โ† All CCP Flashcard Decks

Governance, Compliance & Ethical Hacking Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Governance, Compliance & Ethical Hacking flashcards as text
  1. Which framework provides a set of voluntary cybersecurity standards and best practices developed by NIST primarily for critical infrastructure protection?

    Answer: NIST CSF

    The NIST Cybersecurity Framework (CSF) was developed to help critical infrastructure organizations manage cybersecurity risk using five core functions: Identify, Protect, Detect, Respond, and Recover.

  2. During a penetration test, a tester discovers a zero-day vulnerability in a client's production system. What is the MOST appropriate immediate action?

    Answer: Document and immediately report it to the client's security team

    Responsible disclosure requires immediately notifying the client's security team so they can assess risk and decide on remediation, staying within the rules of engagement.

  3. Which compliance regulation specifically mandates security controls for organizations that process, store, or transmit cardholder data?

    Answer: PCI DSS

    PCI DSS (Payment Card Industry Data Security Standard) is the compliance framework specifically governing cardholder data protection for any entity that handles payment card information.

  4. A company's security policy states that all employees must complete annual security awareness training. Which governance element does this BEST represent?

    Answer: Security policy

    A security policy is a high-level document that mandates what must be done (such as annual training), while standards and procedures define how to implement those mandates.

  5. In ethical hacking, what does the term 'rules of engagement' define?

    Answer: The specific boundaries, scope, and constraints agreed upon before testing begins

    Rules of engagement formally define the scope, allowed techniques, testing windows, and communication protocols that a penetration tester must follow during an engagement.

  6. Which type of audit evaluates whether an organization's security controls meet a specific external standard such as SOC 2 or ISO 27001?

    Answer: Compliance audit

    A compliance audit assesses whether an organization's controls and processes conform to external regulatory or standards-based requirements.

  7. What is the primary purpose of a Business Impact Analysis (BIA) in a cybersecurity governance program?

    Answer: To determine the financial and operational impact of disruptions to critical business functions

    A BIA identifies critical business functions, their dependencies, and the potential impacts (financial, reputational, legal) if those functions are disrupted, informing RTO and RPO targets.