CCP IT Governance, Risk & Compliance Flashcards
6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CCP IT Governance, Risk & Compliance flashcards as text
COBIT is best described as:
Answer: A framework for IT governance and management aligned with business objectives
COBIT (Control Objectives for Information and Related Technologies) is an IT governance framework that helps organizations align IT strategy with business goals.
Which risk management strategy involves transferring risk to a third party, such as an insurance provider?
Answer: Risk transfer
Risk transfer shifts the financial impact of a risk to another party, typically through insurance or outsourcing, without eliminating the underlying risk.
The ITIL framework is primarily focused on:
Answer: IT service management best practices
ITIL (Information Technology Infrastructure Library) provides a set of best practices for delivering and managing IT services aligned with business needs.
In risk assessment, the formula Risk = Threat × Vulnerability × Impact is used to:
Answer: Quantify the level of risk associated with an asset
This formula combines the likelihood of a threat exploiting a vulnerability with the resulting business impact to produce a risk score for prioritization.
What is the purpose of a Service Level Agreement (SLA)?
Answer: To formally define the expected level of service between a provider and customer
An SLA is a contract that specifies measurable service standards such as uptime, response times, and support quality that a provider must meet.
Separation of duties (SoD) is an internal control that:
Answer: Requires multiple individuals to complete sensitive tasks to prevent fraud
Separation of duties ensures no single person can execute a complete sensitive transaction alone, reducing the risk of fraud, errors, and unauthorized access.