{"id":17312,"date":"2026-09-21T07:38:03","date_gmt":"2026-09-21T07:38:03","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17312"},"modified":"2026-09-21T07:38:03","modified_gmt":"2026-09-21T07:38:03","slug":"cyber-ab-ccp-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cyber-ab-ccp-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Cyber AB CCP Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ccp-exam-dumps\"><b>Cyber AB CCP Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 381<\/b><\/h3>\n<p><b>What is the main purpose of security control mapping?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To connect controls with applicable requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To assign passwords to every employee<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase network bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace asset inventories<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security control mapping connects organizational controls with applicable requirements, frameworks, policies, or other obligations. This helps organizations determine which safeguards address particular requirements and can reduce duplicated assessment work. A control may support several requirements, while one requirement may require multiple controls. Mapping also helps identify areas where no suitable control exists, allowing gaps to be evaluated and addressed. Password administration, bandwidth management, and asset inventory are separate security activities. Effective control mapping should remain current when regulations, standards, systems, or organizational processes change. It can also make compliance evidence easier to organize because control activities are linked to specific requirements.<\/span><\/p>\n<h3><b>Question 382<\/b><\/h3>\n<p><b>Which activity best demonstrates regulatory mapping?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Selecting a new antivirus vendor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Linking legal obligations to relevant organizational controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replacing outdated monitors<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increasing wireless coverage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Regulatory mapping involves connecting applicable legal or regulatory obligations to organizational processes and controls. This allows an organization to understand how requirements are addressed and where additional safeguards or evidence may be necessary. Mapping can support compliance assessments, control reviews, audit preparation, and remediation planning. Selecting security products, replacing hardware, or improving wireless coverage may support security operations but do not themselves constitute regulatory mapping. Organizations should identify the relevant requirements, determine which controls address them, document evidence, and periodically review the mapping for changes. This approach helps prevent compliance activities from becoming disconnected from actual operational security practices.<\/span><\/p>\n<h3><b>Question 383<\/b><\/h3>\n<p><b>What is a compliance attestation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A network device configuration file<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A vulnerability scanning technique<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A formal statement that specified requirements or controls have been met<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A method for encrypting removable media<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A compliance attestation is a formal statement or declaration that specified requirements, controls, or conditions have been satisfied based on an applicable assessment or assurance process. The exact meaning depends on the governing framework or program. An attestation may require supporting evidence and may be provided by an organization or an authorized independent party. It is different from a network configuration, vulnerability scan, or encryption mechanism. Organizations should understand what was actually assessed, the scope and time period covered, and any limitations associated with an attestation. An attestation should not automatically be interpreted as proof that every aspect of an organization&#8217;s security environment is risk-free.<\/span><\/p>\n<h3><b>Question 384<\/b><\/h3>\n<p><b>Why is evidence management important during a security assessment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It guarantees that every vulnerability is fixed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It helps organize and preserve material supporting control conclusions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It eliminates the need for security policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It prevents all future audit requests<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Evidence management helps organizations collect, organize, protect, and retrieve material used to demonstrate that controls operate as required. Useful evidence may include system records, approval records, configuration information, review results, logs, or other documented artifacts. Proper evidence handling supports efficient assessments and makes conclusions easier to substantiate. Evidence management does not guarantee vulnerability remediation or eliminate future audits. Organizations should define evidence ownership, retention periods, access restrictions, and handling procedures. Evidence should also be sufficiently relevant and reliable for the conclusion being supported. A structured approach reduces the likelihood of missing documentation when auditors, assessors, or internal reviewers request proof of control operation.<\/span><\/p>\n<h3><b>Question 385<\/b><\/h3>\n<p><b>Which practice can reduce risks from tailgating?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Requiring each individual to authenticate independently at secure entrances<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling all visitor procedures<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allowing unrestricted door sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publishing employee badge numbers publicly<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Requiring each person to authenticate independently at a secured entrance makes it more difficult for an unauthorized individual to enter by simply following an authorized employee. This approach can be supported by badge readers, turnstiles, mantraps, security personnel, or other physical controls. Visitor procedures and employee awareness can provide additional protection. Disabling visitor controls or allowing unrestricted door sharing would increase exposure. Publishing badge numbers could also create unnecessary security risk. Physical access controls should be designed around the sensitivity of the protected area and should be periodically reviewed to ensure that they continue to support organizational security requirements.<\/span><\/p>\n<h3><b>Question 386<\/b><\/h3>\n<p><b>Which wireless attack attempts to impersonate a trusted access point?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC flooding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Evil twin<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP exhaustion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An evil twin attack uses a fraudulent wireless access point that imitates a legitimate network. The attacker may use a familiar network identifier to encourage users to connect to the malicious infrastructure. Once connected, the attacker may attempt to observe traffic, capture information, or redirect users depending on the surrounding controls. MAC flooding targets switch behavior, port scanning identifies network services, and DHCP exhaustion attempts to consume address resources. Organizations can reduce wireless impersonation risks through secure authentication, certificate validation, wireless monitoring, user awareness, and careful configuration of authorized access points. Users should also be cautious when connecting to networks with familiar names in unfamiliar locations.<\/span><\/p>\n<h3><b>Question 387<\/b><\/h3>\n<p><b>What does NAC primarily help an organization enforce?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical document retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network access based on device or user conditions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database backup schedules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Software licensing costs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Access Control, or NAC, helps organizations determine whether users or devices should receive network access based on defined conditions. These conditions may include identity, device posture, authentication status, security configuration, or other organizational requirements. NAC can therefore help prevent unmanaged or noncompliant devices from gaining unrestricted access to protected network resources. Document retention, database backups, and software licensing address different operational concerns. NAC can be integrated with authentication systems, endpoint-management platforms, and network infrastructure. Its effectiveness depends on accurate policy definitions and reliable information about connected devices. Proper deployment can improve visibility and reduce exposure from unauthorized or poorly secured endpoints.<\/span><\/p>\n<h3><b>Question 388<\/b><\/h3>\n<p><b>What is the primary security purpose of a host-based firewall?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To filter network connections at an individual endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To manage employee payroll<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To create physical backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To issue digital certificates<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A host-based firewall runs on an individual endpoint and controls network connections according to configured rules. It can restrict inbound or outbound traffic based on factors such as ports, protocols, addresses, applications, or connection profiles. Because the control operates directly on the host, it can provide protection even when the device is outside the organization&#8217;s traditional network perimeter. Host firewalls do not manage payroll, create physical backups, or issue certificates. Organizations should configure them according to security requirements and monitor policy changes. Host-based filtering is most effective when combined with other endpoint, identity, network, and application security controls.<\/span><\/p>\n<h3><b>Question 389<\/b><\/h3>\n<p><b>What does application control primarily restrict?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Which approved software is allowed to execute<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Which employees may enter the building<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Which databases require backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Which cables connect network switches<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application control restricts software execution according to organizational policy. Depending on the implementation, it may allow approved applications while blocking unknown, unauthorized, or prohibited programs. This can reduce the opportunity for malicious or unapproved software to execute on protected systems. Application control differs from physical access controls, backup procedures, and network cabling management. Organizations should maintain an accurate understanding of approved software and establish processes for legitimate exceptions. Application-control policies require maintenance because software environments change over time. When combined with endpoint monitoring and appropriate administrative restrictions, application control can provide an additional layer against unauthorized code execution.<\/span><\/p>\n<h3><b>Question 390<\/b><\/h3>\n<p><b>What is the purpose of secure boot measurements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To record information about trusted components involved in startup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase internet connection speed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To delete unused applications<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To manage employee identities<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure boot measurements provide information about components involved in the system startup process and can support verification of platform integrity. Trusted hardware mechanisms may record measurements of firmware, boot components, or other elements so that their expected state can be evaluated. This differs from simply increasing network performance or managing user identities. Integrity measurements can help detect unexpected changes to the startup environment and support stronger device trust decisions. Organizations should understand how their platform implements measurement, where the information is stored, and how verification occurs. Such mechanisms are most valuable when integrated into a broader endpoint-security architecture.<\/span><\/p>\n<h3><b>Question 391<\/b><\/h3>\n<p><b>What does a certificate revocation list (CRL) provide?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A list of certificates that should no longer be trusted<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A catalog of authorized software licenses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A record of employee vacation dates<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A schedule for database maintenance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Certificate Revocation List is a published list of digital certificates that a certificate authority has revoked before their normal expiration. Systems that rely on certificate trust can use revocation information when determining whether a certificate should still be accepted. Certificates may be revoked because of key compromise, incorrect issuance, changes in authorization, or other security reasons. A CRL is different from a software-license catalog or operational schedule. Organizations using certificate-based authentication should understand how revocation information is distributed, refreshed, and checked. Appropriate certificate lifecycle management helps reduce the risk of continuing to trust credentials that should no longer be considered valid.<\/span><\/p>\n<h3><b>Question 392<\/b><\/h3>\n<p><b>What is a certificate authority responsible for in a PKI?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Issuing and managing trusted digital certificates<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Filtering physical mail<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assigning network VLAN numbers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performing database compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Certificate Authority, or CA, is a trusted entity within a Public Key Infrastructure that issues and manages digital certificates according to defined policies and procedures. The CA validates required information before issuing certificates and can also support lifecycle functions such as renewal and revocation. Certificates help establish cryptographic identities for systems, services, or users. VLAN assignment, physical mail handling, and database compression are unrelated functions. The security of a PKI depends heavily on protecting the CA, controlling certificate issuance, safeguarding private keys, and maintaining accurate trust relationships. Compromise of a trusted CA can have significant consequences because relying systems may accept certificates issued by that authority.<\/span><\/p>\n<h3><b>Question 393<\/b><\/h3>\n<p><b>Why is symmetric encryption generally efficient for large amounts of data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It uses separate keys for every byte<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It eliminates the need for cryptographic keys<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It typically requires less computational overhead than asymmetric encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It can only protect public information<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Symmetric encryption typically uses the same secret key for encryption and decryption and is generally computationally efficient for processing large volumes of data. This efficiency makes symmetric algorithms suitable for bulk data protection in many systems. Asymmetric cryptography, by contrast, generally involves greater computational overhead and is often used for functions such as key establishment or digital signatures. Symmetric encryption still requires secure key management because anyone possessing the relevant secret key may be able to decrypt protected information. It does not eliminate the need for keys or restrict protection to public information. Secure systems often combine symmetric and asymmetric cryptographic techniques for different purposes.<\/span><\/p>\n<h3><b>Question 394<\/b><\/h3>\n<p><b>What is a nonce used for in cryptographic protocols?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide a value intended for one-time or limited reuse<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To permanently store user passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace all encryption keys<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To identify physical security guards<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A nonce is a value intended to be used in a particular cryptographic operation, often only once or within a narrowly defined context. Its purpose can include helping prevent replay or ensuring that otherwise similar cryptographic operations produce distinct results. The exact requirements depend on the protocol and algorithm because improper nonce reuse can weaken certain cryptographic constructions. A nonce is not a replacement for encryption keys and does not function as a password database or physical identification mechanism. Developers and security professionals should understand the specific uniqueness requirements of the cryptographic system being used rather than assuming that every nonce has identical properties.<\/span><\/p>\n<h3><b>Question 395<\/b><\/h3>\n<p><b>What is a secrets vault designed to protect?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sensitive credentials and machine-access secrets<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public marketing materials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office furniture inventories<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network cable lengths<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A secrets vault is designed to securely store and manage sensitive information such as passwords, API credentials, tokens, private keys, and other machine-access secrets. Centralized secret management can reduce the need to place credentials directly in source code, configuration files, scripts, or other locations where they may be exposed. A vault can also support controlled access, auditing, rotation, and lifecycle management depending on the implementation. Public documents and physical inventory information generally do not require the same type of secret-management infrastructure. Organizations should carefully define who or what may retrieve secrets and should monitor access to sensitive credential stores.<\/span><\/p>\n<h3><b>Question 396<\/b><\/h3>\n<p><b>What does API key management primarily address?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure issuance, storage, rotation, and use of API credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical destruction of hard drives<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Temperature monitoring in server rooms<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee attendance tracking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">API key management addresses the lifecycle and protection of credentials used by applications or services to access APIs. Effective management may include controlled issuance, secure storage, expiration or rotation, access restrictions, monitoring, and revocation when keys are no longer required. Poorly managed API keys can be exposed through source code, logs, configuration files, or repositories and may provide unauthorized access if misused. Physical media destruction, environmental monitoring, and attendance tracking address unrelated concerns. Organizations should treat API keys as sensitive credentials and avoid embedding them unnecessarily in publicly accessible code or other locations where unauthorized parties could obtain them.<\/span><\/p>\n<h3><b>Question 397<\/b><\/h3>\n<p><b>What security benefit can OAuth scopes provide?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They limit what an issued authorization token is permitted to access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They guarantee that users choose strong passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They physically isolate application servers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They prevent every phishing attempt<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">OAuth scopes allow an authorization system to define the permissions associated with an issued token. Instead of granting unrestricted access, a token can be limited to specific resources or operations supported by the application. This supports the principle of limiting authorization to what is required. Scopes do not guarantee strong passwords, physically isolate servers, or prevent every phishing attack. Organizations should carefully design scopes so that applications receive only the permissions necessary for their intended functions. Excessively broad scopes can increase the consequences of token compromise, while appropriately restricted scopes can reduce the amount of access available to an attacker using a stolen authorization credential.<\/span><\/p>\n<h3><b>Question 398<\/b><\/h3>\n<p><b>What does CORS primarily control for web applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Which origins may make certain cross-origin requests<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">How physical badges are printed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">When backup tapes are destroyed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Which employees receive laptops<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cross-Origin Resource Sharing, or CORS, provides a mechanism through which web applications can specify which origins are permitted to make certain cross-origin requests. Proper configuration can help prevent unintended browser-based access to resources from unauthorized origins. CORS is not a general replacement for authentication or authorization, and incorrect configurations can expose resources more broadly than intended. Physical badge production, backup destruction, and laptop assignment are unrelated functions. Security teams should understand which origins, methods, headers, and credentials are permitted and should avoid overly permissive configurations when sensitive resources are involved.<\/span><\/p>\n<h3><b>Question 399<\/b><\/h3>\n<p><b>What is a Content Security Policy (CSP) primarily intended to help mitigate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certain browser-based content injection risks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical theft of servers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Failure of backup generators<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unauthorized building entry<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Content Security Policy is a browser-enforced security mechanism that allows websites to define which sources of content and scripts browsers should trust. A carefully designed CSP can reduce the impact of certain content-injection attacks by restricting where executable resources may originate or how content can be loaded. CSP does not physically protect servers, provide electrical backup, or control building access. Its effectiveness depends on accurate policy design and deployment because overly permissive directives may provide limited protection. CSP should complement secure development practices such as output handling, input validation, authentication controls, and vulnerability testing rather than serve as the sole defense against web attacks.<\/span><\/p>\n<h3><b>Question 400<\/b><\/h3>\n<p><b>Which practice best supports secure webhook design?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authenticating webhook requests and validating their integrity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accepting every incoming request without verification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publishing secret signing keys in documentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling all request logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Webhooks allow one system to send event-driven requests to another system, so receiving applications should verify that incoming requests originate from an expected source and have not been altered. Authentication mechanisms, request signatures, timestamp checks, replay protections, and appropriate authorization controls can help strengthen webhook security. Accepting every request without verification creates unnecessary exposure, while publishing signing secrets defeats their protective purpose. Disabling logging can also make suspicious webhook activity harder to investigate. Webhook endpoints should be treated as externally reachable interfaces when appropriate and should receive the same careful security design, validation, monitoring, and credential-management practices applied to other application interfaces.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cyber AB CCP Exam Dumps and Practice Test Dumps &nbsp; Question 381 What is the main purpose of security control mapping? To connect controls with applicable requirements To assign passwords to every employee To increase network bandwidth To replace asset inventories Correct Answer: 1 Explanation: Security control mapping connects organizational controls with applicable [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17312"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17312"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17312\/revisions"}],"predecessor-version":[{"id":17313,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17312\/revisions\/17313"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17312"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17312"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17312"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}