{"id":17298,"date":"2026-09-21T07:36:04","date_gmt":"2026-09-21T07:36:04","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17298"},"modified":"2026-09-21T07:36:04","modified_gmt":"2026-09-21T07:36:04","slug":"cyber-ab-ccp-practice-test-questions-and-exam-dumps-part13-q241-260","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cyber-ab-ccp-practice-test-questions-and-exam-dumps-part13-q241-260\/","title":{"rendered":"Cyber AB CCP Practice Test Questions and Exam Dumps Part13 Q241-260"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ccp-exam-dumps\"><b>Cyber AB CCP Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 241<\/b><\/h3>\n<p><b>What is the main purpose of a control self-assessment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow control owners to evaluate their own control environment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace every independent security audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Calculate equipment depreciation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Approve employee promotions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A control self-assessment allows personnel responsible for business or security processes to evaluate whether controls are appropriately designed and operating as expected. It can help identify weaknesses, documentation issues, process deviations, and areas requiring remediation before an independent assessment occurs. Self-assessments are valuable because control owners have direct knowledge of how processes operate in practice. However, they should not automatically replace independent testing because self-assessment can involve limited objectivity. Organizations may use structured questionnaires, evidence reviews, interviews, or sampling to perform these assessments. Results can then feed into corrective action and broader security improvement activities.<\/span><\/p>\n<h3><b>Question 242<\/b><\/h3>\n<p><b>Why is separation of duties important when approving security exceptions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It guarantees that exceptions never expire<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It reduces the chance that one person can approve and conceal an inappropriate exception<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It eliminates the need for documentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It prevents all policy changes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties divides sensitive responsibilities among different individuals or roles so that one person does not have excessive control over an important process. For security exceptions, separating the request, review, and approval responsibilities can reduce the opportunity for inappropriate exceptions to be granted without scrutiny. The exact arrangement depends on organizational size and risk. Smaller organizations may use compensating oversight when complete separation is impractical. Separation of duties does not remove the need for documentation, expiration dates, or periodic review. Instead, it adds an accountability mechanism that makes sensitive decisions more difficult to manipulate without detection.<\/span><\/p>\n<h3><b>Question 243<\/b><\/h3>\n<p><b>What is a preventive control designed to do?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Stop or reduce the likelihood of an unwanted event before it occurs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Record evidence after a security incident<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restore systems following a disaster<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Calculate annual security spending<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Preventive controls are designed to stop an unwanted event or reduce its likelihood before it occurs. Examples include access restrictions, secure configuration requirements, network segmentation, authentication mechanisms, and application allowlisting. Preventive controls differ from detective controls, which identify events or conditions after or while they occur, and corrective controls, which address problems after identification. No preventive control is guaranteed to stop every threat, so organizations typically use multiple layers of protection. Their effectiveness should also be tested periodically because changes in technology, user behavior, and attack methods can reduce the protection originally expected.<\/span><\/p>\n<h3><b>Question 244<\/b><\/h3>\n<p><b>What is a detective control primarily intended to accomplish?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Prevent users from accessing every external website<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identify suspicious or unauthorized activity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restore deleted information automatically<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Establish annual procurement budgets<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detective controls are intended to identify suspicious events, unauthorized activity, or deviations from expected conditions. Examples include security monitoring, intrusion detection, audit-log review, file integrity monitoring, and alerting mechanisms. Detective controls are particularly important because preventive measures may fail or be bypassed. Once suspicious activity is identified, organizations can initiate investigation, containment, and corrective actions. Effective detective controls depend on appropriate data sources, meaningful detection logic, and timely response. Simply collecting large amounts of information does not guarantee effective detection. Monitoring should focus on events that are relevant to the organization&#8217;s risks and security objectives.<\/span><\/p>\n<h3><b>Question 245<\/b><\/h3>\n<p><b>Why is control evidence retained during an audit?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To demonstrate that required controls were implemented or operated<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase the number of security policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace employee background checks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To eliminate all audit findings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control evidence provides objective support for determining whether a control exists, was implemented, or operated during a relevant period. Evidence may include system records, approval records, configuration outputs, review logs, tickets, reports, or other documented information. Auditors use appropriate evidence to support their conclusions rather than relying solely on verbal claims. The quality and relevance of evidence matter because incomplete or unreliable records may not adequately demonstrate control operation. Evidence should also be protected from unauthorized alteration and retained according to applicable requirements. Maintaining organized evidence can make assessments more efficient and improve accountability for control owners.<\/span><\/p>\n<h3><b>Question 246<\/b><\/h3>\n<p><b>What is audit sampling used to accomplish?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Review every transaction without exception<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Select representative items for testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove the need for audit evidence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Approve security policies automatically<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Audit sampling involves selecting a subset of items from a larger population for testing. Instead of examining every transaction, access record, or control instance, an auditor can use an appropriate sampling method to obtain evidence about the broader population. The sample should be selected using a defensible methodology that considers factors such as population size, risk, expected error rates, and required confidence. Poor sampling can produce misleading conclusions if the selected items are not representative. Sampling does not eliminate evidence requirements; the selected items still need to be examined and documented appropriately.<\/span><\/p>\n<h3><b>Question 247<\/b><\/h3>\n<p><b>What is an audit trail primarily intended to provide?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A chronological record of relevant activities or transactions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A list of future software purchases<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A replacement for access controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A schedule of employee holidays<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An audit trail records activities or transactions in a way that supports later review and investigation. Depending on the environment, it may capture user actions, system changes, approvals, transactions, or access events. Audit trails can help establish what happened, when it happened, and sometimes which account or system performed the action. Their usefulness depends on accurate timestamps, appropriate event coverage, protection against unauthorized alteration, and suitable retention. Audit trails support accountability and investigations but should not be confused with preventive controls. Organizations should determine which activities require logging based on security, operational, legal, and compliance requirements.<\/span><\/p>\n<h3><b>Question 248<\/b><\/h3>\n<p><b>What is log normalization intended to improve?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The physical storage capacity of a server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The consistency of data formats across log sources<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The strength of user passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The speed of software compilation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Log normalization converts information from different log sources into a more consistent structure or format. Different applications, operating systems, and security devices may record similar events using different field names, timestamp formats, or representations. Normalization makes it easier for monitoring platforms to correlate and analyze events across those sources. For example, user identity, source address, destination, event type, and timestamp can be represented consistently. Normalization does not itself determine whether an event is malicious. Instead, it improves the ability of security tools and analysts to process information consistently and build useful detection or correlation rules.<\/span><\/p>\n<h3><b>Question 249<\/b><\/h3>\n<p><b>Why should audit logs be protected from unauthorized modification?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Altered logs can undermine their reliability as evidence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Modified logs always improve system performance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unprotected logs eliminate network latency<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Changing logs automatically fixes security incidents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Audit logs are valuable for accountability, investigation, troubleshooting, and compliance, so their integrity must be protected. If unauthorized individuals can modify or delete records, important evidence may be concealed or misleading information may be introduced. Organizations can protect logs through access restrictions, centralized collection, integrity controls, write-protected storage, appropriate retention, and monitoring of administrative activity. Time synchronization also improves the usefulness of records from multiple systems. Log protection should cover both the collection process and the storage environment. Reliable logs can provide important evidence when reconstructing events or determining whether security controls operated as expected.<\/span><\/p>\n<h3><b>Question 250<\/b><\/h3>\n<p><b>What is alert fatigue in a security operations environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduced analyst effectiveness caused by excessive or low-value alerts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A hardware failure caused by excessive cooling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A method for encrypting monitoring data<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A procedure for restoring archived files<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Alert fatigue occurs when security personnel receive so many alerts, particularly low-value or repetitive ones, that distinguishing genuinely important events becomes difficult. Excessive alerts can consume analyst attention and increase the risk that a serious event is overlooked. Organizations can reduce alert fatigue by tuning detection rules, prioritizing alerts using risk context, removing unnecessary notifications, improving correlation, and regularly reviewing detection performance. The goal is not simply to reduce the number of alerts but to improve their usefulness. Effective alert management combines technology with clear triage procedures and escalation criteria.<\/span><\/p>\n<h3><b>Question 251<\/b><\/h3>\n<p><b>What is an escalation matrix used for during incident handling?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Define who should be notified or involved at different severity levels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Determine the encryption algorithm for backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign permanent workstation locations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace the organization&#8217;s asset inventory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An escalation matrix defines which individuals, teams, managers, or specialized functions should become involved when an incident reaches particular severity or impact levels. It can identify technical contacts, management authorities, legal personnel, privacy teams, communications staff, or external parties where appropriate. A clear matrix reduces uncertainty during high-pressure situations and helps ensure that significant incidents receive timely attention. Escalation criteria should be based on factors such as business impact, affected information, scope, regulatory considerations, and operational disruption. The matrix should be reviewed periodically because organizational roles and contact information can change.<\/span><\/p>\n<h3><b>Question 252<\/b><\/h3>\n<p><b>What should an incident communication plan establish?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Approved communication channels, responsibilities, and notification procedures<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The maximum size of email attachments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A list of employee performance ratings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The physical dimensions of the security office<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An incident communication plan establishes how information will be communicated during and after a security incident. It can identify authorized communicators, internal and external audiences, approved channels, notification requirements, escalation paths, and procedures for handling sensitive information. Clear communication helps prevent contradictory messages and ensures that relevant stakeholders receive appropriate information. Plans should account for situations in which normal communication systems are unavailable or compromised. Communication responsibilities should also be tested during exercises so participants understand their roles. The plan should complement technical incident response procedures rather than attempt to replace containment, investigation, or recovery activities.<\/span><\/p>\n<h3><b>Question 253<\/b><\/h3>\n<p><b>What is a warm site in disaster recovery?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A partially prepared alternate facility requiring some additional setup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A completely inactive location with no equipment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A fully operational duplicate used without preparation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A secure archive for paper documents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A warm site is an alternate recovery facility that has some infrastructure and equipment prepared but may require additional configuration, data restoration, or other work before normal operations can resume. It generally provides a balance between recovery speed and cost compared with other alternate-site approaches. A hot site is typically more immediately operational, while a cold site generally requires more extensive preparation. Organizations select recovery-site strategies according to business impact, recovery objectives, budget, and operational requirements. A warm site&#8217;s effectiveness depends on keeping equipment, connectivity, procedures, and recovery information sufficiently current.<\/span><\/p>\n<h3><b>Question 254<\/b><\/h3>\n<p><b>What does geographic redundancy provide?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A method for assigning user permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Additional resilience by maintaining resources in separate locations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A replacement for vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A technique for compressing log files<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Geographic redundancy places systems, services, data, or infrastructure in separate physical locations so that a localized disruption does not necessarily affect all copies simultaneously. Separation can help reduce exposure to events such as regional power failures, natural disasters, major network outages, or facility incidents. The appropriate degree of geographic separation depends on business requirements and threat scenarios. Redundant locations must also be considered from a security, synchronization, dependency, and recovery perspective. Simply having multiple copies in the same geographic area may not provide meaningful protection against a regional event.<\/span><\/p>\n<h3><b>Question 255<\/b><\/h3>\n<p><b>Why are recovery runbooks useful?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They provide documented steps for performing recovery activities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They eliminate the need to test recovery procedures<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They replace all backup technologies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They guarantee that every recovery will succeed<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery runbooks provide documented, ordered instructions for restoring systems or services after a disruption. They can identify prerequisites, responsible roles, dependencies, commands, validation steps, and escalation points. Detailed runbooks reduce reliance on individual memory during stressful recovery situations and can help teams perform activities consistently. However, documentation can become inaccurate if systems change, so runbooks should be reviewed and exercised periodically. Testing can reveal missing steps, outdated dependencies, or unclear responsibilities. A runbook supports recovery but does not replace backups, redundancy, trained personnel, or appropriate continuity planning.<\/span><\/p>\n<h3><b>Question 256<\/b><\/h3>\n<p><b>What is replication primarily used to accomplish in a resilient architecture?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Create additional copies of data or services across systems<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restrict users from accessing applications<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detect phishing messages<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace physical security controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Replication creates additional copies of data, services, or system state across different systems or locations. It can support availability, disaster recovery, and continuity by allowing operations to continue or be restored when a primary resource becomes unavailable. Replication methods vary in timing and architecture, including synchronous and asynchronous approaches. Organizations must consider consistency, network dependencies, security, and recovery requirements when designing replication. Replication is not the same as a complete backup strategy because replicated changes, including accidental deletion or corruption, may also propagate. Appropriate recovery points and independent recovery mechanisms remain important.<\/span><\/p>\n<h3><b>Question 257<\/b><\/h3>\n<p><b>What is a snapshot commonly used for?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Capture the state of a system or data set at a particular point in time<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Approve new employee accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authenticate wireless devices<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitor physical temperature sensors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A snapshot captures the state of a system, volume, virtual machine, or data set at a particular point in time. Snapshots can support rapid rollback, testing, recovery from certain changes, and operational troubleshooting. However, snapshot implementations vary, and many depend on the underlying storage system or infrastructure. A snapshot should not automatically be considered an independent backup because it may remain within the same failure domain as the original data. Organizations should evaluate whether snapshots meet their recovery requirements and maintain separate backup mechanisms when necessary. Security controls should also protect snapshots because they may contain sensitive information.<\/span><\/p>\n<h3><b>Question 258<\/b><\/h3>\n<p><b>What is a business continuity plan primarily concerned with?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maintaining or restoring critical business functions during disruption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuring individual employee laptops<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ranking software vulnerabilities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Managing application source-code branches<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A business continuity plan focuses on maintaining or restoring critical business functions when disruptive events affect normal operations. It considers essential processes, dependencies, personnel, facilities, technology, communications, and alternative operating arrangements. Business continuity is broader than technical disaster recovery because many disruptions involve people, suppliers, facilities, or business processes rather than technology alone. Plans should identify priorities and responsibilities and should be exercised periodically. Testing can reveal unrealistic assumptions or missing dependencies. A continuity plan should also be updated when important business processes, organizational structures, technology platforms, or external dependencies change.<\/span><\/p>\n<h3><b>Question 259<\/b><\/h3>\n<p><b>What is the primary focus of disaster recovery planning?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restoring technology and services after a disruptive event<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Designing employee compensation packages<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Selecting office furniture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Creating product advertising campaigns<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Disaster recovery planning focuses on restoring technology, systems, applications, and supporting services after a disruptive event. It typically addresses recovery priorities, dependencies, backup resources, recovery procedures, responsibilities, communication, and validation. Disaster recovery is closely related to business continuity but generally emphasizes restoration of technology and operational capabilities. Recovery plans should reflect defined recovery objectives and business priorities. Regular testing is essential because procedures that appear correct on paper may fail when dependencies, credentials, configurations, or contact information have changed. Lessons from exercises and real incidents should be incorporated into subsequent revisions.<\/span><\/p>\n<h3><b>Question 260<\/b><\/h3>\n<p><b>What is a recovery validation step intended to confirm?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">That restored systems are functioning correctly and securely<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">That every employee has changed jobs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">That all archived files have been deleted<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">That physical office space has increased<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery validation confirms that restored systems or services are actually functioning as required after recovery activities. Validation may include checking application availability, data integrity, authentication, network connectivity, security controls, configuration settings, and business functionality. Simply bringing a server online does not prove that the service has been successfully recovered. Validation should therefore involve appropriate technical and business stakeholders who can confirm that critical functions operate correctly. Any discovered problems should be documented and addressed before the recovery is considered complete. These checks help prevent organizations from declaring recovery successful while important dependencies or security controls remain impaired.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cyber AB CCP Exam Dumps and Practice Test Dumps &nbsp; Question 241 What is the main purpose of a control self-assessment? Allow control owners to evaluate their own control environment Replace every independent security audit Calculate equipment depreciation Approve employee promotions Correct Answer: 1 Explanation: A control self-assessment allows personnel responsible for business [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17298"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17298"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17298\/revisions"}],"predecessor-version":[{"id":17299,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17298\/revisions\/17299"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17298"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17298"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17298"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}