{"id":17274,"date":"2026-09-21T07:29:52","date_gmt":"2026-09-21T07:29:52","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17274"},"modified":"2026-09-21T07:29:52","modified_gmt":"2026-09-21T07:29:52","slug":"cyber-ab-ccp-practice-test-questions-and-exam-dumps-part1-q1-20","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cyber-ab-ccp-practice-test-questions-and-exam-dumps-part1-q1-20\/","title":{"rendered":"Cyber AB CCP Practice Test Questions and Exam Dumps Part1 Q1-20"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ccp-exam-dumps\"><b>Cyber AB CCP Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 1<\/b><\/h3>\n<p><b>What is the primary purpose of cybersecurity risk management?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identify, assess, and treat security risks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase employee productivity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace organizational policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eliminate every possible threat<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cybersecurity risk management focuses on understanding potential risks and making informed decisions about how those risks should be handled. Organizations typically identify assets and threats, assess the likelihood and impact of adverse events, and then select appropriate treatments such as mitigation, transfer, avoidance, or acceptance. The objective is not to eliminate every possible threat because complete elimination is generally impractical. Instead, organizations establish an acceptable level of risk while protecting important systems and information. Effective risk management also supports business objectives by helping leadership prioritize security resources according to the organization&#8217;s actual exposure and operational requirements.<\/span><\/p>\n<h3><b>Question 2<\/b><\/h3>\n<p><b>Which security principle gives users only the access required for assigned duties?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege means granting an individual, process, or system only the permissions necessary to perform its authorized responsibilities. Limiting privileges reduces the potential damage caused by compromised credentials, accidental misuse, or malicious activity. For example, an employee responsible for reviewing reports may need read access but not permission to modify production databases. Defense in depth uses multiple security layers, while separation of duties divides sensitive responsibilities among different people or roles. Open access follows the opposite approach and generally increases exposure. Least privilege is therefore a fundamental access-control principle for reducing unnecessary authorization.<\/span><\/p>\n<h3><b>Question 3<\/b><\/h3>\n<p><b>Which security control is primarily intended to discourage unauthorized behavior?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preventive control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detective control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deterrent control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Corrective control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A deterrent control is designed to discourage individuals from attempting unauthorized or harmful actions. Warning banners, visible security personnel, and clearly communicated disciplinary consequences can serve as deterrents because they influence behavior before an incident occurs. Preventive controls actively block unwanted events, detective controls identify events that have occurred or are occurring, and corrective controls help restore systems after an incident. A deterrent may not technically prevent an attack, but it can reduce the likelihood that someone will attempt prohibited activity. Security programs often combine deterrent controls with preventive and detective mechanisms.<\/span><\/p>\n<h3><b>Question 4<\/b><\/h3>\n<p><b>What does confidentiality protect against?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unauthorized modification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unauthorized disclosure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service interruption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware failure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Confidentiality is the protection of information from unauthorized access or disclosure. It ensures that sensitive information is available only to individuals, systems, or processes that have legitimate authorization to view it. Access controls, encryption, data classification, and secure communication channels are common confidentiality safeguards. Integrity addresses unauthorized modification or destruction of information, while availability focuses on reliable access to systems and data when needed. Hardware failure can affect availability but does not specifically define a confidentiality concern. Protecting confidentiality is particularly important for sensitive personal, financial, proprietary, and operational information.<\/span><\/p>\n<h3><b>Question 5<\/b><\/h3>\n<p><b>Which document formally defines acceptable employee behavior when using organizational technology?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident response plan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business continuity plan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Acceptable use policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disaster recovery procedure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An acceptable use policy establishes expectations for how employees and other authorized users may use organizational systems, networks, applications, and information resources. It can address activities such as personal use, prohibited software, internet usage, credential handling, removable media, and protection of organizational information. An incident response plan focuses on handling security incidents, a business continuity plan addresses continued operations during disruptions, and a disaster recovery procedure focuses on restoring technology and services. The acceptable use policy therefore provides the behavioral framework users are expected to follow while interacting with organizational technology.<\/span><\/p>\n<h3><b>Question 6<\/b><\/h3>\n<p><b>Which authentication factor category includes a fingerprint?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you know<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Somewhere you are<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you have<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you are<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A fingerprint is an example of the <\/span><b>something you are<\/b><span style=\"font-weight: 400;\"> authentication factor because it represents a biometric characteristic of the individual. Other biometric examples include facial characteristics, iris patterns, and voice characteristics. Something you know includes information such as passwords or PINs. Something you have refers to possession of an item such as a hardware token or smart card. Somewhere you are can represent a location-based factor. Multifactor authentication becomes stronger when different factor categories are combined rather than relying exclusively on one authentication characteristic.<\/span><\/p>\n<h3><b>Question 7<\/b><\/h3>\n<p><b>What is the main purpose of security awareness training?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Teach users to recognize and respond to security risks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure network routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace technical security controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Approve software licenses<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security awareness training helps users understand common security risks and the behaviors expected when handling organizational information and technology. Training may cover phishing, password protection, social engineering, reporting procedures, removable media, physical security, and safe handling of sensitive information. Users are an important part of an organization&#8217;s security environment because attackers may target human behavior rather than technical vulnerabilities. Awareness training does not replace firewalls, endpoint protection, identity controls, or other technical safeguards. Instead, it complements those controls by helping personnel recognize suspicious situations and respond according to established procedures.<\/span><\/p>\n<h3><b>Question 8<\/b><\/h3>\n<p><b>Which principle requires critical responsibilities to be divided among multiple individuals?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least functionality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data minimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure defaults<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties divides sensitive responsibilities so that one individual cannot independently complete an entire high-risk process. For example, one employee might create a financial transaction while another approves it. This reduces opportunities for fraud, abuse, or undetected mistakes because multiple people participate in the process. Least functionality limits systems to necessary functions, data minimization reduces unnecessary collection or retention, and secure defaults establish safer initial configurations. Separation of duties is especially valuable for privileged administrative activities, financial processes, and other operations where concentrated authority could create significant risk.<\/span><\/p>\n<h3><b>Question 9<\/b><\/h3>\n<p><b>Which control category identifies suspicious activity after it occurs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preventive<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deterrent<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detective controls are designed to identify security events, policy violations, or suspicious activity. Examples include intrusion detection systems, security monitoring, audit logs, and certain alerting mechanisms. These controls do not necessarily stop an event from occurring, but they provide visibility that can help security personnel recognize and investigate problems. Preventive controls attempt to stop unwanted activity before it succeeds, deterrent controls discourage harmful behavior, and recovery controls help restore operations after an incident. Effective security architectures commonly combine all these control categories so that prevention, detection, response, and recovery work together.<\/span><\/p>\n<h3><b>Question 10<\/b><\/h3>\n<p><b>Which asset classification normally requires the strongest protection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public information<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internal information<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restricted information<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Published marketing material<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Restricted information generally represents highly sensitive information whose unauthorized disclosure, alteration, or loss could cause significant harm to an organization or its stakeholders. Examples might include sensitive personal information, critical intellectual property, regulated records, or confidential security information, depending on the organization&#8217;s classification scheme. Public information is intended for unrestricted disclosure, while internal information is generally limited to organizational use. Marketing material may also be publicly distributed. Security controls should be aligned with the sensitivity and business impact associated with each classification rather than applying identical protections to every type of information.<\/span><\/p>\n<h3><b>Question 11<\/b><\/h3>\n<p><b>What does integrity ensure about information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It remains accurate and protected from unauthorized alteration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It is accessible to everyone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It is stored indefinitely<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It is always publicly available<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Integrity ensures that information remains accurate, complete, and protected against unauthorized modification or destruction. Controls supporting integrity include access restrictions, hashing, digital signatures, version controls, audit trails, and change-management processes. These mechanisms help organizations determine whether information has been altered improperly and establish accountability for changes. Confidentiality limits unauthorized disclosure, while availability concerns timely and reliable access. Information does not need to be publicly available or retained indefinitely to maintain integrity. The essential requirement is that authorized information remains trustworthy and that unauthorized changes can be prevented or detected.<\/span><\/p>\n<h3><b>Question 12<\/b><\/h3>\n<p><b>Which process determines whether a security event has become an incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset disposal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Software deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Capacity planning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Incident classification evaluates a reported security event against established criteria to determine its significance and appropriate response. Not every unusual event is automatically treated as a security incident. Organizations may consider factors such as affected assets, business impact, scope, severity, and evidence of unauthorized activity. Classification helps response teams prioritize resources and follow the appropriate escalation procedures. Asset disposal concerns the secure retirement of equipment or information, software deployment introduces applications or updates, and capacity planning addresses resource requirements. Incident classification therefore helps determine how a security event should be handled operationally.<\/span><\/p>\n<h3><b>Question 13<\/b><\/h3>\n<p><b>Which principle focuses on keeping systems limited to necessary capabilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least functionality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Failover<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Redundancy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least functionality means configuring systems, applications, and devices to provide only the capabilities necessary for their intended purpose. Removing unnecessary services, applications, ports, protocols, and features reduces the attack surface and limits opportunities for exploitation. Defense in depth uses multiple layers of protection, while failover and redundancy focus primarily on resilience and continued operation. For example, a server that does not require an unused network service should have that service disabled rather than leaving it available unnecessarily. Least functionality is therefore an effective way to reduce unnecessary exposure within an environment.<\/span><\/p>\n<h3><b>Question 14<\/b><\/h3>\n<p><b>Which activity verifies that an employee still requires assigned system access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An access review examines assigned permissions to determine whether users still require them for their current responsibilities. Regular reviews can identify excessive privileges, outdated accounts, inappropriate group memberships, and access that remained after a role change. This supports least privilege and reduces the risk associated with stale authorization. Log rotation manages the lifecycle of recorded events, vulnerability scanning identifies weaknesses, and network segmentation separates systems or traffic zones. Access reviews are therefore an important administrative control for maintaining appropriate authorization over time.<\/span><\/p>\n<h3><b>Question 15<\/b><\/h3>\n<p><b>Which attack attempts to manipulate people into revealing protected information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Social engineering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk fragmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Social engineering attacks exploit human behavior rather than relying exclusively on technical vulnerabilities. Attackers may impersonate trusted individuals, create urgency, exploit authority, or use deceptive communication to persuade victims to reveal information or perform unsafe actions. Phishing, pretexting, baiting, and impersonation are common examples. Organizations reduce social-engineering risk through awareness training, verification procedures, strong authentication, and reporting mechanisms. Disk fragmentation affects storage organization, packet routing determines network paths, and data compression reduces file size. None of those activities describes manipulation of people for unauthorized access or information disclosure.<\/span><\/p>\n<h3><b>Question 16<\/b><\/h3>\n<p><b>Which security objective focuses on keeping services operational when needed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confidentiality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Integrity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accountability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Availability means that authorized users can access systems, services, and information when they need them. Availability controls include redundancy, backups, resilient architecture, capacity management, monitoring, disaster recovery, and protection against service-disruption attacks. Confidentiality protects information from unauthorized disclosure, integrity protects information from unauthorized modification, and accountability supports tracing actions to responsible entities. An organization may have highly confidential and accurate data, but if authorized personnel cannot access it when required, availability has not been adequately maintained. Availability is therefore a core component of the cybersecurity triad.<\/span><\/p>\n<h3><b>Question 17<\/b><\/h3>\n<p><b>Which document describes how an organization should respond to cybersecurity incidents?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident response plan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Procurement policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password standard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data retention schedule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An incident response plan establishes the organization&#8217;s approach to handling cybersecurity incidents. It typically defines roles, responsibilities, communication paths, escalation requirements, investigation activities, containment strategies, evidence handling, recovery steps, and post-incident activities. Having a documented plan allows responders to act more consistently during stressful situations and reduces uncertainty about responsibilities. A procurement policy governs purchasing activities, a password standard establishes credential requirements, and a data retention schedule defines how long information should be retained. The incident response plan specifically addresses coordinated actions during security incidents.<\/span><\/p>\n<h3><b>Question 18<\/b><\/h3>\n<p><b>Which practice helps ensure security requirements are considered before a new system is deployed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure disposal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security-by-design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log archival<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account deactivation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security-by-design integrates security considerations into the planning, architecture, development, and implementation of a system rather than treating security as an afterthought. Requirements such as authentication, authorization, encryption, logging, privacy, resilience, and secure configuration can be addressed early in the lifecycle. Early consideration generally makes security requirements easier to incorporate into system architecture and development processes. Secure disposal applies when assets are retired, log archival concerns preservation of records, and account deactivation removes access when it is no longer required. Security-by-design therefore emphasizes security throughout system development.<\/span><\/p>\n<h3><b>Question 19<\/b><\/h3>\n<p><b>Which physical control restricts unauthorized entry into a secured facility?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Badge-controlled door<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A badge-controlled door is a physical access control that restricts entry to authorized individuals. Access badges can be associated with identities and may generate records showing when personnel enter or leave protected areas. Physical controls are important because unauthorized physical access can allow attackers to reach systems, devices, storage media, or sensitive documents directly. Encryption protects information, password policies govern authentication requirements, and file integrity monitoring detects changes to digital files. A badge-controlled door directly addresses the physical boundary of a protected facility and helps prevent unauthorized entry.<\/span><\/p>\n<h3><b>Question 20<\/b><\/h3>\n<p><b>Which security process removes access promptly when an employee leaves an organization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account deprovisioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk acceptance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration baselining<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Account deprovisioning removes or disables a user&#8217;s access when employment or authorization ends. Prompt deprovisioning is important because inactive accounts can become targets for attackers and may retain access to sensitive systems if they are not properly managed. An effective offboarding process can include disabling accounts, revoking sessions and credentials, recovering organizational devices, removing group memberships, and reviewing privileged access. Vulnerability assessment identifies technical weaknesses, risk acceptance documents an intentional decision to tolerate a risk, and configuration baselining establishes approved system settings. Deprovisioning directly addresses access removal during employee separation.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cyber AB CCP Exam Dumps and Practice Test Dumps &nbsp; Question 1 What is the primary purpose of cybersecurity risk management? Identify, assess, and treat security risks Increase employee productivity Replace organizational policies Eliminate every possible threat Correct Answer: 1 Explanation: Cybersecurity risk management focuses on understanding potential risks and making informed decisions [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17274"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17274"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17274\/revisions"}],"predecessor-version":[{"id":17275,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17274\/revisions\/17275"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17274"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17274"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17274"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}