{"id":17284,"date":"2026-09-21T07:32:34","date_gmt":"2026-09-21T07:32:34","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17284"},"modified":"2026-09-21T07:32:34","modified_gmt":"2026-09-21T07:32:34","slug":"cyber-ab-ccp-practice-test-questions-and-exam-dumps-part6-q101-120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cyber-ab-ccp-practice-test-questions-and-exam-dumps-part6-q101-120\/","title":{"rendered":"Cyber AB CCP Practice Test Questions and Exam Dumps Part6 Q101-120"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ccp-exam-dumps\"><b>Cyber AB CCP Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 101<\/b><\/h3>\n<p><b>Which process identifies and evaluates the security posture of an external service provider before engagement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor risk assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Media formatting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password recovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vendor risk assessment evaluates the cybersecurity risks associated with an external organization before or during a business relationship. The assessment may examine security controls, data handling practices, incident history, compliance evidence, access requirements, and business dependencies. Organizations use these findings to determine whether additional safeguards or contractual requirements are necessary. Third-party relationships can introduce risks because vendors may process sensitive information or connect directly to organizational systems. Vendor assessment should therefore be proportional to the services and information involved. Risk should also be reassessed periodically because a supplier&#8217;s technology, ownership, services, or threat exposure can change.<\/span><\/p>\n<h3><b>Question 102<\/b><\/h3>\n<p><b>Which contract provision gives an organization defined rights to evaluate a supplier&#8217;s security controls?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Equipment warranty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Right-to-audit clause<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Marketing authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shipping schedule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A right-to-audit clause establishes contractual rights allowing an organization to assess or obtain evidence concerning a supplier&#8217;s compliance with specified requirements. Depending on the agreement, this may involve reviewing reports, certifications, questionnaires, or conducting an assessment under defined conditions. Such clauses can improve visibility into third-party security practices, especially when vendors handle sensitive information or provide critical services. The exact audit rights should be clearly defined to avoid ambiguity. Contractual assessment mechanisms should complement, rather than replace, ongoing vendor monitoring and risk management. Organizations should ensure requirements remain appropriate throughout the supplier relationship.<\/span><\/p>\n<h3><b>Question 103<\/b><\/h3>\n<p><b>What is the main security purpose of including incident notification requirements in a vendor contract?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To establish how quickly and through what process the supplier must report relevant incidents<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To guarantee that no breach can occur<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To eliminate the need for internal monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To transfer every organizational responsibility to the supplier<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Contractual incident notification requirements establish expectations for when and how a supplier must inform an organization about relevant security incidents. Clear requirements can specify notification timeframes, communication channels, information to be provided, escalation contacts, and ongoing reporting expectations. Early notification can help the organization assess potential impact and coordinate its own response activities. Such clauses do not prevent incidents from occurring and do not eliminate the organization&#8217;s responsibilities. Organizations should ensure vendor contracts align with applicable legal, regulatory, and business requirements. Defined notification procedures are particularly important when suppliers have access to critical systems or sensitive information.<\/span><\/p>\n<h3><b>Question 104<\/b><\/h3>\n<p><b>Which document typically defines measurable service commitments between a customer and service provider?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data dictionary<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security baseline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service-level agreement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident ticket<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A service-level agreement, or SLA, defines measurable expectations between a service provider and customer. Depending on the relationship, an SLA may address availability, response times, support obligations, performance targets, escalation procedures, and other service characteristics. Security-related expectations can also be incorporated when appropriate. Clear service commitments help organizations evaluate whether a provider is meeting agreed requirements. An SLA should not be confused with a technical security baseline, which establishes configuration expectations for systems. Organizations should periodically review service performance and ensure that contractual commitments remain aligned with current business and security needs.<\/span><\/p>\n<h3><b>Question 105<\/b><\/h3>\n<p><b>Which risk treatment deliberately stops an activity because its associated exposure is unacceptable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk avoidance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk measurement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk documentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk avoidance involves deciding not to perform an activity, use a technology, or continue a process because the associated risk is considered unacceptable or cannot be appropriately controlled. For example, an organization might decide not to offer a particular service if its security requirements cannot reasonably be met. Avoidance differs from mitigation, where the activity continues after safeguards are implemented to reduce exposure. It also differs from acceptance, where management knowingly retains the risk. Decisions about avoidance should consider business objectives, alternatives, costs, obligations, and potential consequences rather than being based solely on the existence of a security concern.<\/span><\/p>\n<h3><b>Question 106<\/b><\/h3>\n<p><b>Which risk treatment keeps an identified exposure while formally acknowledging the remaining risk?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk elimination<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk acceptance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk isolation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk duplication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk acceptance occurs when authorized decision-makers consciously choose to retain a known level of risk. Acceptance should normally be based on established organizational criteria and documented by the appropriate authority. It does not mean that the risk is unknown or ignored. Management should understand the potential consequences and ensure that the remaining exposure falls within acceptable boundaries. Accepted risks should also be periodically reviewed because circumstances can change. A risk that was reasonable to accept previously may require treatment later if threat conditions, business importance, regulations, technology, or potential impact change.<\/span><\/p>\n<h3><b>Question 107<\/b><\/h3>\n<p><b>What is the primary purpose of a risk treatment plan?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To describe actions selected to address identified risks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace the organization&#8217;s asset inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To record employee attendance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To authorize physical construction<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A risk treatment plan documents the actions selected to address identified risks and provides a structured way to track their implementation. Depending on the decision, treatment may involve mitigation, transfer, avoidance, or acceptance. A treatment plan can identify responsible parties, required resources, deadlines, dependencies, and expected outcomes. It helps convert risk analysis into actionable work rather than leaving findings as theoretical observations. Treatment activities should be monitored to determine whether they are completed and whether they actually reduce exposure as intended. Changes in risk conditions may also require the treatment plan to be updated.<\/span><\/p>\n<h3><b>Question 108<\/b><\/h3>\n<p><b>Which activity creates an authoritative record of hardware, software, and other organizational resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat hunting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate signing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Email filtering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An asset inventory provides an organized record of resources that an organization owns, operates, or manages. Assets may include servers, workstations, applications, cloud resources, network devices, databases, and other technology components. Maintaining accurate inventory information supports vulnerability management, access control, incident response, configuration management, and lifecycle planning. Security teams cannot reliably protect resources they do not know exist. Inventory records should therefore be updated when assets are acquired, modified, transferred, retired, or removed. Organizations may automate discovery, but discovered information should still be validated so that inaccurate records do not create misleading security assumptions.<\/span><\/p>\n<h3><b>Question 109<\/b><\/h3>\n<p><b>Why is asset ownership important in cybersecurity governance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It establishes accountability for managing a resource and its associated requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It guarantees that the resource has no vulnerabilities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It removes the need for classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It prevents every possible unauthorized action<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Asset ownership establishes clear accountability for a resource and helps determine who is responsible for decisions concerning its use, protection, classification, and lifecycle. Owners may coordinate with technical custodians who operate the systems where assets are stored or processed. Without defined ownership, security requirements can become unclear and remediation activities may lack accountable decision-makers. Ownership is particularly useful when multiple teams depend on the same resource. Organizations should document ownership and update it when responsibilities change. Clear accountability supports security governance by connecting technical controls with business requirements and decision-making authority.<\/span><\/p>\n<h3><b>Question 110<\/b><\/h3>\n<p><b>Which practice helps ensure outdated software is replaced or removed according to an established lifecycle?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat emulation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset lifecycle management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network tunneling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity federation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Asset lifecycle management governs resources from acquisition through deployment, maintenance, modification, and eventual retirement or disposal. For software, lifecycle management can help identify unsupported versions and ensure that outdated applications are upgraded, replaced, or removed. Unsupported software may no longer receive security updates, increasing exposure to known weaknesses. Lifecycle processes can also address licensing, ownership, configuration, and disposal requirements. Organizations should maintain visibility into asset status and establish responsibilities for lifecycle decisions. Security considerations should be incorporated from acquisition through retirement rather than being treated only after a technology becomes obsolete.<\/span><\/p>\n<h3><b>Question 111<\/b><\/h3>\n<p><b>Which privacy practice gives individuals greater control over how their personal information is handled?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data subject rights management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage deduplication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware acceleration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data subject rights management supports processes that allow individuals to exercise applicable rights concerning their personal information. Depending on the relevant legal framework, rights may include requesting access, correction, deletion, restriction, or other forms of control over personal data. Organizations need procedures for receiving, validating, processing, and responding to such requests within applicable requirements. Effective implementation may require coordination among privacy, legal, security, records, and application teams. The exact rights available differ by jurisdiction and context, so organizations should identify which obligations apply to their processing activities rather than assuming that every individual has identical rights everywhere.<\/span><\/p>\n<h3><b>Question 112<\/b><\/h3>\n<p><b>What is the primary purpose of a data retention schedule?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To define how long categories of information should be maintained<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase network throughput<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To assign administrator privileges<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To determine firewall capacity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A data retention schedule establishes how long specific categories of information should be maintained before approved disposal or further review. Retention periods can be influenced by business requirements, legal obligations, regulatory rules, contractual commitments, and operational needs. Keeping information indefinitely can increase storage costs and exposure, while deleting it too early may create compliance or business problems. Retention schedules should therefore be documented and consistently applied. Organizations should also account for legal holds and other circumstances that can suspend normal disposal. Effective retention management connects information governance with privacy, security, records management, and legal requirements.<\/span><\/p>\n<h3><b>Question 113<\/b><\/h3>\n<p><b>Which method is appropriate for rendering information on a discarded storage device difficult to recover?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure media sanitization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session federation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure media sanitization removes or destroys information from storage media so that previously stored data cannot be readily recovered. The appropriate method depends on the media type, sensitivity of the information, and intended disposition of the device. Techniques may include secure erasure, cryptographic erasure, or physical destruction. Simply deleting files or performing a basic formatting operation may not provide sufficient protection in every situation. Organizations should maintain documented disposal procedures and verify that sensitive media is handled through authorized channels. Sanitization is especially important when devices are being retired, repurposed, returned, or transferred outside organizational control.<\/span><\/p>\n<h3><b>Question 114<\/b><\/h3>\n<p><b>Which principle requires an organization to communicate relevant information about its personal-data processing practices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Concealment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Transparency<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Obfuscation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Transparency requires organizations to provide appropriate information about how personal data is collected, used, stored, shared, and otherwise processed. Clear privacy notices and related communications can help individuals understand organizational practices and applicable choices or rights. Transparency should be meaningful rather than merely presenting complicated information that users cannot reasonably understand. The specific disclosure requirements depend on applicable laws, regulations, and the nature of the processing. Security teams may support transparency by accurately documenting data flows, retention practices, access arrangements, and safeguards so that privacy information reflects actual organizational behavior.<\/span><\/p>\n<h3><b>Question 115<\/b><\/h3>\n<p><b>Which attack manipulates a trusted individual into revealing confidential information or performing an unsafe action?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Social engineering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk partitioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Code compilation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Social engineering involves manipulating people into revealing information, granting access, transferring funds, or performing actions that benefit an attacker. Unlike attacks focused solely on technical vulnerabilities, social engineering exploits human behavior, trust, urgency, authority, curiosity, or fear. Examples include fraudulent messages, impersonation, deceptive phone calls, and manipulated support requests. Organizations can reduce exposure through awareness training, strong verification procedures, multifactor authentication, reporting mechanisms, and carefully designed approval processes. Technical controls remain important because human-targeted attacks can bypass otherwise strong infrastructure protections when personnel are persuaded to perform unauthorized actions.<\/span><\/p>\n<h3><b>Question 116<\/b><\/h3>\n<p><b>Which phishing variant specifically targets a known individual or organization with customized deception?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Generic broadcast phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spear phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Random port scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automated patching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Spear phishing is a targeted form of phishing that uses information about a particular person, department, or organization to make a fraudulent message appear more credible. Attackers may research job responsibilities, business relationships, public information, or organizational terminology before constructing the deception. The customized nature of the message can make detection more difficult than generic mass phishing. Defensive measures include security awareness, strong authentication, email security controls, verification procedures, and reporting mechanisms. Personnel should be cautious when messages request sensitive information, unusual payments, credential changes, or urgent actions, even when the sender appears familiar.<\/span><\/p>\n<h3><b>Question 117<\/b><\/h3>\n<p><b>What distinguishes business email compromise from ordinary unsolicited advertising email?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It commonly attempts to manipulate trusted business communication for fraud or unauthorized action<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It is always sent by a legitimate employee<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It contains only harmless promotional material<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It cannot involve financial requests<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business email compromise, or BEC, involves deceptive activity that abuses trusted business communication to persuade victims to perform unauthorized actions. Attackers may impersonate executives, suppliers, employees, or other trusted parties and request payments, changes to banking information, sensitive documents, or other actions. BEC can involve compromised accounts or convincing impersonation without actually taking control of the legitimate mailbox. Organizations can reduce exposure through payment verification procedures, multifactor authentication, email security controls, staff awareness, and independent confirmation of unusual requests. Financial and sensitive-data workflows should not rely solely on the apparent identity of an email sender.<\/span><\/p>\n<h3><b>Question 118<\/b><\/h3>\n<p><b>Which malware characteristic allows malicious software to replicate itself across systems without requiring a user to manually copy it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm propagation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual installation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A worm is a type of malicious software capable of propagating from one system to another without requiring the same type of manual copying associated with ordinary software distribution. Worms may exploit vulnerabilities, weak credentials, or other mechanisms to spread through connected environments. Rapid propagation can increase the scale and speed of an incident, particularly on poorly segmented networks. Defensive measures include timely patching, network segmentation, endpoint monitoring, access controls, and restricting unnecessary services. Security teams should also monitor unusual scanning or connection patterns because unexpected internal propagation can provide an early indication of worm-like activity.<\/span><\/p>\n<h3><b>Question 119<\/b><\/h3>\n<p><b>Which malware category is commonly designed to maintain concealed privileged access to a compromised system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen saver<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compression utility<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A rootkit is malicious software designed to conceal its presence and potentially maintain privileged access within a compromised system. Rootkits may modify system components or use other techniques to hide files, processes, network connections, or other evidence of compromise. Because they can operate at highly privileged levels, detecting and removing them may be difficult. Organizations should use layered endpoint defenses, integrity monitoring, secure configuration, vulnerability management, and appropriate incident-response procedures. When a system is suspected of containing deeply embedded malicious components, responders may need to consider trusted recovery methods rather than relying solely on routine file deletion.<\/span><\/p>\n<h3><b>Question 120<\/b><\/h3>\n<p><b>What is the primary purpose of command-and-control infrastructure used by attackers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide authorized software updates<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To facilitate communication between compromised systems and the attacker<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To synchronize employee calendars<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To manage legitimate backup schedules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Command-and-control, or C2, infrastructure enables attackers to communicate with compromised systems and issue instructions or receive information. Depending on the malware and attack campaign, C2 communication may support task execution, data collection, persistence, additional payload delivery, or coordination of compromised hosts. Detecting C2 activity can involve examining unusual destinations, communication patterns, domain behavior, network timing, and endpoint processes. Organizations can reduce exposure through network monitoring, DNS security, endpoint detection, application controls, segmentation, and threat intelligence. Because attackers may attempt to disguise C2 traffic as legitimate communication, detection should consider both network and endpoint context.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cyber AB CCP Exam Dumps and Practice Test Dumps &nbsp; Question 101 Which process identifies and evaluates the security posture of an external service provider before engagement? Vendor risk assessment Media formatting Network address translation Password recovery Correct Answer: 3 Explanation: Vendor risk assessment evaluates the cybersecurity risks associated with an external organization [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17284"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17284"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17284\/revisions"}],"predecessor-version":[{"id":17285,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17284\/revisions\/17285"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17284"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17284"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17284"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}