โ† All CCP Flashcard Decks

Cybersecurity Principles & Risk Management Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cybersecurity Principles & Risk Management flashcards as text
  1. Which risk treatment option involves transferring the financial impact of a risk to a third party?

    Answer: Risk transference

    Risk transference shifts the financial burden of a risk to another party, such as an insurance provider or outsourced vendor.

  2. What is the PRIMARY purpose of a Business Impact Analysis (BIA)?

    Answer: Determine the criticality of business functions and recovery priorities

    A BIA identifies critical business processes, quantifies the impact of disruptions, and establishes Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).

  3. An organization wants to ensure that no single employee can complete a high-risk transaction alone. Which principle does this implement?

    Answer: Separation of duties

    Separation of duties requires multiple individuals to complete a sensitive task, reducing the risk of fraud or error by any one person.

  4. In the NIST Cybersecurity Framework, which function focuses on developing and implementing appropriate safeguards to ensure delivery of critical services?

    Answer: Protect

    The Protect function encompasses safeguards such as access control, awareness training, data security, and protective technology to limit the impact of cybersecurity events.

  5. What term describes a weakness in a system that can be exploited by a threat actor?

    Answer: Vulnerability

    A vulnerability is a flaw or weakness in a system, process, or control that could be exploited to compromise security.

  6. Which of the following BEST describes qualitative risk assessment?

    Answer: Relies on subjective ratings such as High, Medium, and Low

    Qualitative risk assessment uses descriptive scales and expert judgment rather than precise numerical values to evaluate and prioritize risks.

  7. A company decides not to launch a new internet-facing service because the associated security risks are too high. Which risk response is being applied?

    Answer: Risk avoidance

    Risk avoidance involves eliminating the risk entirely by deciding not to engage in the activity that creates it.