hardware size or user activity. Understanding asset criticality allows security teams to focus protective and recovery resources where disruption could have the greatest organizational consequences.

Question 147

What is the primary purpose of a configuration management database (CMDB)?

  1. Track relationships and information about technology assets
  2. Encrypt every file stored by an organization
  3. Generate employee performance evaluations
  4. Replace vulnerability scanning tools

Correct Answer: 1

Explanation:

A configuration management database, or CMDB, stores information about configuration items and their relationships within an organization’s technology environment. These items may include servers, applications, network devices, and services. Understanding relationships can help security and operations teams assess the potential impact of changes, outages, or vulnerabilities. For example, knowing which business service depends on a particular server can help prioritize remediation. A CMDB does not itself encrypt organizational data or replace vulnerability scanners. Its value comes from maintaining structured information about the technology environment and the dependencies connecting its components.

Question 148

What is the main reason organizations establish formal security exceptions?

  1. To permanently remove mandatory safeguards
  2. To document approved deviations from established requirements
  3. To allow employees to bypass controls without review
  4. To prevent security policies from being updated

Correct Answer: 2

Explanation:

A formal security exception process allows an organization to document and manage situations where an established security requirement cannot currently be met. The process normally records the reason for the exception, affected assets, associated risks, compensating measures, approval authority, and expiration or review date. This creates accountability and prevents informal control bypasses from becoming permanent. Exceptions should be reviewed periodically because circumstances can change and the original limitation may eventually disappear. A properly managed exception does not eliminate the underlying requirement. Instead, it provides a controlled mechanism for handling deviations while maintaining visibility into the resulting risk.

Question 149

What is a security charter primarily used to establish?

  1. The authority and responsibilities of a security function
  2. The encryption algorithm used by a database
  3. The retention period for application logs
  4. The network address of a firewall

Correct Answer: 1

Explanation:

A security charter establishes the mandate, authority, responsibilities, and general scope of a security function or program. It can clarify leadership responsibilities, reporting relationships, decision-making authority, and the security program’s organizational objectives. This helps prevent ambiguity about what the security function is expected and authorized to accomplish. A charter is a governance document rather than a technical configuration record. Encryption choices, firewall addressing, and log retention may be governed by separate standards or procedures. A well-defined charter gives security teams organizational legitimacy and provides a foundation for coordinating security responsibilities across departments.

Question 150

Why are security governance committees commonly established?

  1. To provide cross-functional oversight of security matters
  2. To perform every vulnerability scan manually
  3. To replace all technical administrators
  4. To issue software licenses to customers

Correct Answer: 1

Explanation:

Security governance committees bring representatives from relevant business and technical areas together to provide oversight and coordinated decision-making. Members may include security, information technology, legal, privacy, risk, compliance, and business representatives. Their responsibilities can include reviewing significant risks, discussing security priorities, monitoring program performance, and supporting decisions that require multiple organizational perspectives. A governance committee does not replace operational security teams or perform every technical task itself. Its primary value is organizational coordination and oversight. By involving different stakeholders, the committee can help ensure that security decisions consider business requirements alongside technical and compliance considerations.

Question 151

What does a control objective describe?

  1. The security outcome a control is intended to achieve
  2. The employee assigned to purchase hardware
  3. The exact physical location of a server
  4. The number of applications installed on a workstation

Correct Answer: 1

Explanation:

A control objective describes the desired outcome that a security control or group of controls should accomplish. For example, an objective might require unauthorized users to be prevented from accessing sensitive information. Specific controls can then be selected or designed to achieve that objective. This distinction is useful because organizations may change technologies while retaining the same underlying security goal. A control objective therefore focuses on what protection should accomplish rather than prescribing one particular implementation. It can also support control testing because assessors can evaluate whether the implemented measures actually achieve the intended security outcome.

Question 152

Which activity best demonstrates control effectiveness testing?

  1. Selecting a new security framework
  2. Checking evidence to determine whether a control works as designed
  3. Purchasing additional storage capacity
  4. Creating employee identification badges

Correct Answer: 2

Explanation:

Control effectiveness testing evaluates whether a security control is properly designed and operates as intended. Testers may inspect evidence, examine configurations, observe processes, interview responsible personnel, or perform sampling. The goal is to determine whether the control actually provides the expected protection rather than merely confirming that a policy exists. Testing results can identify deficiencies that require remediation or additional monitoring. Control effectiveness assessments are therefore different from selecting a framework or performing ordinary administrative tasks. Reliable evidence is especially important because conclusions should be based on observable implementation and operation rather than assumptions about how a control is supposed to function.

Question 153

What is a zero-day vulnerability?

  1. A flaw publicly documented after being fully patched
  2. A weakness unknown to defenders or lacking an available fix
  3. A vulnerability that exists only on disconnected systems
  4. A defect that automatically disappears after rebooting

Correct Answer: 2

Explanation:

A zero-day vulnerability refers to a security weakness for which defenders have had little or no opportunity to address the problem before exploitation or public discovery. In many cases, there is initially no vendor patch available, creating a difficult defensive situation. The term is associated with the limited time available to develop and deploy a mitigation. Once a vendor releases a fix, organizations still need to assess affected systems and apply appropriate remediation. A zero-day should not be confused with an old vulnerability that simply remains unpatched. Rapid detection, temporary mitigations, and vendor coordination can help reduce exposure.

Question 154

What does CVSS primarily provide for a vulnerability?

  1. A standardized severity scoring approach
  2. A unique encryption key
  3. A list of authorized administrators
  4. A backup restoration sequence

Correct Answer: 1

Explanation:

The Common Vulnerability Scoring System, or CVSS, provides a standardized method for describing and scoring the severity characteristics of vulnerabilities. Scores can help organizations compare vulnerabilities and prioritize remediation based on factors such as exploitability and potential impact. A CVSS score is useful for prioritization, but it should not be treated as the only factor in deciding remediation order. Asset criticality, exposure, available mitigations, threat activity, and business context can also influence urgency. CVSS is therefore a vulnerability assessment mechanism rather than an encryption system, access-control mechanism, or recovery procedure.

Question 155

Which malware characteristic is most associated with encrypting files to demand payment?

  1. Ransomware behavior
  2. Spyware collection
  3. Rootkit concealment
  4. Worm propagation

Correct Answer: 1

Explanation:

Ransomware is malware commonly associated with restricting access to data, frequently through encryption, followed by a demand for payment. Its impact can extend beyond individual devices when shared resources or interconnected systems are affected. Effective defenses include tested backups, endpoint protection, network segmentation, access controls, vulnerability management, and user awareness. Ransomware should not be confused with spyware, which focuses on covert information collection; rootkits, which emphasize concealment and privileged persistence; or worms, which are designed to propagate between systems. Organizations should also consider recovery planning because preventing every infection is difficult in complex environments.

Question 156

What is DNS tunneling commonly used to accomplish?

  1. Hide data or command traffic within DNS communications
  2. Increase the physical speed of network switches
  3. Replace certificates used by web servers
  4. Automatically repair corrupted operating systems

Correct Answer: 1

Explanation:

DNS tunneling can abuse DNS queries and responses to carry information or command traffic that would not normally belong in DNS communications. Attackers may use this technique for command-and-control activity or data exfiltration because DNS traffic is widely permitted in many environments. Detection can involve analyzing unusual query patterns, abnormal domain structures, excessive request volumes, or unexpected destinations. DNS tunneling is therefore different from ordinary DNS resolution. Network monitoring and properly controlled DNS infrastructure can reduce opportunities for abuse. Organizations should also investigate suspicious DNS behavior alongside endpoint and network telemetry for stronger detection.

Question 157

What does lateral movement describe during a cyberattack?

  1. Moving from one compromised system or account to additional internal resources
  2. Installing a legitimate operating-system update
  3. Moving backup media into an archive room
  4. Transferring ownership of a software license

Correct Answer: 1

Explanation:

Lateral movement occurs when an attacker moves from an initially compromised system, account, or network location toward additional internal resources. The attacker may use stolen credentials, remote services, vulnerabilities, or administrative tools to expand access. This activity is important because an initial compromise does not necessarily provide access to the attacker’s ultimate target. Network segmentation, strong authentication, privileged access controls, endpoint monitoring, and unusual authentication detection can limit or expose lateral movement. Understanding internal relationships and trust paths is also valuable because attackers often attempt to move toward systems containing sensitive information or high-value administrative privileges.

Question 158

Which activity is an example of privilege escalation?

  1. Obtaining administrator-level permissions from a lower-privileged account
  2. Updating a user profile photograph
  3. Moving a workstation to another office
  4. Exporting a list of approved software

Correct Answer: 1

Explanation:

Privilege escalation occurs when an attacker or unauthorized user gains permissions beyond those originally available. For example, a compromised standard account might exploit a vulnerability or misconfiguration to obtain administrative privileges. Escalation can be vertical, such as moving from a normal user to administrator, or involve broader access across accounts and systems. Strong privilege separation, secure configuration, timely patching, application controls, and monitoring of unusual privilege changes can reduce exposure. Detecting escalation is important because elevated permissions can allow attackers to disable defenses, access sensitive resources, create persistence mechanisms, or move deeper into an environment.

Question 159

What is data exfiltration?

  1. Unauthorized removal or transfer of information from an environment
  2. Authorized deletion of expired temporary files
  3. Routine synchronization between approved servers
  4. Scheduled movement of backup tapes to storage

Correct Answer: 1

Explanation:

Data exfiltration is the unauthorized transfer or removal of information from an environment controlled by an organization. Attackers may exfiltrate data through web services, cloud storage, email, compromised accounts, removable media, or covert channels. Detecting exfiltration can involve monitoring unusual outbound traffic, large transfers, unexpected destinations, sensitive-data access patterns, and abnormal user behavior. Data loss prevention technologies can provide additional protection by identifying or restricting certain transfers. Organizations should also limit unnecessary access to sensitive information because reducing the amount of accessible data can reduce the potential impact of a compromised account.

Question 160

Which attack technique involves maintaining access after an initial compromise?

  1. Persistence
  2. Enumeration
  3. Reconnaissance
  4. Classification

Correct Answer: 1

Explanation:

Persistence refers to techniques attackers use to maintain access to a compromised environment even after interruptions, reboots, credential changes, or other defensive actions. Examples can include unauthorized scheduled tasks, modified startup mechanisms, additional accounts, malicious services, or other hidden access paths. Security teams can detect persistence by monitoring configuration changes, account creation, startup mechanisms, scheduled tasks, and unexpected services. Removing the original malware may not be sufficient if a persistence mechanism remains active. Effective incident response therefore includes examining how access was maintained and verifying that unauthorized mechanisms have been removed before systems are considered fully recovered.