{"id":17296,"date":"2026-09-21T07:35:48","date_gmt":"2026-09-21T07:35:48","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17296"},"modified":"2026-09-21T07:35:48","modified_gmt":"2026-09-21T07:35:48","slug":"cyber-ab-ccp-practice-test-questions-and-exam-dumps-part12-q221-240","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cyber-ab-ccp-practice-test-questions-and-exam-dumps-part12-q221-240\/","title":{"rendered":"Cyber AB CCP Practice Test Questions and Exam Dumps Part12 Q221-240"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ccp-exam-dumps\"><b>Cyber AB CCP Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 221<\/b><\/h3>\n<p><b>What is the main purpose of a security baseline?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Define an approved minimum security configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Estimate annual software revenue<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Track employee attendance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Measure office occupancy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security baseline establishes an approved minimum configuration or security condition that systems are expected to maintain. It can specify required settings for operating systems, applications, network devices, or cloud resources. Baselines help organizations reduce configuration inconsistencies and provide a reference for identifying unauthorized or insecure changes. They may include requirements for services, authentication settings, logging, encryption, or unnecessary functionality. Baselines should be reviewed periodically because technology and security requirements evolve. They are particularly useful when combined with configuration monitoring, change management, and automated compliance checks that can identify systems deviating from the approved state.<\/span><\/p>\n<h3><b>Question 222<\/b><\/h3>\n<p><b>What is configuration drift?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accidental loss of encrypted backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gradual deviation from an approved system configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unauthorized entry into a restricted facility<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Failure of an employee awareness course<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration drift occurs when a system gradually moves away from its approved or intended configuration. Changes can result from manual administration, software updates, troubleshooting, temporary modifications, or unauthorized activity. Even seemingly minor differences can create security weaknesses if required protections are disabled or inconsistent settings are introduced. Organizations can reduce configuration drift through standardized baselines, automated configuration management, continuous monitoring, and controlled change processes. Detecting drift allows security teams to determine whether a deviation is legitimate or requires remediation. Maintaining consistent configurations is especially important across large environments where manually checking every system is impractical.<\/span><\/p>\n<h3><b>Question 223<\/b><\/h3>\n<p><b>What is the primary benefit of infrastructure as code security controls?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They eliminate the need for system administrators<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They prevent all cloud outages<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They allow security requirements to be checked in automated deployment definitions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They replace incident response teams<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Infrastructure as code, or IaC, allows infrastructure configurations to be represented in machine-readable files and deployed through automated processes. Security controls can be incorporated into these definitions and checked before resources are deployed. This can help identify insecure configurations earlier and make environments more consistent. Examples include detecting publicly exposed storage, overly broad permissions, or prohibited network settings during deployment validation. IaC security does not eliminate administrators or guarantee availability. Instead, it moves security checks earlier into the infrastructure lifecycle and helps organizations apply repeatable configuration requirements across environments.<\/span><\/p>\n<h3><b>Question 224<\/b><\/h3>\n<p><b>Why is container image scanning performed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To identify vulnerabilities or unwanted components before deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase monitor resolution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace identity verification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To manage office access cards<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Container image scanning examines container images for security issues before they are deployed into an environment. Scanners may identify known vulnerabilities in operating-system packages, application libraries, outdated components, or potentially unwanted content. Early detection allows development and security teams to address problems before affected workloads reach production. Scanning should be integrated into development and deployment workflows and repeated because vulnerabilities can be discovered after an image was originally built. Image scanning is not a complete container security strategy; runtime monitoring, access controls, image provenance, secure configurations, and dependency management remain important.<\/span><\/p>\n<h3><b>Question 225<\/b><\/h3>\n<p><b>What does a software artifact repository primarily store?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Approved build outputs and software packages<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee identity documents<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical access badges<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disaster recovery contact numbers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An artifact repository stores software outputs such as compiled packages, libraries, container images, and other files produced or consumed during development and deployment. Centralized repositories can help organizations control which artifacts are approved for use and preserve version history. Security controls can include access restrictions, integrity verification, retention rules, malware scanning, and provenance information. Protecting repositories is important because attackers who modify legitimate build artifacts may introduce malicious code into downstream systems. Artifact management therefore contributes to software supply-chain security. It should work alongside secure build processes, code review, dependency management, and deployment controls.<\/span><\/p>\n<h3><b>Question 226<\/b><\/h3>\n<p><b>What is build integrity intended to protect?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The physical location of development offices<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The trustworthiness of software produced by a build process<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The lifespan of network cables<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The number of users assigned to an application<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Build integrity focuses on ensuring that software produced by a build process has not been improperly modified and originates from trusted inputs and processes. Compromised build environments can allow attackers to inject malicious code into otherwise legitimate software. Organizations can strengthen build integrity through controlled build environments, protected source repositories, restricted pipeline permissions, dependency verification, artifact signing, and auditable build records. Reproducible or independently verifiable builds can provide additional confidence where appropriate. Protecting the build process is important because compromising a trusted software production mechanism can affect many downstream systems and users.<\/span><\/p>\n<h3><b>Question 227<\/b><\/h3>\n<p><b>What is code signing primarily used to provide?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Evidence that software came from an identified signing source and was not altered<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Faster execution of application code<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatic removal of software vulnerabilities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical protection for development servers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Code signing uses cryptographic signatures to help establish the authenticity and integrity of software or other digital code. A valid signature can provide evidence that the signed content was associated with the holder of a particular signing key and has not been altered since signing, assuming the key and trust process remain secure. Code signing does not prove that software is free of vulnerabilities or malicious behavior. Organizations must protect signing keys carefully because unauthorized use could allow attackers to produce apparently trusted software. Verification mechanisms should also validate signatures against appropriate trusted certificates or keys.<\/span><\/p>\n<h3><b>Question 228<\/b><\/h3>\n<p><b>Why is dependency pinning useful in software development?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It prevents developers from using version control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It ensures a project consistently references specified dependency versions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It automatically removes all vulnerable libraries<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It eliminates the need for application testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dependency pinning specifies particular versions of external software components instead of allowing builds to automatically select changing versions. This improves reproducibility and reduces the possibility that an unexpected dependency update introduces breaking changes or security concerns. Pinning does not guarantee that a selected version is secure; pinned components still need vulnerability monitoring and planned updates. Teams should establish processes for reviewing pinned dependencies and upgrading them when security fixes become available. Dependency management is especially important in automated build environments because uncontrolled changes to external packages can alter software behavior without developers intentionally modifying application source code.<\/span><\/p>\n<h3><b>Question 229<\/b><\/h3>\n<p><b>What is a secrets rotation process designed to accomplish?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Periodically replace sensitive credentials or keys<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase storage capacity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete application source code<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable all service accounts permanently<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secrets rotation involves replacing sensitive authentication material such as API keys, passwords, tokens, or cryptographic credentials according to defined requirements. Regular rotation can reduce the period during which a compromised secret remains useful. Rotation is particularly important when credentials are long-lived or when exposure is suspected. Automated systems can help rotate secrets while minimizing service interruption. Organizations should also maintain procedures for emergency rotation following suspected compromise. Rotation alone is not sufficient if secrets are stored insecurely or widely shared. Access restrictions, secure storage, monitoring, and proper lifecycle management should accompany rotation practices.<\/span><\/p>\n<h3><b>Question 230<\/b><\/h3>\n<p><b>What is a workload identity primarily associated with?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identifying and authorizing applications or automated workloads<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assigning employees to office departments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recording physical equipment dimensions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scheduling backup maintenance rooms<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Workload identity provides a way for applications, services, containers, or other automated workloads to authenticate and receive appropriate authorization without relying on a human user&#8217;s credentials. This can reduce the risks associated with embedding long-lived passwords or static secrets into application code. Workload identities can be integrated with cloud platforms, identity providers, and service authorization systems. Permissions should follow least-privilege principles so workloads receive only the access they require. Proper lifecycle management is also necessary because identities associated with retired applications or services should no longer remain active.<\/span><\/p>\n<h3><b>Question 231<\/b><\/h3>\n<p><b>What is adaptive authentication designed to do?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Apply authentication requirements based on assessed context or risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable authentication for internal users<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace all authorization decisions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store authentication secrets in application logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Adaptive authentication adjusts authentication requirements according to contextual or risk-related information. Factors may include device condition, location, behavior, network characteristics, previous activity, or other signals. A low-risk access attempt might proceed normally, while an unusual request could trigger stronger verification. This approach can improve security by applying additional controls when circumstances suggest elevated risk. Adaptive authentication does not eliminate authorization because determining what a user may access remains a separate concern. Organizations should carefully configure risk signals and fallback mechanisms so attackers cannot easily manipulate conditions to bypass stronger authentication requirements.<\/span><\/p>\n<h3><b>Question 232<\/b><\/h3>\n<p><b>What is passwordless authentication intended to reduce?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The number of approved network devices<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reliance on reusable passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The need for software updates<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The number of security logs generated<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Passwordless authentication reduces or eliminates reliance on traditional reusable passwords as the primary authentication secret. Modern approaches may use cryptographic credentials, hardware-backed authenticators, biometrics combined with secure devices, or other authentication mechanisms. Reducing password dependence can address risks such as password reuse, phishing, credential stuffing, and weak password selection. Passwordless systems still require secure enrollment, account recovery, device protection, and lifecycle management. Removing passwords does not automatically remove all authentication risks. Organizations should ensure that recovery procedures and alternative authentication paths are also protected because attackers may target weaker fallback mechanisms.<\/span><\/p>\n<h3><b>Question 233<\/b><\/h3>\n<p><b>What is a secure cookie attribute used to help ensure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cookies are transmitted only through protected connections<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cookies are stored permanently<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cookies can be accessed by every application<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cookies bypass authentication controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Secure cookie attribute instructs a browser to send the associated cookie only over an HTTPS connection. This helps reduce the risk of session information being exposed through an unencrypted HTTP connection. Secure cookies should be considered alongside other protections such as appropriate expiration, the HttpOnly attribute where suitable, and appropriate SameSite settings. These mechanisms address different aspects of cookie security and do not replace secure application design. Session cookies are particularly sensitive because possession of a valid session identifier may allow an attacker to impersonate an authenticated user.<\/span><\/p>\n<h3><b>Question 234<\/b><\/h3>\n<p><b>What is the purpose of the HttpOnly cookie attribute?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Force cookies to expire after one minute<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Prevent cookies from being transmitted over HTTPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restrict client-side scripts from directly accessing the cookie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatically encrypt the web server database<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The HttpOnly attribute helps prevent client-side scripts from directly accessing a cookie through browser scripting interfaces. This can reduce the ability of certain client-side attacks to directly retrieve session cookies. It does not prevent the browser from sending the cookie to the appropriate server, and it does not itself protect against every form of cross-site scripting or session compromise. Secure transport, output encoding, input handling, and appropriate cookie scope remain important. Cookie attributes should therefore be used together as part of a broader session-security strategy rather than treated as standalone protection.<\/span><\/p>\n<h3><b>Question 235<\/b><\/h3>\n<p><b>What is the purpose of a network tap?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Provide a copy of network traffic for monitoring or analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encrypt all stored database records<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign identities to cloud workloads<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manage employee training schedules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A network tap provides a way to obtain a copy of network traffic for monitoring, troubleshooting, or security analysis. Security teams can use traffic copies with network monitoring and detection systems to examine communications without necessarily placing the monitoring tool directly inline with production traffic. Taps can support incident investigation, performance analysis, and detection activities. Their deployment should consider network architecture, traffic volume, privacy requirements, and physical security. A tap does not automatically analyze the copied traffic; monitoring or analysis tools are still required to interpret the information and identify suspicious behavior.<\/span><\/p>\n<h3><b>Question 236<\/b><\/h3>\n<p><b>What is ingress filtering intended to restrict?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unauthorized or invalid traffic entering a network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The number of employees entering a building<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The frequency of backup restoration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The storage duration of audit records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Ingress filtering controls traffic entering a network or system and can restrict packets that do not meet defined source, destination, protocol, or policy requirements. Proper filtering can reduce exposure to unauthorized connections and certain spoofing or malicious traffic patterns. Rules should reflect legitimate communication requirements and should be reviewed as the environment changes. Ingress filtering is one layer of network defense and should operate alongside segmentation, authentication, monitoring, endpoint protection, and other controls. Filtering alone cannot determine whether an authorized connection is being used maliciously after access has been established.<\/span><\/p>\n<h3><b>Question 237<\/b><\/h3>\n<p><b>What is DNSSEC validation primarily intended to verify?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">That DNS responses have valid cryptographic authenticity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">That websites have unlimited bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">That email attachments contain no malware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">That users have selected strong passwords<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNSSEC validation allows a resolver to verify the authenticity and integrity of signed DNS information. When validation succeeds, the resolver has greater assurance that the response originated from the appropriate DNS zone and was not modified in transit. DNSSEC does not provide general confidentiality for DNS queries and does not determine whether a website itself is safe. Proper key management, signing, delegation, and resolver configuration are necessary for effective deployment. DNSSEC can help defend against certain forms of DNS manipulation, particularly attacks that attempt to provide forged DNS records to users or applications.<\/span><\/p>\n<h3><b>Question 238<\/b><\/h3>\n<p><b>What is a reverse proxy commonly positioned to do?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Receive client requests and forward them to backend services<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace all endpoint security software<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Destroy expired cryptographic keys<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Approve employee access badges<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A reverse proxy sits between clients and backend servers and receives requests on behalf of those services. It can provide functions such as traffic routing, TLS termination, access control, caching, load distribution, and security filtering depending on the implementation. Because backend systems may not need to be directly exposed to clients, a reverse proxy can also contribute to architectural separation. It should not be considered a complete security solution. Backend applications still require secure authentication, authorization, validation, patching, and monitoring. Reverse proxies are commonly used as part of layered architectures for web applications and APIs.<\/span><\/p>\n<h3><b>Question 239<\/b><\/h3>\n<p><b>Why is a jump server used in some administrative environments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide a controlled intermediary for privileged access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase the physical size of a data center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To store customer marketing preferences<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To eliminate authentication requirements<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A jump server provides an intermediary point through which administrators can access protected systems. Instead of allowing direct administrative connections from numerous user devices, organizations can require privileged sessions to pass through a controlled and monitored system. This architecture can simplify logging, restrict access paths, and reduce exposure of sensitive management interfaces. Jump servers should themselves be strongly secured, monitored, patched, and limited to necessary services. They work particularly well with multifactor authentication, privileged access controls, session recording, and network segmentation. A jump server does not remove the need to authenticate or authorize administrative users.<\/span><\/p>\n<h3><b>Question 240<\/b><\/h3>\n<p><b>What is egress monitoring particularly useful for detecting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unauthorized outbound communication or possible data transfer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical damage to server racks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incorrect employee job titles<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Expired building access cards<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Egress monitoring examines outbound network activity to identify unusual or unauthorized communication leaving an environment. Security teams may look for unexpected destinations, abnormal transfer volumes, unusual protocols, or connections associated with suspicious infrastructure. Such monitoring can help identify command-and-control activity, data exfiltration, malware communication, or compromised accounts. Effective monitoring requires knowledge of legitimate business traffic so normal services are not incorrectly treated as threats. Outbound visibility is valuable because attackers who compromise internal systems may attempt to communicate externally after gaining access. Combining egress monitoring with endpoint and identity telemetry can provide stronger investigative context.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cyber AB CCP Exam Dumps and Practice Test Dumps &nbsp; Question 221 What is the main purpose of a security baseline? Define an approved minimum security configuration Estimate annual software revenue Track employee attendance Measure office occupancy Correct Answer: 1 Explanation: A security baseline establishes an approved minimum configuration or security condition that [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17296"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17296"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17296\/revisions"}],"predecessor-version":[{"id":17297,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17296\/revisions\/17297"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17296"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17296"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17296"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}