โ† All CCP Flashcard Decks

CCP IT Governance, Risk & Compliance Flashcards

6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CCP IT Governance, Risk & Compliance flashcards as text
  1. Change management in ITIL is designed to:

    Answer: Ensure changes to IT systems are assessed, approved, and implemented with minimal risk

    ITIL Change Management provides a structured process for requesting, evaluating, authorizing, and reviewing changes to reduce service disruption.

  2. A vulnerability assessment differs from a penetration test in that it:

    Answer: Identifies and classifies vulnerabilities without attempting to exploit them

    Vulnerability assessments scan and categorize security weaknesses, while penetration tests go further by actively exploiting vulnerabilities to measure real-world impact.

  3. SOX (Sarbanes-Oxley Act) IT controls primarily aim to:

    Answer: Ensure the integrity and accuracy of financial reporting systems

    SOX Section 404 requires organizations to implement and document IT controls that protect the reliability and integrity of financial reporting data.

  4. In project management, a Work Breakdown Structure (WBS) is used to:

    Answer: Decompose a project into smaller, manageable components and deliverables

    A WBS hierarchically breaks down the total project scope into smaller work packages, making planning, scheduling, and cost estimating more manageable.

  5. Which risk response strategy involves implementing controls to reduce the probability or impact of a risk?

    Answer: Risk mitigation

    Risk mitigation involves taking proactive steps such as adding controls, redundancy, or process improvements to lower a risk's likelihood or reduce its impact.

  6. A Configuration Management Database (CMDB) is used in IT governance to:

    Answer: Track and manage IT assets and their relationships and configurations

    A CMDB maintains a repository of configuration items (CIs) and their interdependencies, supporting change management, incident resolution, and compliance.