{"id":17290,"date":"2026-09-21T07:33:44","date_gmt":"2026-09-21T07:33:44","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17290"},"modified":"2026-09-21T07:33:44","modified_gmt":"2026-09-21T07:33:44","slug":"cyber-ab-ccp-practice-test-questions-and-exam-dumps-part9-q161-180","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cyber-ab-ccp-practice-test-questions-and-exam-dumps-part9-q161-180\/","title":{"rendered":"Cyber AB CCP Practice Test Questions and Exam Dumps Part9 Q161-180"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ccp-exam-dumps\"><b>Cyber AB CCP Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 161<\/b><\/h3>\n<p><b>What is the primary purpose of a privacy impact assessment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Measure network bandwidth usage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identify privacy risks associated with processing personal information<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Calculate hardware depreciation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Determine employee attendance levels<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A privacy impact assessment, or PIA, evaluates how a planned system, process, or activity may affect the privacy of individuals whose information is collected or processed. It helps identify potential privacy risks before or during implementation and supports the selection of appropriate safeguards. A PIA may examine the types of information involved, collection purposes, access, retention, sharing, and potential impacts on individuals. Conducting the assessment early can allow privacy concerns to be addressed during system design rather than after deployment. It is therefore an important component of responsible information handling and privacy risk management.<\/span><\/p>\n<h3><b>Question 162<\/b><\/h3>\n<p><b>Which principle requires personal information to be collected for clearly defined purposes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data portability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Purpose limitation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cryptographic agility<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Purpose limitation requires organizations to identify and communicate legitimate purposes for collecting personal information and avoid using that information in ways incompatible with those purposes. The principle encourages organizations to consider why information is needed before collecting it and to prevent unnecessary secondary uses. Purpose limitation can influence privacy notices, system design, data-sharing arrangements, and retention practices. It differs from data portability, which concerns transferring information, and network segmentation, which is a security architecture technique. Applying purpose limitation can reduce unnecessary processing and help organizations maintain clearer boundaries around how personal information is used.<\/span><\/p>\n<h3><b>Question 163<\/b><\/h3>\n<p><b>What is pseudonymization intended to achieve?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanently destroy personal information<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove all security requirements from sensitive data<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduce direct identifiability by replacing identifiers with alternatives<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Make information publicly searchable<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Pseudonymization reduces direct identification of individuals by replacing identifying information with another value, such as a randomly generated identifier. The original identity may still be recoverable when additional information, such as a mapping table or key, is available and properly protected. This distinguishes pseudonymization from anonymization, where information is processed so that individuals should no longer be reasonably identifiable. Pseudonymization can reduce exposure when organizations need to process information for legitimate purposes while limiting direct identifiers. The replacement mechanism and associated information must still receive appropriate security protection because re-identification may remain possible.<\/span><\/p>\n<h3><b>Question 164<\/b><\/h3>\n<p><b>What is tokenization primarily used to accomplish?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Convert passwords into stronger passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace sensitive values with non-sensitive surrogate tokens<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compress large database tables<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Synchronize clocks between servers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tokenization replaces sensitive information with a surrogate value called a token. The token itself generally has no meaningful value outside the controlled tokenization system, while the original sensitive value is stored separately and protected. Organizations may use tokenization to reduce the exposure of payment information or other sensitive data within applications and databases. Unlike encryption, tokenization does not necessarily transform the original value through a reversible cryptographic algorithm. Proper token management and protection of the underlying data remain essential. Tokenization can also reduce the number of systems that directly handle sensitive information.<\/span><\/p>\n<h3><b>Question 165<\/b><\/h3>\n<p><b>Which control helps prevent unauthorized use of removable storage devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint device-control restrictions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public website analytics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database indexing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee scheduling software<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint device-control restrictions can regulate how removable storage devices such as USB drives are used on organizational systems. Depending on policy, the control may block unauthorized devices, permit only approved hardware, restrict writing to removable media, or require encryption. These measures can reduce the risk of data theft, malware introduction, and uncontrolled movement of sensitive information. Device control should normally be combined with user awareness, endpoint monitoring, and data protection requirements. Merely having a written policy may not prevent technical misuse. Technical restrictions provide an enforcement mechanism that can help organizations apply their removable-media requirements consistently.<\/span><\/p>\n<h3><b>Question 166<\/b><\/h3>\n<p><b>What does data masking generally do?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanently erase information from storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Display sensitive values in a modified or obscured form<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase database query performance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Create additional administrator accounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data masking changes how sensitive information is displayed or represented so that unauthorized viewers cannot see the original values. For example, an application might display only the last few digits of an account number while concealing the remaining characters. Masking is particularly useful in user interfaces, testing environments, support systems, and reporting applications where full values are unnecessary. Unlike deletion, masking does not necessarily remove the original information from the underlying system. Access controls and other safeguards are still required because improperly protected original data could remain accessible through another interface or process.<\/span><\/p>\n<h3><b>Question 167<\/b><\/h3>\n<p><b>Why might an organization deploy a secure email gateway?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To manage physical building access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To filter and inspect inbound and outbound email threats<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace all endpoint operating systems<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To assign database ownership<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A secure email gateway provides a security layer for organizational email traffic. It can inspect messages for malicious attachments, phishing indicators, spam, suspicious links, malware, and policy violations. Depending on its capabilities, it may also enforce email encryption or data-loss prevention rules. Positioning the gateway between external mail sources and internal mail infrastructure allows organizations to apply filtering before messages reach users. It does not eliminate the need for endpoint protection or user awareness because some malicious content can evade automated filtering. Email security is strongest when gateway controls operate alongside authentication, monitoring, and awareness measures.<\/span><\/p>\n<h3><b>Question 168<\/b><\/h3>\n<p><b>Which DNS-related technology helps authenticate the origin of DNS data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS Security Extensions, or DNSSEC, add cryptographic authentication to DNS responses. They help clients verify that DNS information originated from an authorized source and has not been altered during transmission. This helps address attacks involving forged or manipulated DNS responses. DNSSEC does not provide general confidentiality for DNS queries, nor does it replace transport encryption. Its primary security value is authenticity and integrity of DNS data. Organizations implementing DNSSEC must manage signing keys and supporting DNS records correctly. Proper validation by resolvers is also necessary for the protections to be effective.<\/span><\/p>\n<h3><b>Question 169<\/b><\/h3>\n<p><b>What is the purpose of DMARC in email security?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign wireless network channels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compress email attachments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Define employee password complexity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Help domain owners specify handling for authentication failures<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Domain-based Message Authentication, Reporting, and Conformance, or DMARC, allows domain owners to publish policies concerning messages that fail specified email authentication checks. It builds on mechanisms such as SPF and DKIM and can provide reporting that helps organizations understand how their domains are being used. DMARC can therefore help reduce certain forms of domain impersonation and improve visibility into unauthorized email activity. A DMARC policy can instruct receiving systems to take actions such as monitoring, quarantining, or rejecting messages that fail the relevant requirements. Correct configuration and gradual deployment are important to avoid disrupting legitimate mail.<\/span><\/p>\n<h3><b>Question 170<\/b><\/h3>\n<p><b>What is the main purpose of a web application firewall?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Protect web applications by filtering application-layer requests<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Synchronize time across network devices<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manage employee identity documents<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store offline backup media<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A web application firewall, or WAF, monitors and filters HTTP or HTTPS requests directed toward web applications. It can help detect or block certain application-layer attacks, including malicious input patterns and abnormal requests. A WAF provides an additional defensive layer between clients and applications, but it should not be treated as a replacement for secure application development. Developers still need proper input validation, authentication, authorization, and secure coding practices. WAF rules should also be maintained as applications and attack techniques evolve. Proper tuning is important because overly broad rules may block legitimate requests while weak rules may fail to detect malicious activity.<\/span><\/p>\n<h3><b>Question 171<\/b><\/h3>\n<p><b>Which protocol is commonly used to provide centralized authentication for network access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NFS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IMAP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RADIUS, or Remote Authentication Dial-In User Service, is commonly used to centralize authentication, authorization, and accounting for network access services. It can support environments such as wireless networks, VPN services, and network access infrastructure. Centralizing these functions can reduce the need for independent credentials and authentication configurations across numerous access devices. RADIUS can work with various authentication methods and is frequently integrated with directory services. Its use does not eliminate the need for strong identity controls or appropriate authorization policies. Organizations should protect communications and administrative interfaces associated with the authentication infrastructure.<\/span><\/p>\n<h3><b>Question 172<\/b><\/h3>\n<p><b>What is 802.1X primarily used for?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Email message signing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port-based network access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IEEE 802.1X provides port-based network access control, allowing a network device to require authentication before granting access through a controlled port. It is commonly deployed on wired switches and enterprise wireless networks. An endpoint can be required to authenticate before receiving normal network connectivity, helping organizations prevent unauthorized devices from simply connecting to internal networks. 802.1X commonly works with an authentication server and an authentication method suitable for the environment. It is different from network encryption because its primary purpose is controlling access to the network rather than encrypting application data.<\/span><\/p>\n<h3><b>Question 173<\/b><\/h3>\n<p><b>What is the purpose of egress filtering?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restrict unauthorized outbound network traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase the number of available IP addresses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace endpoint authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatically classify documents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Egress filtering controls traffic leaving an organization&#8217;s network. It can restrict outbound communication to approved destinations, protocols, ports, or address ranges. This can help limit data exfiltration, prevent communication with malicious infrastructure, and reduce the impact of compromised systems attempting to contact external services. Egress controls are especially useful because many security architectures focus heavily on incoming traffic while giving less attention to outbound communication. Effective egress filtering should be aligned with legitimate business requirements so necessary services continue to function. Monitoring denied outbound connections can also provide useful indicators of suspicious activity.<\/span><\/p>\n<h3><b>Question 174<\/b><\/h3>\n<p><b>What is a bastion host generally designed to provide?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A public repository for confidential documents<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A hardened system used as a controlled access point<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A replacement for disaster recovery backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A method for anonymizing all internet traffic<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A bastion host is a hardened system designed to serve as a controlled access point into a protected environment. It may provide administrators with a limited and monitored path to internal systems that should not be directly exposed. Bastion hosts are typically configured with minimal services, strong authentication, restricted access, and extensive monitoring. Their reduced attack surface helps limit opportunities for compromise. A bastion host does not replace backups or automatically anonymize traffic. Organizations may combine bastion hosts with jump servers, privileged access controls, network segmentation, and session monitoring to strengthen administrative access.<\/span><\/p>\n<h3><b>Question 175<\/b><\/h3>\n<p><b>Which technology is commonly used to provide encrypted remote network connectivity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A virtual private network, or VPN, can establish an encrypted communication channel across an untrusted or public network. Organizations commonly use VPNs to provide remote users or connected sites with protected access to internal resources. Depending on the implementation, a VPN can provide confidentiality and integrity for traffic traversing the underlying network. Strong authentication and appropriate authorization remain important because encryption alone does not determine whether a user should access a resource. VPN configurations should also be maintained and monitored because compromised credentials or poorly secured endpoints can still create significant risk.<\/span><\/p>\n<h3><b>Question 176<\/b><\/h3>\n<p><b>What is a secure API gateway commonly responsible for?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Managing and protecting API traffic between clients and services<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physically destroying obsolete storage devices<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Measuring employee satisfaction<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assigning building evacuation routes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An API gateway provides a controlled entry point for API traffic between clients and backend services. Depending on its design, it can enforce authentication, authorization, rate limits, request validation, routing, logging, and other security policies. Centralizing these functions can provide consistent protection across multiple services. An API gateway does not automatically make an underlying application secure; backend services still require appropriate authorization, input validation, and secure implementation. Monitoring gateway activity can also help identify abnormal request patterns and potential abuse. Rate limiting is particularly useful for reducing certain forms of automated misuse and excessive request activity.<\/span><\/p>\n<h3><b>Question 177<\/b><\/h3>\n<p><b>What is rate limiting intended to control?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The physical temperature of data centers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The number of requests accepted during a defined period<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The encryption strength of stored files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The number of employees in a department<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Rate limiting restricts how many requests, transactions, or actions a user, application, or client can perform within a specified period. It is commonly used to protect APIs, login services, and web applications from excessive requests and automated abuse. For example, limiting repeated authentication attempts can reduce the effectiveness of automated credential attacks. Rate limits can also help preserve service availability by preventing individual clients from consuming disproportionate resources. The appropriate threshold depends on business requirements and expected usage patterns. Rate limiting should complement authentication, monitoring, and other controls rather than operate as the sole defense.<\/span><\/p>\n<h3><b>Question 178<\/b><\/h3>\n<p><b>What does federated identity allow organizations to accomplish?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use trusted identity relationships across separate security domains<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eliminate all user authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable authorization controls between applications<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store every password in plain text<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Federated identity allows users to authenticate through a trusted identity provider and access services across separate organizational or security domains. Instead of every service independently maintaining the user&#8217;s authentication information, participating systems establish trust and exchange appropriate identity assertions or tokens. Federation can simplify access management and reduce repeated authentication experiences. It does not eliminate authentication or authorization requirements. Trust relationships must be carefully configured, and identity providers require strong protection because compromise could affect many connected services. Organizations should also define which attributes and permissions can be transferred between participating systems.<\/span><\/p>\n<h3><b>Question 179<\/b><\/h3>\n<p><b>What is a session hijacking attack?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deleting expired authentication logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Capturing or abusing an active user&#8217;s session<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replacing a damaged backup disk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Blocking legitimate DNS records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Session hijacking occurs when an attacker gains unauthorized control of an active authenticated session. The attacker may obtain or abuse a session identifier, token, or other authentication state and use it to impersonate the legitimate user without necessarily knowing the user&#8217;s password. Strong session management can reduce this risk through secure cookies, appropriate session expiration, token protection, reauthentication for sensitive actions, and encrypted communications. Applications should also invalidate sessions when users sign out or when suspicious activity is detected. Session hijacking demonstrates why protecting authentication tokens can be just as important as protecting passwords.<\/span><\/p>\n<h3><b>Question 180<\/b><\/h3>\n<p><b>Which control helps reduce the risk of unauthorized access through stolen authentication tokens?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increasing monitor brightness<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling system backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Extending every session indefinitely<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Requiring reauthentication for sensitive operations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Requiring reauthentication for sensitive operations can reduce the impact of stolen or misused authentication tokens. Even when an attacker obtains an active session, the application can require the user to authenticate again before allowing high-risk actions such as changing security settings or modifying payment information. This creates an additional checkpoint around particularly sensitive operations. Other useful measures include short session lifetimes, secure token storage, token rotation, device monitoring, and prompt session invalidation. Reauthentication does not replace strong authentication at initial login, but it can provide an additional layer of protection when the consequences of session compromise are significant.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cyber AB CCP Exam Dumps and Practice Test Dumps &nbsp; Question 161 What is the primary purpose of a privacy impact assessment? Measure network bandwidth usage Identify privacy risks associated with processing personal information Calculate hardware depreciation Determine employee attendance levels Correct Answer: 2 Explanation: A privacy impact assessment, or PIA, evaluates how [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17290"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17290"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17290\/revisions"}],"predecessor-version":[{"id":17291,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17290\/revisions\/17291"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17290"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17290"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17290"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}