{"id":17288,"date":"2026-09-21T07:33:17","date_gmt":"2026-09-21T07:33:17","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17288"},"modified":"2026-09-21T07:33:17","modified_gmt":"2026-09-21T07:33:17","slug":"cyber-ab-ccp-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cyber-ab-ccp-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"Cyber AB CCP Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ccp-exam-dumps\"><b>Cyber AB CCP Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 141<\/b><\/h3>\n<p><b>What is the primary purpose of a security governance framework?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Establish organizational security direction<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure endpoint antivirus software<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restore deleted production files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scan applications for coding flaws<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security governance framework establishes the organizational direction for protecting information and technology resources. It defines how security decisions are made, who has authority, and how security objectives align with business requirements. Governance typically includes policies, accountability structures, oversight mechanisms, and decision-making principles. It differs from operational security activities, which focus on implementing and maintaining controls. A strong governance structure helps ensure that cybersecurity is treated as an organizational responsibility rather than only a technical function. It also provides a basis for measuring security performance and holding responsible parties accountable for agreed requirements.<\/span><\/p>\n<h3><b>Question 142<\/b><\/h3>\n<p><b>What does a risk tolerance statement primarily define?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The systems requiring daily backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The amount of variation from objectives the organization can accept<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The employees authorized to approve invoices<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The software versions permitted on laptops<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk tolerance describes the degree of variation from established objectives that an organization is willing to accept. It provides practical boundaries for managing uncertainty after risk appetite has established the broader level of risk the organization is prepared to pursue or retain. For example, an organization might define a very small tolerance for unauthorized disclosure of highly sensitive information. Risk tolerance can therefore guide decisions about controls, escalation, and risk treatment. It is not the same as a backup requirement, software standard, or financial approval process. Clearly defined tolerance levels help security teams determine when a risk requires additional attention.<\/span><\/p>\n<h3><b>Question 143<\/b><\/h3>\n<p><b>Who is normally responsible for ensuring a specific security control operates as intended?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control owner<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External customer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Procurement analyst<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Facilities receptionist<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The control owner is generally accountable for ensuring that a particular security control is appropriately implemented, maintained, and functioning as expected. This responsibility may include monitoring performance, coordinating testing, addressing deficiencies, and retaining evidence that demonstrates operation. The control owner is different from a data owner, who is responsible for decisions concerning particular information assets. Assigning ownership prevents security responsibilities from becoming unclear or overlooked. In larger organizations, the person accountable for a control may coordinate with several operational teams, but there should still be a clearly identified owner responsible for its effectiveness.<\/span><\/p>\n<h3><b>Question 144<\/b><\/h3>\n<p><b>What is a compensating control designed to accomplish?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace every security policy with technical rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eliminate the need for risk assessments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Provide an alternative safeguard when the preferred control cannot be used<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove accountability from the original control owner<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A compensating control provides an alternative safeguard when the primary or prescribed control cannot reasonably be implemented. For example, a legacy system might be unable to support a required authentication mechanism, so additional network isolation and monitoring could provide supplementary protection. A compensating control should address the relevant security objective rather than simply being a different technical mechanism. Its suitability should be documented and evaluated according to organizational requirements. Compensating controls do not eliminate the need for risk assessment or accountability. They are used to reduce exposure when the intended control is impractical, unavailable, or incompatible with an existing environment.<\/span><\/p>\n<h3><b>Question 145<\/b><\/h3>\n<p><b>What is the main objective of continuous control monitoring?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detect changes in control performance over time<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Approve employee vacation requests<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace organizational security policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Determine the market value of hardware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Continuous control monitoring focuses on observing security controls over time to identify changes, failures, or deviations from expected conditions. Instead of relying only on occasional assessments, organizations can use automated or recurring monitoring to detect issues sooner. Examples include checking whether required security settings remain enabled or whether privileged access continues to follow established rules. Continuous monitoring can improve visibility into control effectiveness and support faster corrective action. It does not replace governance documentation or policy requirements. Its value comes from providing ongoing evidence about whether controls continue to operate as designed as systems, configurations, and threats change.<\/span><\/p>\n<h3><b>Question 146<\/b><\/h3>\n<p><b>Why is an asset criticality rating useful during security planning?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It identifies which assets are most important to business operations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It determines the physical dimensions of equipment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It assigns usernames to application accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It measures employee training attendance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Asset criticality ratings help an organization distinguish systems and resources according to their importance to business operations. A system supporting essential services may require stronger protection, tighter recovery objectives, or greater monitoring than a nonessential asset. Criticality can also help prioritize vulnerability remediation and continuity planning when resources are limited. The rating should be based on factors such as operational dependency, business impact, regulatory importance, and recovery requirements. It is not simply a measure of hardware size or user activity. Understanding asset criticality allows security teams to focus protective and recovery resources where disruption could have the greatest organizational consequences.<\/span><\/p>\n<h3><b>Question 147<\/b><\/h3>\n<p><b>What is the primary purpose of a configuration management database (CMDB)?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Track relationships and information about technology assets<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encrypt every file stored by an organization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Generate employee performance evaluations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace vulnerability scanning tools<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A configuration management database, or CMDB, stores information about configuration items and their relationships within an organization&#8217;s technology environment. These items may include servers, applications, network devices, and services. Understanding relationships can help security and operations teams assess the potential impact of changes, outages, or vulnerabilities. For example, knowing which business service depends on a particular server can help prioritize remediation. A CMDB does not itself encrypt organizational data or replace vulnerability scanners. Its value comes from maintaining structured information about the technology environment and the dependencies connecting its components.<\/span><\/p>\n<h3><b>Question 148<\/b><\/h3>\n<p><b>What is the main reason organizations establish formal security exceptions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To permanently remove mandatory safeguards<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To document approved deviations from established requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To allow employees to bypass controls without review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To prevent security policies from being updated<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A formal security exception process allows an organization to document and manage situations where an established security requirement cannot currently be met. The process normally records the reason for the exception, affected assets, associated risks, compensating measures, approval authority, and expiration or review date. This creates accountability and prevents informal control bypasses from becoming permanent. Exceptions should be reviewed periodically because circumstances can change and the original limitation may eventually disappear. A properly managed exception does not eliminate the underlying requirement. Instead, it provides a controlled mechanism for handling deviations while maintaining visibility into the resulting risk.<\/span><\/p>\n<h3><b>Question 149<\/b><\/h3>\n<p><b>What is a security charter primarily used to establish?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The authority and responsibilities of a security function<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The encryption algorithm used by a database<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The retention period for application logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The network address of a firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security charter establishes the mandate, authority, responsibilities, and general scope of a security function or program. It can clarify leadership responsibilities, reporting relationships, decision-making authority, and the security program&#8217;s organizational objectives. This helps prevent ambiguity about what the security function is expected and authorized to accomplish. A charter is a governance document rather than a technical configuration record. Encryption choices, firewall addressing, and log retention may be governed by separate standards or procedures. A well-defined charter gives security teams organizational legitimacy and provides a foundation for coordinating security responsibilities across departments.<\/span><\/p>\n<h3><b>Question 150<\/b><\/h3>\n<p><b>Why are security governance committees commonly established?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide cross-functional oversight of security matters<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To perform every vulnerability scan manually<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace all technical administrators<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To issue software licenses to customers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security governance committees bring representatives from relevant business and technical areas together to provide oversight and coordinated decision-making. Members may include security, information technology, legal, privacy, risk, compliance, and business representatives. Their responsibilities can include reviewing significant risks, discussing security priorities, monitoring program performance, and supporting decisions that require multiple organizational perspectives. A governance committee does not replace operational security teams or perform every technical task itself. Its primary value is organizational coordination and oversight. By involving different stakeholders, the committee can help ensure that security decisions consider business requirements alongside technical and compliance considerations.<\/span><\/p>\n<h3><b>Question 151<\/b><\/h3>\n<p><b>What does a control objective describe?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The security outcome a control is intended to achieve<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The employee assigned to purchase hardware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The exact physical location of a server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The number of applications installed on a workstation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A control objective describes the desired outcome that a security control or group of controls should accomplish. For example, an objective might require unauthorized users to be prevented from accessing sensitive information. Specific controls can then be selected or designed to achieve that objective. This distinction is useful because organizations may change technologies while retaining the same underlying security goal. A control objective therefore focuses on what protection should accomplish rather than prescribing one particular implementation. It can also support control testing because assessors can evaluate whether the implemented measures actually achieve the intended security outcome.<\/span><\/p>\n<h3><b>Question 152<\/b><\/h3>\n<p><b>Which activity best demonstrates control effectiveness testing?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Selecting a new security framework<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Checking evidence to determine whether a control works as designed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Purchasing additional storage capacity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Creating employee identification badges<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control effectiveness testing evaluates whether a security control is properly designed and operates as intended. Testers may inspect evidence, examine configurations, observe processes, interview responsible personnel, or perform sampling. The goal is to determine whether the control actually provides the expected protection rather than merely confirming that a policy exists. Testing results can identify deficiencies that require remediation or additional monitoring. Control effectiveness assessments are therefore different from selecting a framework or performing ordinary administrative tasks. Reliable evidence is especially important because conclusions should be based on observable implementation and operation rather than assumptions about how a control is supposed to function.<\/span><\/p>\n<h3><b>Question 153<\/b><\/h3>\n<p><b>What is a zero-day vulnerability?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A flaw publicly documented after being fully patched<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A weakness unknown to defenders or lacking an available fix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A vulnerability that exists only on disconnected systems<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A defect that automatically disappears after rebooting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A zero-day vulnerability refers to a security weakness for which defenders have had little or no opportunity to address the problem before exploitation or public discovery. In many cases, there is initially no vendor patch available, creating a difficult defensive situation. The term is associated with the limited time available to develop and deploy a mitigation. Once a vendor releases a fix, organizations still need to assess affected systems and apply appropriate remediation. A zero-day should not be confused with an old vulnerability that simply remains unpatched. Rapid detection, temporary mitigations, and vendor coordination can help reduce exposure.<\/span><\/p>\n<h3><b>Question 154<\/b><\/h3>\n<p><b>What does CVSS primarily provide for a vulnerability?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A standardized severity scoring approach<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A unique encryption key<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A list of authorized administrators<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A backup restoration sequence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Common Vulnerability Scoring System, or CVSS, provides a standardized method for describing and scoring the severity characteristics of vulnerabilities. Scores can help organizations compare vulnerabilities and prioritize remediation based on factors such as exploitability and potential impact. A CVSS score is useful for prioritization, but it should not be treated as the only factor in deciding remediation order. Asset criticality, exposure, available mitigations, threat activity, and business context can also influence urgency. CVSS is therefore a vulnerability assessment mechanism rather than an encryption system, access-control mechanism, or recovery procedure.<\/span><\/p>\n<h3><b>Question 155<\/b><\/h3>\n<p><b>Which malware characteristic is most associated with encrypting files to demand payment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ransomware behavior<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spyware collection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit concealment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm propagation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Ransomware is malware commonly associated with restricting access to data, frequently through encryption, followed by a demand for payment. Its impact can extend beyond individual devices when shared resources or interconnected systems are affected. Effective defenses include tested backups, endpoint protection, network segmentation, access controls, vulnerability management, and user awareness. Ransomware should not be confused with spyware, which focuses on covert information collection; rootkits, which emphasize concealment and privileged persistence; or worms, which are designed to propagate between systems. Organizations should also consider recovery planning because preventing every infection is difficult in complex environments.<\/span><\/p>\n<h3><b>Question 156<\/b><\/h3>\n<p><b>What is DNS tunneling commonly used to accomplish?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hide data or command traffic within DNS communications<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase the physical speed of network switches<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace certificates used by web servers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatically repair corrupted operating systems<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS tunneling can abuse DNS queries and responses to carry information or command traffic that would not normally belong in DNS communications. Attackers may use this technique for command-and-control activity or data exfiltration because DNS traffic is widely permitted in many environments. Detection can involve analyzing unusual query patterns, abnormal domain structures, excessive request volumes, or unexpected destinations. DNS tunneling is therefore different from ordinary DNS resolution. Network monitoring and properly controlled DNS infrastructure can reduce opportunities for abuse. Organizations should also investigate suspicious DNS behavior alongside endpoint and network telemetry for stronger detection.<\/span><\/p>\n<h3><b>Question 157<\/b><\/h3>\n<p><b>What does lateral movement describe during a cyberattack?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Moving from one compromised system or account to additional internal resources<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Installing a legitimate operating-system update<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Moving backup media into an archive room<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Transferring ownership of a software license<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Lateral movement occurs when an attacker moves from an initially compromised system, account, or network location toward additional internal resources. The attacker may use stolen credentials, remote services, vulnerabilities, or administrative tools to expand access. This activity is important because an initial compromise does not necessarily provide access to the attacker&#8217;s ultimate target. Network segmentation, strong authentication, privileged access controls, endpoint monitoring, and unusual authentication detection can limit or expose lateral movement. Understanding internal relationships and trust paths is also valuable because attackers often attempt to move toward systems containing sensitive information or high-value administrative privileges.<\/span><\/p>\n<h3><b>Question 158<\/b><\/h3>\n<p><b>Which activity is an example of privilege escalation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Obtaining administrator-level permissions from a lower-privileged account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Updating a user profile photograph<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Moving a workstation to another office<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exporting a list of approved software<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privilege escalation occurs when an attacker or unauthorized user gains permissions beyond those originally available. For example, a compromised standard account might exploit a vulnerability or misconfiguration to obtain administrative privileges. Escalation can be vertical, such as moving from a normal user to administrator, or involve broader access across accounts and systems. Strong privilege separation, secure configuration, timely patching, application controls, and monitoring of unusual privilege changes can reduce exposure. Detecting escalation is important because elevated permissions can allow attackers to disable defenses, access sensitive resources, create persistence mechanisms, or move deeper into an environment.<\/span><\/p>\n<h3><b>Question 159<\/b><\/h3>\n<p><b>What is data exfiltration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unauthorized removal or transfer of information from an environment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authorized deletion of expired temporary files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Routine synchronization between approved servers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scheduled movement of backup tapes to storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data exfiltration is the unauthorized transfer or removal of information from an environment controlled by an organization. Attackers may exfiltrate data through web services, cloud storage, email, compromised accounts, removable media, or covert channels. Detecting exfiltration can involve monitoring unusual outbound traffic, large transfers, unexpected destinations, sensitive-data access patterns, and abnormal user behavior. Data loss prevention technologies can provide additional protection by identifying or restricting certain transfers. Organizations should also limit unnecessary access to sensitive information because reducing the amount of accessible data can reduce the potential impact of a compromised account.<\/span><\/p>\n<h3><b>Question 160<\/b><\/h3>\n<p><b>Which attack technique involves maintaining access after an initial compromise?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Persistence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enumeration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reconnaissance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Classification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Persistence refers to techniques attackers use to maintain access to a compromised environment even after interruptions, reboots, credential changes, or other defensive actions. Examples can include unauthorized scheduled tasks, modified startup mechanisms, additional accounts, malicious services, or other hidden access paths. Security teams can detect persistence by monitoring configuration changes, account creation, startup mechanisms, scheduled tasks, and unexpected services. Removing the original malware may not be sufficient if a persistence mechanism remains active. Effective incident response therefore includes examining how access was maintained and verifying that unauthorized mechanisms have been removed before systems are considered fully recovered.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cyber AB CCP Exam Dumps and Practice Test Dumps &nbsp; Question 141 What is the primary purpose of a security governance framework? Establish organizational security direction Configure endpoint antivirus software Restore deleted production files Scan applications for coding flaws Correct Answer: 1 Explanation: A security governance framework establishes the organizational direction for protecting [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17288"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17288"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17288\/revisions"}],"predecessor-version":[{"id":17289,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17288\/revisions\/17289"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17288"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17288"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17288"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}