CCP CCP IT Governance, Risk & Compliance 1 — Questions and Answers
Question 1: COBIT is best described as:
- A framework for IT governance and management aligned with business objectives (Correct answer)
- A programming language for enterprise applications
- A network security standard
- A database normalization methodology
Correct answer: A framework for IT governance and management aligned with business objectives
COBIT (Control Objectives for Information and Related Technologies) is an IT governance framework that helps organizations align IT strategy with business goals.
Question 2: Which risk management strategy involves transferring risk to a third party, such as an insurance provider?
- Risk transfer (Correct answer)
- Risk avoidance
- Risk mitigation
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts the financial impact of a risk to another party, typically through insurance or outsourcing, without eliminating the underlying risk.
Question 3: The ITIL framework is primarily focused on:
- IT service management best practices (Correct answer)
- Network infrastructure design
- Software development lifecycle
- Data warehouse architecture
Correct answer: IT service management best practices
ITIL (Information Technology Infrastructure Library) provides a set of best practices for delivering and managing IT services aligned with business needs.
Question 4: In risk assessment, the formula Risk = Threat × Vulnerability × Impact is used to:
- Quantify the level of risk associated with an asset (Correct answer)
- Calculate the cost of implementing controls
- Determine backup frequency requirements
- Schedule penetration testing intervals
Correct answer: Quantify the level of risk associated with an asset
This formula combines the likelihood of a threat exploiting a vulnerability with the resulting business impact to produce a risk score for prioritization.
Question 5: What is the purpose of a Service Level Agreement (SLA)?
- To formally define the expected level of service between a provider and customer (Correct answer)
- To document hardware specifications for procurement
- To outline employee performance expectations
- To describe software licensing terms
Correct answer: To formally define the expected level of service between a provider and customer
An SLA is a contract that specifies measurable service standards such as uptime, response times, and support quality that a provider must meet.
Question 6: Separation of duties (SoD) is an internal control that:
- Requires multiple individuals to complete sensitive tasks to prevent fraud (Correct answer)
- Physically separates IT infrastructure across geographic zones
- Divides network traffic across multiple switches
- Segments user data by department
Correct answer: Requires multiple individuals to complete sensitive tasks to prevent fraud
Separation of duties ensures no single person can execute a complete sensitive transaction alone, reducing the risk of fraud, errors, and unauthorized access.
COBIT is best described as: