{"id":17276,"date":"2026-09-21T07:30:13","date_gmt":"2026-09-21T07:30:13","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17276"},"modified":"2026-09-21T07:30:13","modified_gmt":"2026-09-21T07:30:13","slug":"cyber-ab-ccp-practice-test-questions-and-exam-dumps-part2-q21-40","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cyber-ab-ccp-practice-test-questions-and-exam-dumps-part2-q21-40\/","title":{"rendered":"Cyber AB CCP Practice Test Questions and Exam Dumps Part2 Q21-40"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ccp-exam-dumps\"><b>Cyber AB CCP Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 21<\/b><\/h3>\n<p><b>Which risk concept describes the amount of uncertainty an organization is willing to pursue while achieving its objectives?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk appetite<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk register<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk ownership<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk treatment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk appetite is the broad amount and type of risk an organization is willing to accept in pursuit of its strategic and operational objectives. It provides direction for making decisions when security risks could affect business goals. Senior leadership typically establishes the organization&#8217;s overall appetite, while individual risk decisions should remain consistent with it. A risk appetite statement can influence investments, controls, and approval thresholds. It differs from risk tolerance, which normally defines more specific boundaries around acceptable variation. Understanding appetite helps cybersecurity professionals determine whether proposed activities align with the organization&#8217;s broader willingness to take risk.<\/span><\/p>\n<h3><b>Question 22<\/b><\/h3>\n<p><b>What is the primary purpose of maintaining a formal risk register?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To authorize employee access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To document identified risks and their treatment status<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace security policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To record software licenses<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A risk register provides a structured record of identified organizational risks and relevant information about them. Depending on the organization&#8217;s process, entries may include risk descriptions, affected assets, likelihood, impact, assigned owners, treatment decisions, and current status. The register helps management maintain visibility into outstanding exposures and track whether planned responses are progressing. It is not intended to replace policies or function as an access-management system. A well-maintained register also supports periodic risk reviews because changes in technology, business operations, or threats can alter previously documented risk conditions.<\/span><\/p>\n<h3><b>Question 23<\/b><\/h3>\n<p><b>Who is normally accountable for deciding how a specific business risk should be handled?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Help desk technician<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Designated risk owner<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External software vendor<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The risk owner is the individual or organizational role accountable for managing a particular risk within an established governance framework. This person typically understands the affected business activity and has sufficient authority to make or approve decisions concerning treatment, acceptance, transfer, avoidance, or mitigation. Security specialists can provide technical analysis and recommendations, but they do not automatically become the business risk owner. Assigning ownership prevents risks from becoming organizationally invisible or remaining without accountability. Clear ownership also makes follow-up easier because someone is responsible for monitoring the risk and ensuring agreed actions are addressed.<\/span><\/p>\n<h3><b>Question 24<\/b><\/h3>\n<p><b>Which assessment focuses on determining how the loss of a business function could affect organizational operations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business impact analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Source-code inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A business impact analysis, or BIA, examines the potential consequences of disruption to important business functions and processes. It helps organizations understand operational dependencies and determine which activities require timely restoration. A BIA may consider financial losses, regulatory consequences, customer effects, operational disruption, and reputational consequences. Its findings can support business continuity and disaster recovery planning. A BIA is different from a technical configuration review because its primary focus is business impact rather than identifying insecure settings. Understanding business priorities allows recovery resources and restoration objectives to be aligned with organizational needs.<\/span><\/p>\n<h3><b>Question 25<\/b><\/h3>\n<p><b>Which risk response involves moving a financial consequence to another party through an agreement or insurance arrangement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk avoidance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk acceptance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk transfer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk elimination<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk transfer involves shifting some financial or contractual consequences of a risk to another party. Common mechanisms include insurance policies, contractual agreements, and outsourcing arrangements with defined responsibilities. Transfer does not necessarily remove the underlying risk itself. For example, an organization may purchase cyber insurance to reduce certain financial consequences associated with an incident, while still needing technical and administrative safeguards. Risk acceptance means knowingly retaining the exposure, whereas avoidance generally involves deciding not to perform the activity that creates the risk. Selecting a treatment depends on business objectives, available controls, cost, and organizational risk criteria.<\/span><\/p>\n<h3><b>Question 26<\/b><\/h3>\n<p><b>What distinguishes residual risk from inherent risk?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Residual risk exists before controls are applied<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Residual risk represents exposure remaining after controls are considered<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Residual risk only applies to physical security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Residual risk is always completely eliminated<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Residual risk refers to the level of exposure that remains after risk treatments and controls have been implemented or considered. Inherent risk describes exposure before accounting for those controls. The distinction helps organizations determine whether implemented safeguards have reduced risk to a level that management is willing to tolerate. Residual risk can still exist even when extensive controls are deployed because no practical control environment eliminates every possible threat. Organizations should periodically reassess residual risk as threats, technologies, vulnerabilities, and business processes change. The remaining exposure may then be accepted, further reduced, transferred, or otherwise treated.<\/span><\/p>\n<h3><b>Question 27<\/b><\/h3>\n<p><b>Which principle limits collected personal information to what is necessary for a defined purpose?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data minimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilege escalation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration inheritance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data minimization is the privacy principle of collecting, processing, and retaining only the personal information that is reasonably necessary for a legitimate and defined purpose. Limiting unnecessary information can reduce privacy exposure and decrease the consequences of a potential compromise. For example, an application should avoid collecting sensitive attributes when those attributes have no meaningful role in delivering its service. Data minimization can also simplify retention and disposal activities because fewer unnecessary records are maintained. It should be considered during system design rather than treated solely as a requirement after information has already been collected.<\/span><\/p>\n<h3><b>Question 28<\/b><\/h3>\n<p><b>What role does a data custodian typically perform?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Establishing corporate risk appetite<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Managing and protecting data according to the owner&#8217;s requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Approving organizational mergers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defining business revenue targets<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A data custodian is generally responsible for the operational handling and protection of data according to requirements established by the data owner and organizational policies. Custodial responsibilities may include maintaining storage systems, implementing safeguards, managing backups, and supporting access controls. The data owner remains responsible for determining appropriate classification, access requirements, or business use of the information. Separating ownership from custody creates clearer accountability. A custodian therefore does not automatically decide the business value or classification of information simply because the custodian operates the technology that stores or processes it.<\/span><\/p>\n<h3><b>Question 29<\/b><\/h3>\n<p><b>Which practice helps ensure information is removed when its approved retention period expires?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data disposal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat hunting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity federation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data disposal is the controlled removal of information when it is no longer required under applicable business, legal, regulatory, or contractual requirements. Secure disposal can involve different methods depending on the storage medium and sensitivity of the information. Examples include secure deletion, cryptographic erasure, or physical destruction of storage media. Disposal should be performed according to documented retention schedules rather than arbitrary individual decisions. Effective disposal reduces unnecessary data exposure and limits the quantity of information an organization must protect. Organizations should also consider legal holds and other requirements that may temporarily prevent otherwise scheduled destruction.<\/span><\/p>\n<h3><b>Question 30<\/b><\/h3>\n<p><b>Which control helps prevent unauthorized personnel from entering a restricted facility by requiring verification at the entrance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Visitor escort log<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Environmental temperature sensor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mantrap entry system<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup generator<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer:4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A mantrap is a physical access-control arrangement consisting of two interlocking doors that regulate movement into a protected area. Typically, one door must close before the other can open, helping prevent unauthorized individuals from simply following an authorized person through an entrance. Mantraps can be combined with badges, biometric verification, cameras, or security personnel. They are particularly useful in locations requiring stronger physical access restrictions. A generator addresses power continuity, while a temperature sensor monitors environmental conditions. Physical controls should be selected according to the sensitivity of the facility and the organization&#8217;s assessment of unauthorized-entry risks.<\/span><\/p>\n<h3><b>Question 31<\/b><\/h3>\n<p><b>What is the main purpose of establishing a secure configuration baseline?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To define an approved starting configuration for systems<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To calculate insurance premiums<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace incident investigations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To determine employee salaries<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A secure configuration baseline defines an approved set of technical settings that systems should maintain. It can specify requirements such as unnecessary service restrictions, authentication settings, logging configuration, permissions, and other security-related parameters. Baselines provide a consistent reference for deployment and configuration assessment. When systems drift away from the approved state, administrators can investigate and correct the deviation. Baselines should be appropriate for the technology and business purpose rather than copied blindly between systems. Regular review is also important because emerging threats, software changes, and organizational requirements can make an older baseline unsuitable.<\/span><\/p>\n<h3><b>Question 32<\/b><\/h3>\n<p><b>Which process prioritizes fixing weaknesses in systems according to their assessed severity and business exposure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset disposal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Document archiving<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Personnel onboarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vulnerability management is the ongoing process of identifying, evaluating, prioritizing, remediating, and monitoring security weaknesses. Effective programs do not necessarily treat every vulnerability identically because severity, exploitability, affected assets, exposure, and business importance can differ substantially. Organizations may use vulnerability assessments and scoring information to establish remediation priorities. After fixes are applied, verification helps confirm that the weakness has actually been addressed. Vulnerability management is therefore more than simply running a scanner. It is a continuing operational discipline that connects technical findings with business risk and remediation activities.<\/span><\/p>\n<h3><b>Question 33<\/b><\/h3>\n<p><b>What does a CVE identifier primarily provide for a publicly documented software vulnerability?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A standardized reference identifier<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A guaranteed remediation deadline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A replacement encryption key<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A hardware inventory number<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A CVE identifier provides a standardized reference for a publicly disclosed cybersecurity vulnerability. Common Vulnerabilities and Exposures, or CVE, identifiers make it easier for security teams, vendors, researchers, and tools to refer to the same vulnerability consistently. A CVE identifier itself does not determine how quickly an organization must remediate the issue. Remediation priority can depend on factors such as exploitability, affected systems, exposure, business criticality, and organizational policy. CVE references are therefore useful for vulnerability tracking and communication, but organizations normally need additional information to determine appropriate treatment.<\/span><\/p>\n<h3><b>Question 34<\/b><\/h3>\n<p><b>Which technique attempts to identify security weaknesses by safely simulating attacks against a system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Penetration testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Capacity planning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Penetration testing involves controlled attempts to exploit security weaknesses in systems, applications, networks, or other environments. The goal is to demonstrate how identified weaknesses could potentially be used and to provide evidence that supports remediation. Testing should be authorized, scoped, and performed under defined rules to avoid unintended operational disruption. Penetration testing differs from vulnerability scanning because a scanner primarily identifies potential weaknesses, while penetration testing can attempt to validate exploitability and understand attack paths. Organizations should document findings and ensure discovered weaknesses are addressed according to established risk-management processes.<\/span><\/p>\n<h3><b>Question 35<\/b><\/h3>\n<p><b>Which activity uses information about adversaries and emerging threats to improve defensive decisions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat intelligence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Media sanitization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business archiving<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Facilities maintenance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat intelligence involves collecting, analyzing, and applying information about threats, threat actors, attack techniques, vulnerabilities, and other relevant security developments. Useful intelligence can help organizations understand which threats may affect their environment and adjust defensive priorities accordingly. Intelligence may come from internal observations, trusted external sources, industry groups, or security research. Simply collecting large quantities of threat information does not automatically create useful intelligence; analysis and contextualization are important. Security teams can use relevant intelligence to improve detection rules, vulnerability priorities, incident preparation, and broader risk decisions.<\/span><\/p>\n<h3><b>Question 36<\/b><\/h3>\n<p><b>What does an indicator of compromise most commonly represent?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A sign suggesting that a security compromise may have occurred<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A contractual service-level target<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A planned equipment replacement date<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A business continuity budget<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An indicator of compromise, or IOC, is an observable artifact or condition that may indicate malicious activity or a security compromise. Examples can include suspicious file hashes, unusual network destinations, malicious domains, unexpected account activity, or known attacker artifacts. Security teams can use IOCs in monitoring and investigation processes to identify potentially affected systems. An IOC does not necessarily prove that an attack occurred because legitimate activity can sometimes resemble malicious behavior. Analysts therefore evaluate indicators alongside additional evidence and context. Maintaining useful IOC information can improve detection and support incident investigation.<\/span><\/p>\n<h3><b>Question 37<\/b><\/h3>\n<p><b>Which attack technique attempts authentication with many accounts using a small number of commonly used passwords?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate pinning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Password spraying is an authentication attack in which an attacker tries a small set of commonly used passwords against many different accounts. This approach differs from traditional brute-force attacks, which may repeatedly attempt many passwords against a single account. Spraying can help attackers avoid account lockout thresholds that are designed to detect repeated failures against one account. Defensive measures include strong password policies, multifactor authentication, monitoring authentication failures, and detecting unusual login patterns. Organizations should also identify and address weak or commonly used credentials because password spraying relies heavily on predictable authentication secrets.<\/span><\/p>\n<h3><b>Question 38<\/b><\/h3>\n<p><b>What is the primary security benefit of network segmentation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It increases every user&#8217;s privileges<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It limits communication between defined network zones<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It removes the need for authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It guarantees that malware cannot spread<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation separates systems or services into distinct network zones and controls communication between them. The objective is to reduce unnecessary connectivity and limit the potential movement of an attacker after an initial compromise. Segmentation can be implemented using technologies such as firewalls, virtual networks, access-control mechanisms, and other network enforcement points. It does not guarantee that malware cannot spread because compromised systems may still communicate through permitted paths. Effective segmentation is based on business and security requirements and should be reviewed as applications, dependencies, and network architectures change.<\/span><\/p>\n<h3><b>Question 39<\/b><\/h3>\n<p><b>Which security technology is primarily designed to collect and correlate events from multiple systems for centralized analysis?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware security module<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security information and event management platform<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression utility<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security information and event management, or SIEM, platform centralizes security-related events from multiple sources and can correlate those events to identify suspicious patterns. Sources may include servers, endpoints, network devices, applications, authentication systems, and security controls. Centralized analysis can help security teams investigate incidents and prioritize alerts. A SIEM is not simply a storage location for logs; its value comes from aggregation, analysis, correlation, alerting, and investigation capabilities. Effective SIEM operations depend on appropriate data sources, useful detection logic, accurate time synchronization, and processes for reviewing and responding to generated alerts.<\/span><\/p>\n<h3><b>Question 40<\/b><\/h3>\n<p><b>Which recovery objective specifies the maximum acceptable amount of data loss measured in time?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery point objective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery time objective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maximum tolerable downtime<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service restoration threshold<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The recovery point objective, or RPO, defines the maximum acceptable amount of data loss expressed as a period of time. For example, an organization with an RPO of 30 minutes aims to ensure that recoverable data is no more than approximately 30 minutes behind the point of disruption. RPO influences backup frequency, replication strategies, and recovery architecture. It differs from RTO, which focuses on how quickly a service or process should be restored. Organizations establish recovery objectives according to business requirements, dependencies, acceptable disruption, and the consequences associated with losing data.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cyber AB CCP Exam Dumps and Practice Test Dumps &nbsp; Question 21 Which risk concept describes the amount of uncertainty an organization is willing to pursue while achieving its objectives? Risk appetite Risk register Risk ownership Risk treatment Correct Answer: 1 Explanation: Risk appetite is the broad amount and type of risk an [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17276"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17276"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17276\/revisions"}],"predecessor-version":[{"id":17277,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17276\/revisions\/17277"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17276"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17276"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17276"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}