โ† All CCP Flashcard Decks

Governance, Compliance & Ethical Hacking Flashcards

9 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 9 Governance, Compliance & Ethical Hacking flashcards as text
  1. What does IT governance ensure within an organization?

    Answer: It ensures IT aligns with business goals and compliance

    IT governance is crucial for ensuring that an organization's information technology strategy and operations align with its overall business goals and regulatory compliance requirements. It establishes a framework for decision-making, accountability, and risk management related to IT. This alignment helps maximize the value of IT investments while managing associated risks and adhering to legal and ethical standards.

  2. Which regulation focuses on protecting personal health information?

    Answer: HIPAA

    HIPAA, the Health Insurance Portability and Accountability Act, is a U.S. federal law specifically designed to protect sensitive patient health information (PHI). It sets standards for the security, privacy, and integrity of medical data, requiring healthcare providers and related entities to implement robust safeguards. Compliance with HIPAA is mandatory to prevent unauthorized access, use, or disclosure of health records.

  3. What is ethical hacking?

    Answer: Testing systems for security vulnerabilities with permission

    Ethical hacking involves authorized attempts to penetrate computer systems, applications, or data to identify security vulnerabilities. Unlike malicious hacking, ethical hackers operate with explicit permission from the system owner and aim to improve security by discovering weaknesses before malicious actors can exploit them. This proactive approach helps organizations strengthen their defenses and protect sensitive information.

  4. What is the purpose of compliance audits?

    Answer: To evaluate adherence to laws and regulations

    Compliance audits are systematic evaluations conducted to determine whether an organization is adhering to specific laws, regulations, industry standards, or internal policies. Their purpose is to verify that controls are in place and operating effectively to meet these requirements. By identifying gaps or non-compliance, audits help organizations mitigate legal risks, avoid penalties, and maintain trust with stakeholders.

  5. What is a penetration test?

    Answer: An intentional attack to find security weaknesses

    A penetration test, or pen test, is a simulated cyberattack against a computer system, network, or web application to check for exploitable vulnerabilities. It is an intentional and authorized attempt to bypass security controls and gain access, mimicking the actions of a real attacker. The goal is to identify security weaknesses that could be exploited by malicious actors, allowing organizations to fix them proactively.

  6. Which role ensures that security policies are followed?

    Answer: Compliance Officer

    A Compliance Officer is responsible for ensuring that an organization adheres to all relevant external laws, regulations, and internal policies. This role involves developing, implementing, and monitoring compliance programs, conducting audits, and providing training to employees. Their primary duty is to mitigate legal and reputational risks by ensuring the organization operates within established ethical and legal boundaries.

  7. What is social engineering in cybersecurity?

    Answer: Manipulating individuals to gain sensitive data

    Social engineering in cybersecurity refers to the psychological manipulation of people into performing actions or divulging confidential information. Attackers exploit human psychology, trust, and curiosity rather than technical vulnerabilities to gain unauthorized access to systems or data. Common tactics include phishing, pretexting, and baiting, making user education a critical defense.

  8. Which standard applies to payment card data security?

    Answer: PCI DSS

    PCI DSS, the Payment Card Industry Data Security Standard, is a set of security standards designed to ensure that all companies that process, store, or transmit credit card information maintain a secure environment. Compliance is mandatory for any entity handling payment card data to protect cardholder information from theft and fraud. Adherence helps prevent data breaches and maintains consumer trust in electronic transactions.

  9. What is the goal of ethical hacking certifications?

    Answer: To certify professionals in legal vulnerability assessments

    Ethical hacking certifications are designed to validate the skills and knowledge of professionals in conducting legal and authorized vulnerability assessments and penetration tests. These certifications ensure that individuals understand ethical guidelines, methodologies, and tools for identifying security weaknesses responsibly. The goal is to equip professionals to proactively strengthen an organization's security posture, not to facilitate illegal activities.