Certified CMMC Professional (CCP) β Questions and Answers
Question 1: What is an incident response plan (IRP)?
- An IRP outlines procedures for responding to security incidents to minimize damage. (Correct answer)
- An IRP is a marketing strategy.
- An IRP is only a backup plan.
- An IRP is used only for compliance reporting.
Correct answer: An IRP outlines procedures for responding to security incidents to minimize damage.
An Incident Response Plan (IRP) is a documented set of procedures and guidelines that an organization follows when a security incident occurs. It provides a structured framework for detection, analysis, containment, eradication, recovery, and post-incident activities. The IRP ensures a coordinated and effective response, minimizing disruption, damage, and recovery time during a cyberattack.
Question 2: What does Single Loss Expectancy (SLE) represent?
- The probability of a threat occurring within one year
- The expected monetary loss from one occurrence of a specific risk event (Correct answer)
- The total value of all organizational assets
- The annual cost of all security controls
Correct answer: The expected monetary loss from one occurrence of a specific risk event
SLE is the estimated dollar loss associated with a single occurrence of a given risk event.
Question 3: Which law requires US federal agencies to implement information security programs and report security incidents to Congress?
- FISMA (Correct answer)
- GLBA
- ECPA
- FERPA
Correct answer: FISMA
The Federal Information Security Modernization Act (FISMA) mandates that federal agencies develop, document, and implement information security programs.
Question 4: Which TLS component proves the server's identity to the client during the handshake process?
- Digital certificate (Correct answer)
- Cipher suite
- MAC address
- Session key
Correct answer: Digital certificate
The server presents a digital certificate signed by a trusted CA, allowing the client to verify the server's identity before establishing an encrypted session.
Question 5: A SIEM rule triggers an alert every time a user accesses more than 50 files within 5 minutes. What type of detection logic is this?
- Heuristic behavioral analysis
- Signature-based detection
- Machine learning classification
- Anomaly threshold detection (Correct answer)
Correct answer: Anomaly threshold detection
Triggering on a fixed count threshold (50 files in 5 minutes) is anomaly threshold detection, which flags activity exceeding defined limits.
Question 6: What is a data breach?
- A legal data access procedure.
- A routine data backup procedure.
- A secure data transfer process.
- An incident where unauthorized individuals access protected data. (Correct answer)
Correct answer: An incident where unauthorized individuals access protected data.
A data breach occurs when sensitive, protected, or confidential data is accessed, viewed, stolen, or used by an unauthorized individual. These incidents can expose personal information, financial details, or intellectual property, leading to significant financial, reputational, and legal consequences for individuals and organizations. It represents a critical failure in data security measures, compromising confidentiality and integrity.
Question 7: When performing a NIST-based risk assessment, which document specifically guides the risk assessment process?
- NIST SP 800-53A
- NIST SP 800-137
- NIST SP 800-30 (Correct answer)
- NIST SP 800-37
Correct answer: NIST SP 800-30
NIST SP 800-30 (Guide for Conducting Risk Assessments) provides the process for conducting risk assessments of federal information systems.
Question 8: When documenting activities related to cve assessment & patch management, which practice is considered essential for CCP certification holders?
- Keeping documentation in personal notes that are not accessible to other team members
- Maintaining comprehensive records that include procedures, observations, results, and any anomalies (Correct answer)
- Completing documentation only when requested by auditors or supervisors
- Recording only outcomes while omitting the methods and processes used
Correct answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in cve assessment & patch management. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
Question 9: Which firewall rule processing model evaluates rules from top to bottom and stops at the first match?
- Best-match processing
- First-match processing (Correct answer)
- Weighted-match processing
- Last-match processing
Correct answer: First-match processing
Most firewalls use first-match (top-down) processing, so rule order is critical β more specific rules must appear before broader ones.
Question 10: When a vendor releases a patch marked 'Defense in Depth' rather than a direct fix, it typically means:
- The vulnerability has no known exploit
- The patch only applies to non-production systems
- The patch adds mitigating controls that reduce attack surface without fully eliminating the vulnerability (Correct answer)
- The patch completely remediates the vulnerability
Correct answer: The patch adds mitigating controls that reduce attack surface without fully eliminating the vulnerability
Defense-in-depth patches add hardening measures (e.g., additional validation, ASLR improvements) that reduce exploitability without resolving the underlying root cause.
Question 11: During a ransomware incident, the IR team isolates affected hosts but discovers the malware has a kill-switch domain. What is the BEST immediate action?
- Reimage all affected hosts immediately
- Sinkhole the kill-switch domain to prevent detonation (Correct answer)
- Pay the ransom to obtain the decryption key
- Block all outbound DNS at the perimeter firewall
Correct answer: Sinkhole the kill-switch domain to prevent detonation
Sinkholing the kill-switch domain redirects C2 traffic to a controlled server, potentially halting further encryption while preserving forensic evidence.
Question 12: Which memory forensics artifact would MOST reliably reveal an injected shellcode payload that never touched disk?
- Volatile memory dump analyzed for injected executable regions (Correct answer)
- Windows Event Log (EVTX) files
- MFT (Master File Table) records
- Prefetch files in C:\Windows\Prefetch
Correct answer: Volatile memory dump analyzed for injected executable regions
Fileless malware exists only in memory; a RAM dump analyzed with tools like Volatility can reveal injected code in process address spaces that leave no disk artifacts.
Question 13: What distinguishes a Host-based Intrusion Prevention System (HIPS) from a HIDS?
- HIPS uses signature detection while HIDS uses behavioral analysis
- HIPS actively blocks suspicious activity while HIDS only detects and alerts (Correct answer)
- HIPS monitors network traffic while HIDS monitors host processes
- HIPS operates at the network level while HIDS operates at the host level
Correct answer: HIPS actively blocks suspicious activity while HIDS only detects and alerts
HIPS actively prevents suspicious activities from executing on the host, whereas HIDS only detects and generates alerts.
Question 14: Which approach to application security testing simulates real-world attackers by actively probing a running application for exploitable vulnerabilities?
- Code Review
- Design Review
- Dynamic Application Security Testing (DAST) (Correct answer)
- Static Application Security Testing (SAST)
Correct answer: Dynamic Application Security Testing (DAST)
DAST tests the running application from the outside by simulating attacker behavior, identifying vulnerabilities like injection flaws and authentication weaknesses that only appear at runtime.
Question 15: A CCP professional encounters an unfamiliar situation while performing cloud workload protection duties. What is the most appropriate first action?
- Skip the task entirely and move to the next assignment
- Apply a solution from an unrelated field without verification
- Consult relevant standards, guidelines, or a qualified supervisor before proceeding (Correct answer)
- Proceed based on general assumptions to avoid delays
Correct answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in cloud workload protection, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Question 16: What is the purpose of a SIEM use case library?
- To store raw log data for long-term retention
- To define pre-built detection rules and alert logic for known attack patterns (Correct answer)
- To configure network sensors and data collectors
- To manage user access to the SIEM platform
Correct answer: To define pre-built detection rules and alert logic for known attack patterns
A use case library contains pre-built detection logic, correlation rules, and alert thresholds mapped to known attack techniques, accelerating threat detection.
Question 17: An organization wants to measure how quickly it identifies a breach after it occurs. Which metric directly reflects this capability?
- Recovery Point Objective (RPO)
- Mean Time to Respond (MTTR)
- Mean Time to Detect (MTTD) (Correct answer)
- Recovery Time Objective (RTO)
Correct answer: Mean Time to Detect (MTTD)
Mean Time to Detect (MTTD) measures the average elapsed time between when an intrusion begins and when the security team first identifies it.
Question 18: What is the primary function of a Security Information and Event Management (SIEM) system?
- To encrypt data in transit
- To block malware at the endpoint
- To aggregate and correlate security logs for real-time analysis (Correct answer)
- To manage firewall rules
Correct answer: To aggregate and correlate security logs for real-time analysis
A SIEM collects and analyzes log data from across an organization's infrastructure to detect threats and generate alerts.
Question 19: In cloud workload security, what is 'drift detection'?
- Detecting data exfiltration to foreign IP ranges
- Tracking cost increases in cloud spending
- Identifying changes to a workload's configuration or state that deviate from its approved baseline (Correct answer)
- Monitoring network latency between cloud regions
Correct answer: Identifying changes to a workload's configuration or state that deviate from its approved baseline
Drift detection identifies when a running workload's configuration, files, or behavior has changed from its approved secure baseline.
Question 20: Which phase of the Cyber Kill Chain does spear-phishing with a malicious attachment PRIMARILY represent?
- Delivery (Correct answer)
- Reconnaissance
- Exploitation
- Weaponization
Correct answer: Delivery
Delivery is the phase where the adversary transmits the weaponized payload to the victim, such as via email attachment, link, or USB drop.
Question 21: When evaluating a CVE, the 'Scope' metric in CVSS v3.1 set to 'Changed' means:
- The attacker's privileges change after exploitation
- The patch changes the system's security configuration
- The vulnerability impacts components beyond the vulnerable component's authorization scope (Correct answer)
- The vulnerability scope changes between versions
Correct answer: The vulnerability impacts components beyond the vulnerable component's authorization scope
A 'Changed' Scope indicates that exploitation can affect components with different authorization scope, such as a VM escape affecting the hypervisor.
Question 22: In the context of vulnerability management, what is a 'false positive'?
- A patch that fails to remediate the vulnerability
- A CVE with an incorrect severity score
- A scanner reports a vulnerability that does not actually exist on the target system (Correct answer)
- A critical vulnerability that is not detected by the scanner
Correct answer: A scanner reports a vulnerability that does not actually exist on the target system
A false positive occurs when a vulnerability scanner incorrectly identifies a vulnerability on a system where it does not actually exist or is not exploitable in that configuration.
Question 23: Which of the following is a fundamental principle of nist & iso 27001 compliance as it applies to Certified Cybersecurity Professional?
- Avoiding documentation to streamline workflow efficiency
- Systematic evaluation and adherence to established industry standards (Correct answer)
- Relying solely on personal experience without reference to guidelines
- Prioritizing speed of completion over accuracy and compliance
Correct answer: Systematic evaluation and adherence to established industry standards
A fundamental principle of nist & iso 27001 compliance in Certified Cybersecurity Professional is the systematic evaluation and adherence to established industry standards, which ensures consistency, quality, and regulatory compliance across all professional activities.
Question 24: A user receives an email appearing to be from their bank asking them to click a link and enter credentials. This is an example of:
- Spear phishing
- Smishing
- Vishing
- Phishing (Correct answer)
Correct answer: Phishing
Phishing is a broad social engineering attack using fraudulent emails to trick users into revealing sensitive information.
Question 25: What is the importance of a cybersecurity policy in an organization?
- A cybersecurity policy helps establish guidelines for securing data and managing risks. (Correct answer)
- A cybersecurity policy is unnecessary if the organization has strong technical defenses.
- A cybersecurity policy is only necessary for large organizations.
- A cybersecurity policy focuses solely on hardware security.
Correct answer: A cybersecurity policy helps establish guidelines for securing data and managing risks.
A cybersecurity policy is a foundational document that outlines an organization's rules, procedures, and responsibilities for protecting its information assets. It establishes clear guidelines for employees on acceptable use, data handling, incident reporting, and security best practices. This policy creates a consistent framework for managing cyber risks, ensuring compliance, and fostering a security-aware culture.
Question 26: Under the ISCΒ² Code of Ethics, which canon takes the HIGHEST priority when canons conflict?
- Advance and protect the profession
- Provide diligent and competent service to principals
- Act honorably, honestly, justly, responsibly, and legally
- Protect society, the common good, necessary public trust and confidence, and the infrastructure (Correct answer)
Correct answer: Protect society, the common good, necessary public trust and confidence, and the infrastructure
The ISCΒ² Code of Ethics prioritizes protecting society and the public good above all other professional obligations when conflicts arise.
Question 27: Which vulnerability management framework uses 'Required Action' deadlines and is enforced by CISA for US federal agencies?
- CISA Known Exploited Vulnerabilities (KEV) catalog (Correct answer)
- CVSSv3.1 temporal scoring
- MITRE ATT&CK framework
- NIST NVD scoring system
Correct answer: CISA Known Exploited Vulnerabilities (KEV) catalog
The CISA KEV catalog lists vulnerabilities with evidence of active exploitation and mandates remediation deadlines for US federal civilian agencies under BOD 22-01.
Question 28: What is the primary ethical obligation of a CCP professional when a conflict of interest arises during iam & multi-factor authentication activities?
- Proceed while favoring the outcome that benefits the professional personally
- Disclose the conflict to all relevant parties and recuse from the decision if necessary (Correct answer)
- Ignore the conflict if it does not directly affect the current task
- Resolve the conflict privately without informing stakeholders
Correct answer: Disclose the conflict to all relevant parties and recuse from the decision if necessary
The primary ethical obligation when a conflict of interest arises in iam & multi-factor authentication is to disclose it to all relevant parties and, if necessary, recuse from the decision. This maintains professional integrity and stakeholder trust.
Question 29: Which type of risk assessment assigns numerical probabilities and financial values to risk outcomes?
- Qualitative
- Hybrid
- Subjective
- Quantitative (Correct answer)
Correct answer: Quantitative
Quantitative risk assessments use numerical data and monetary metrics to express risk in measurable financial terms.
Question 30: Data masking is most commonly used to protect sensitive data when:
- Encrypting production data for offsite backup
- Blocking unauthorized users from accessing live databases
- Compressing large data sets for archival storage
- Used in non-production environments such as development and testing (Correct answer)
Correct answer: Used in non-production environments such as development and testing
Data masking replaces real sensitive data with realistic but fictitious values, protecting actual data while allowing testing with representative data.
Question 31: Which metric defines the maximum acceptable downtime for a system following a disaster?
- Maximum Tolerable Downtime (MTD)
- Recovery Point Objective (RPO)
- Recovery Time Objective (RTO) (Correct answer)
- Mean Time to Repair (MTTR)
Correct answer: Recovery Time Objective (RTO)
The Recovery Time Objective (RTO) specifies the maximum time allowed to restore a system or process after a disruption.
Question 32: What does a high ratio of failed-to-successful login attempts on a single account over a short period MOST likely indicate?
- Session hijacking
- Brute-force or credential stuffing attack (Correct answer)
- Privilege escalation attempt
- Password spraying attack
Correct answer: Brute-force or credential stuffing attack
Many failed attempts followed by a success on one account is the classic signature of brute-force or credential stuffing rather than a distributed spray.
Question 33: A qualitative risk assessment is best characterized by the use of:
- Descriptive ratings such as High, Medium, and Low (Correct answer)
- Precise numerical formulas
- Statistical probability tables
- Exact monetary values
Correct answer: Descriptive ratings such as High, Medium, and Low
Qualitative risk assessments use descriptive categories rather than precise numerical or financial values.
Question 34: What is a firewall in cybersecurity?
- A tool for data backup and storage.
- A system that monitors and controls network traffic based on security rules. (Correct answer)
- A type of encryption used for file sharing.
- A physical device used to increase data speed.
Correct answer: A system that monitors and controls network traffic based on security rules.
A firewall acts as a security barrier between a trusted internal network and untrusted external networks, such as the internet. It monitors incoming and outgoing network traffic and enforces a set of predefined security rules to permit or block specific data packets. This prevents unauthorized access and protects the network from various cyber threats, serving as a first line of defense.
Question 35: In patch management, what is the primary purpose of maintaining a Software Bill of Materials (SBOM)?
- To track software license costs across the organization
- To document the patch deployment schedule
- To enable rapid identification of which systems are affected when a CVE is published for a specific component (Correct answer)
- To store CVSS scores for installed software
Correct answer: To enable rapid identification of which systems are affected when a CVE is published for a specific component
An SBOM catalogs all software components and dependencies in an application, enabling security teams to quickly identify exposure when a new CVE targets a specific library or component.
Question 36: Under the NIST SP 800-40 guidance on patch management, what is the recommended maximum timeframe to patch critical vulnerabilities in internet-facing systems?
- Within days to a few weeks, depending on risk (Correct answer)
- Only during the next scheduled maintenance window
- Within 12 months
- Within 6 months
Correct answer: Within days to a few weeks, depending on risk
NIST SP 800-40 recommends patching critical vulnerabilities in exposed systems as quickly as possible, typically within days to weeks, based on assessed risk.
Question 37: Which legal doctrine protects security researchers from CFAA liability when testing systems they are explicitly authorized to test?
- First Amendment protection
- Good faith exception
- Authorization as a complete defense (Correct answer)
- Implied consent
Correct answer: Authorization as a complete defense
Explicit written authorization from the system owner is the primary legal defense against CFAA claims, as the law's core prohibition requires lack of authorization.
Question 38: During a tabletop exercise, team members disagree on who has authority to authorize taking a production database offline. Which document SHOULD resolve this?
- Incident Response Plan's escalation and authority matrix (Correct answer)
- Business Impact Analysis (BIA)
- Disaster Recovery Plan
- Risk Register
Correct answer: Incident Response Plan's escalation and authority matrix
The IR Plan's authority matrix defines decision-making roles and escalation paths, including who can authorize disruptive containment actions.
Question 39: What is the primary difference between a self-signed certificate and a certificate issued by a trusted CA for establishing a public TLS service?
- Self-signed certificates are not trusted by browsers/OS trust stores, causing warnings for end users (Correct answer)
- Self-signed certificates use weaker encryption algorithms
- Self-signed certificates cannot contain Subject Alternative Names
- Self-signed certificates expire after 30 days by default
Correct answer: Self-signed certificates are not trusted by browsers/OS trust stores, causing warnings for end users
Self-signed certificates are not chained to any CA in a client's trust store, so browsers display security warnings; CA-issued certificates inherit trust from a pre-installed root CA.
Question 40: Which risk treatment option involves shifting financial impact to a third party such as an insurer?
- Risk avoidance
- Risk acceptance
- Risk mitigation
- Risk transference (Correct answer)
Correct answer: Risk transference
Risk transference moves the financial consequences of a risk event to another party, such as through cyber insurance.
Question 41: In the NIST Risk Management Framework (RMF), which step involves choosing appropriate security controls?
- Categorize
- Select (Correct answer)
- Implement
- Assess
Correct answer: Select
The Select step in NIST RMF involves choosing security controls tailored to the system's risk categorization.
Question 42: A CCP professional encounters an unfamiliar situation while performing iam & multi-factor authentication duties. What is the most appropriate first action?
- Consult relevant standards, guidelines, or a qualified supervisor before proceeding (Correct answer)
- Proceed based on general assumptions to avoid delays
- Skip the task entirely and move to the next assignment
- Apply a solution from an unrelated field without verification
Correct answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in iam & multi-factor authentication, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Question 43: Which document formally authorizes a system to operate while acknowledging its residual risks?
- Risk Management Plan
- Security Assessment Report (SAR)
- System Security Plan (SSP)
- Authorization to Operate (ATO) (Correct answer)
Correct answer: Authorization to Operate (ATO)
An Authorization to Operate (ATO) is issued by an authorizing official who accepts the residual risks of a system.
Question 44: After recovering from a supply chain attack via a compromised software update, which LONG-TERM control BEST prevents recurrence?
- Implementing software composition analysis and code signing verification (Correct answer)
- Blocking all automatic software updates organization-wide
- Requiring vendors to sign an updated SLA
- Increasing the frequency of vulnerability scans
Correct answer: Implementing software composition analysis and code signing verification
Software composition analysis detects malicious or altered components, and code signing verification ensures updates come from legitimate, untampered sources.
Question 45: Which CVSS v3.1 Temporal metric lowers the effective severity when an official vendor fix is available?
- Attack Complexity (AC)
- Exploit Code Maturity (E)
- Remediation Level (RL) (Correct answer)
- Report Confidence (RC)
Correct answer: Remediation Level (RL)
The Remediation Level (RL) temporal metric adjusts the score downward when an official fix exists, distinguishing between unpatched, workaround, and fully remediated states.
Question 46: What is the primary function of threat intelligence feeds integrated into a SIEM?
- To train machine learning models for anomaly detection
- To automatically patch vulnerable systems
- To provide indicators of compromise (IOCs) for matching against collected log data (Correct answer)
- To encrypt sensitive log data during transmission
Correct answer: To provide indicators of compromise (IOCs) for matching against collected log data
Threat intelligence feeds supply known malicious IOCs (IPs, domains, file hashes) that the SIEM matches against ingested logs to identify connections to known threat actors.
Question 47: Which approach prioritizes patching assets based on their exposure to the internet and business criticality?
- Chronological patch ordering
- Vendor severity-only ranking
- Risk-based patch prioritization (Correct answer)
- Alphabetical system patching
Correct answer: Risk-based patch prioritization
Risk-based patch prioritization factors in asset exposure, exploitability (e.g., EPSS score), and business criticality rather than relying solely on vendor severity ratings.
Question 48: The term 'threat landscape' refers to:
- The list of known malware signatures in a database
- A visual diagram of the network topology
- The complete range of potential threats facing an organization (Correct answer)
- The physical geography of network infrastructure assets
Correct answer: The complete range of potential threats facing an organization
The threat landscape encompasses all known and emerging threats that an organization may face at a given point in time.
Question 49: Which process systematically identifies, documents, and prioritizes risks to organizational assets?
- Vulnerability scanning
- Risk assessment (Correct answer)
- Penetration testing
- Incident response
Correct answer: Risk assessment
Risk assessment is the structured process of identifying threats and vulnerabilities, then evaluating their likelihood and impact to prioritize treatment.
Question 50: What does the CVE identifier format CVE-2023-12345 indicate?
- The CVE was patched in 2023
- The vendor ID is 12345
- The vulnerability was assigned in 2023 with sequence number 12345 (Correct answer)
- The vulnerability severity score is 12,345
Correct answer: The vulnerability was assigned in 2023 with sequence number 12345
CVE identifiers follow the format CVE-[year]-[sequence], where the year reflects when the CVE ID was assigned, not when the vulnerability was discovered or patched.
Question 51: Which log source is essential for detecting DNS-based data exfiltration?
- Antivirus scan logs from endpoints
- Windows Security Event logs
- NetFlow records from core switches
- DNS query and response logs showing unusually large TXT record queries or high-entropy subdomains (Correct answer)
Correct answer: DNS query and response logs showing unusually large TXT record queries or high-entropy subdomains
DNS exfiltration encodes data in DNS queries (often as long, high-entropy subdomains or TXT record lookups), making DNS server query logs the primary detection source.
Question 52: How is Annual Loss Expectancy (ALE) calculated?
- Asset value minus controls cost
- SLE multiplied by ARO (Correct answer)
- ARO divided by asset value
- SLE divided by ARO
Correct answer: SLE multiplied by ARO
ALE equals Single Loss Expectancy (SLE) multiplied by Annual Rate of Occurrence (ARO), representing expected yearly financial loss.
Question 53: Which MITRE ATT&CK tactic involves adversaries trying to steal credentials to gain further access?
- Credential Access (Correct answer)
- Privilege Escalation
- Collection
- Discovery
Correct answer: Credential Access
The Credential Access tactic in MITRE ATT&CK covers techniques adversaries use to steal account names and passwords, such as keylogging or credential dumping.
Question 54: Which OWASP Top 10 vulnerability occurs when an attacker inserts malicious SQL code into an input field that is directly passed to a database query?
- Insecure Direct Object Reference
- Cross-Site Scripting (XSS)
- SQL Injection (Correct answer)
- Security Misconfiguration
Correct answer: SQL Injection
SQL Injection occurs when untrusted data is sent to an interpreter as part of a command or query, allowing attackers to manipulate database queries.
Question 55: What is the purpose of a 'patch staging environment' in the patch management process?
- To generate compliance reports on patch status
- To test patches on representative systems before production deployment to catch regressions (Correct answer)
- To store backup copies of original software before patching
- To notify stakeholders about upcoming patches
Correct answer: To test patches on representative systems before production deployment to catch regressions
A staging environment mirrors production and is used to validate patches for compatibility and stability before they are pushed to live systems.
Question 56: NIST SP 800-61 focuses on which security domain?
- Risk Assessment
- Computer Security Incident Handling (Correct answer)
- Cryptographic Standards
- Access Control
Correct answer: Computer Security Incident Handling
NIST SP 800-61 (Computer Security Incident Handling Guide) provides guidelines for establishing and operating an incident response capability.
Question 57: Which hashing algorithm is currently recommended for password storage due to its resistance to brute-force attacks?
- SHA-1
- bcrypt (Correct answer)
- Base64
- MD5
Correct answer: bcrypt
bcrypt is a password hashing algorithm that intentionally slows down computation, making brute-force attacks significantly harder.
Question 58: An organization subject to SOX must maintain internal controls over financial reporting. Which IT control directly supports SOX compliance?
- Access control logs showing who modified financial data (Correct answer)
- Antivirus signature update schedules
- Network segmentation for DMZ zones
- Wireless encryption standards
Correct answer: Access control logs showing who modified financial data
SOX Section 404 requires controls ensuring the integrity of financial data; audit logs of financial system access directly demonstrate those controls.
Question 59: What is the key difference between a signature-based IDS and a behavior-based IDS?
- Signature-based IDS operates inline while behavior-based IDS only monitors passively
- Signature-based IDS is hardware-based while behavior-based IDS is software-based
- Signature-based IDS detects known attacks via pattern matching; behavior-based IDS detects anomalies from established baselines (Correct answer)
- Signature-based IDS requires more computational resources than behavior-based IDS
Correct answer: Signature-based IDS detects known attacks via pattern matching; behavior-based IDS detects anomalies from established baselines
Signature-based IDS matches traffic against known attack patterns (limited to known threats), while behavior-based IDS detects deviations from normal baselines (capable of detecting novel threats).
Question 60: A SOC analyst receives an alert that a privileged account logged in from two geographically impossible locations within 10 minutes. This is an example of which threat indicator?
- Impossible travel anomaly (Correct answer)
- Credential stuffing
- Beaconing pattern
- Lateral movement
Correct answer: Impossible travel anomaly
Impossible travel anomaly flags authentication events from locations that cannot be physically reached within the observed time window.
Question 61: Which security principle states that systems should fail in a secure state rather than an insecure one?
- Economy of mechanism
- Open design
- Complete mediation
- Fail-safe defaults (Correct answer)
Correct answer: Fail-safe defaults
Fail-safe defaults ensure that when a system fails or encounters an error, access is denied rather than granted.
Question 62: Which patch management metric measures the average time from patch availability to deployment across all systems?
- Mean Time to Detect (MTTD)
- Patch Compliance Rate
- Vulnerability Density
- Mean Time to Patch (MTTP) (Correct answer)
Correct answer: Mean Time to Patch (MTTP)
Mean Time to Patch (MTTP) measures the average elapsed time from when a patch becomes available to when it is deployed across target systems.
Question 63: What is a DDoS attack?
- A form of network optimization.
- An attack that floods a network or server with traffic, causing it to become unavailable. (Correct answer)
- A method of speeding up data access.
- A process used to recover lost data.
Correct answer: An attack that floods a network or server with traffic, causing it to become unavailable.
A Distributed Denial of Service (DDoS) attack is a malicious attempt to disrupt the normal traffic of a targeted server, service, or network. It achieves this by overwhelming the target with a flood of internet traffic from multiple compromised computer systems. This excessive traffic consumes bandwidth and resources, making the service unavailable to legitimate users and causing significant operational disruption.
Question 64: What is an intrusion detection system (IDS)?
- A system that detects hardware failures.
- A system that monitors network traffic for signs of unauthorized access or malicious activity. (Correct answer)
- A software used to track user activity.
- A tool for storing backup copies of data.
Correct answer: A system that monitors network traffic for signs of unauthorized access or malicious activity.
An Intrusion Detection System (IDS) is a security technology designed to monitor network or system activities for malicious behavior or policy violations. It analyzes traffic patterns and system logs, alerting administrators to potential security incidents or attacks. While an IDS detects, it typically does not prevent the intrusion, but rather provides crucial information for rapid response and mitigation.
Question 65: In PKI, what is a Certificate Revocation List (CRL) Distribution Point (CDP)?
- A URL embedded in certificates indicating where to download the issuing CA's CRL (Correct answer)
- A database of all certificates issued by a CA
- A hardware security module that stores CRL signing keys
- A network device that caches OCSP responses
Correct answer: A URL embedded in certificates indicating where to download the issuing CA's CRL
The CDP extension in an X.509 certificate contains URLs pointing to the issuing CA's current CRL, allowing relying parties to check whether the certificate has been revoked.
Question 66: In a federated identity model, what role does the Identity Provider (IdP) play?
- It manages firewall rules for authenticated sessions
- It encrypts data between the user and Service Provider
- It authenticates users and issues tokens that Service Providers trust (Correct answer)
- It stores user passwords locally at each service
Correct answer: It authenticates users and issues tokens that Service Providers trust
The IdP authenticates users and issues assertions or tokens (e.g., SAML assertions, JWTs) that Service Providers accept as proof of authentication.
Question 67: What is the significance of eBPF (extended Berkeley Packet Filter) in modern cloud workload security?
- It encrypts data at rest in cloud storage
- It provides DDoS mitigation at the network edge
- It enables low-overhead kernel-level visibility into workload behavior without modifying application code (Correct answer)
- It manages SSL/TLS certificate rotation
Correct answer: It enables low-overhead kernel-level visibility into workload behavior without modifying application code
eBPF allows security tools to observe system calls, network activity, and process behavior at the kernel level with minimal performance overhead.
Question 68: An attacker performs a BGP hijack to redirect traffic for an OCSP responder's IP address. What is the likely goal of this attack in the context of PKI?
- Force clients to fall back to CRL checking instead of OCSP
- Obtain a fraudulent certificate from the target CA
- Steal the OCSP responder's private signing key
- Cause OCSP responses to return 'good' for revoked certificates, enabling use of compromised credentials (Correct answer)
Correct answer: Cause OCSP responses to return 'good' for revoked certificates, enabling use of compromised credentials
By intercepting OCSP traffic, an attacker can return forged 'good' responses for revoked certificates, allowing continued use of compromised client or server certificates that should have been rejected.
Question 69: An analyst notices thousands of failed SSH login attempts from a single IP, followed by one successful login. What attack stage does this most likely represent?
- Lateral movement after initial access
- Brute force attack culminating in successful authentication (Correct answer)
- Pass-the-hash attack against SSH
- Credential stuffing leading to account compromise
Correct answer: Brute force attack culminating in successful authentication
Many failed logins followed by one success is the classic signature of a brute force attack where the attacker eventually guesses the correct password.
Question 70: A security engineer needs to determine if a CVE affects their environment without a scanner. Which artifact provides the most authoritative list of affected product versions?
- Third-party blog posts about the vulnerability
- The CVE description text alone
- The CVSS vector string
- The vendor security advisory and associated CPE list in the NVD entry (Correct answer)
Correct answer: The vendor security advisory and associated CPE list in the NVD entry
Vendor security advisories combined with NVD CPE data provide authoritative, versioned product lists to determine applicability without relying on scanner output.
Question 71: Which Kerberos component issues Ticket Granting Tickets (TGTs) after verifying user credentials?
- Key Distribution Center β Authentication Service (KDC-AS) (Correct answer)
- Resource Server
- Ticket Granting Service (TGS)
- Service Principal
Correct answer: Key Distribution Center β Authentication Service (KDC-AS)
The Authentication Service (AS) component of the KDC verifies the user's credentials and issues a TGT, which is then used to request service tickets from the TGS.
Question 72: Which principle ensures that if one security control is defeated, another independent control still protects the asset?
- Redundancy of controls (Correct answer)
- Perimeter focus
- Single-factor authentication
- Security through complexity
Correct answer: Redundancy of controls
Redundancy of controls is the core defense-in-depth principle where multiple independent safeguards protect assets even when one fails.
Question 73: Which tunneling protocol creates a point-to-point connection and is commonly used with IPsec for remote access VPNs on Windows?
- L2TP (Correct answer)
- GRE
- SSL/TLS
- PPTP
Correct answer: L2TP
L2TP provides the tunneling mechanism while IPsec provides encryption, and together they form L2TP/IPsec, widely used for Windows remote access VPNs.
Question 74: Which HTTP security header helps prevent Cross-Site Scripting attacks by specifying which dynamic resources are allowed to load?
- Content-Security-Policy (Correct answer)
- X-Content-Type-Options
- Strict-Transport-Security
- X-Frame-Options
Correct answer: Content-Security-Policy
Content-Security-Policy (CSP) instructs browsers to only execute or render resources from trusted sources, significantly reducing XSS attack surface.
Question 75: A SOC analyst receives an alert for a PowerShell command with a Base64-encoded payload. What is the attacker most likely attempting?
- Obfuscating malicious code to evade signature-based detection (Correct answer)
- Legitimate administrative scripting for patch deployment
- Compressing log files to free up disk space
- Encrypting data for secure transmission to a backup server
Correct answer: Obfuscating malicious code to evade signature-based detection
Attackers commonly Base64-encode PowerShell payloads to bypass signature-based detection tools that scan for plaintext malicious strings.
Question 76: A cloud service provider wants ISO 27001 certification. Which additional ISO standard specifically extends 27001 for cloud security?
- ISO 27035
- ISO 27701
- ISO 27017 (Correct answer)
- ISO 27018
Correct answer: ISO 27017
ISO/IEC 27017 provides guidelines for information security controls applicable to the provision and use of cloud services, extending ISO 27001.
Question 77: Which AWS service provides managed threat detection for EC2 instances, containers, and serverless workloads by analyzing CloudTrail, VPC Flow Logs, and DNS logs?
- AWS Shield
- AWS Inspector
- AWS Macie
- AWS GuardDuty (Correct answer)
Correct answer: AWS GuardDuty
AWS GuardDuty is a managed threat detection service that continuously monitors and analyzes data sources to identify malicious activity across workloads.
Question 78: An employee uses company resources to run a personal cryptocurrency mining operation. Which ethical violation has primarily occurred?
- Unauthorized use of resources (Correct answer)
- Failure to report a security incident
- Violation of need-to-know principle
- Breach of confidentiality
Correct answer: Unauthorized use of resources
Using organizational resources for personal financial gain without authorization violates the ethical obligation to use employer resources only for authorized purposes.
Question 79: In the Secure Software Development Lifecycle (SSDLC), during which phase should threat modeling primarily be performed?
- Design (Correct answer)
- Testing
- Deployment
- Maintenance
Correct answer: Design
Threat modeling is most effective during the Design phase, enabling architects to identify and mitigate security risks before code is written.
Question 80: In CVSS v3.1, a vulnerability with Integrity Impact: High means that:
- System availability is severely impacted
- Authentication data can be stolen
- There is total loss of integrity; the attacker can modify any or all files protected by the vulnerable component (Correct answer)
- Only low-sensitivity data can be modified
Correct answer: There is total loss of integrity; the attacker can modify any or all files protected by the vulnerable component
Integrity Impact: High in CVSS v3.1 means the attacker can completely modify protected data or system files, resulting in total loss of integrity.
Question 81: In OAuth 2.0, what does the 'scope' parameter control?
- The token expiration window
- The encryption algorithm used for the token
- The specific permissions and resources the access token grants (Correct answer)
- The geographic region where tokens are valid
Correct answer: The specific permissions and resources the access token grants
Scopes define the level of access requested by the client, limiting what actions the access token permits on the resource server.
Question 82: Which quality assurance method is most commonly applied in network perimeter defense to verify that CCP professional standards are being met?
- Informal self-assessment without external validation
- Structured audits, peer reviews, and performance metrics aligned with industry benchmarks (Correct answer)
- Annual reviews conducted exclusively by non-technical management
- Relying on client satisfaction surveys as the sole measure of quality
Correct answer: Structured audits, peer reviews, and performance metrics aligned with industry benchmarks
Structured audits, peer reviews, and performance metrics aligned with industry benchmarks are the most effective quality assurance methods in network perimeter defense, providing objective, measurable evidence that CCP standards are consistently met.
Question 83: A security engineer needs to ensure that a set of TLS certificates cannot be misused after their private keys are stolen, even retroactively for past captured traffic. Which property addresses this?
- Extended validation certificates
- Certificate transparency logging
- Perfect Forward Secrecy (PFS) (Correct answer)
- Online Certificate Status Protocol
Correct answer: Perfect Forward Secrecy (PFS)
PFS, achieved via ephemeral key exchange (ECDHE/DHE), ensures that session keys are not derivable from the server's long-term private key, protecting past sessions even if that key is later compromised.
Question 84: Which NVD data field provides a standardized list of weakness types associated with a CVE, helping analysts understand root causes?
- CPE (Common Platform Enumeration)
- CAPEC ID
- CWE (Common Weakness Enumeration) (Correct answer)
- CVSS Base Score
Correct answer: CWE (Common Weakness Enumeration)
CWE entries linked to a CVE describe the underlying software weakness category (e.g., CWE-79 for XSS), aiding root-cause analysis and remediation prioritization.
Question 85: What is an SSL/TLS certificate used for?
- To store customer data.
- To monitor network traffic.
- To encrypt data transmission and protect sensitive information on websites. (Correct answer)
- To improve network performance.
Correct answer: To encrypt data transmission and protect sensitive information on websites.
An SSL/TLS certificate is essential for securing communication over the internet, particularly for websites. It enables encrypted data transmission between a user's browser and a web server, protecting sensitive information like login credentials and payment details from interception. The certificate also verifies the authenticity of the website, assuring users they are connecting to the legitimate site.
Question 86: A CVE marked 'DISPUTED' in the NVD indicates:
- The vulnerability is under active exploitation
- At least one party disagrees that the reported issue is a vulnerability or that the details are accurate (Correct answer)
- The CVE ID has been reserved but not yet published
- The CVE has been patched by the vendor
Correct answer: At least one party disagrees that the reported issue is a vulnerability or that the details are accurate
A DISPUTED status means there is disagreement between the reporter and vendor (or other parties) about whether the issue constitutes a valid exploitable vulnerability.
Question 87: What is the primary purpose of a threat intelligence feed in an IR workflow?
- To automate patch deployment on vulnerable systems
- To enrich IOCs with known adversary TTPs for faster triage (Correct answer)
- To generate compliance reports for auditors
- To replace manual log review in the SOC
Correct answer: To enrich IOCs with known adversary TTPs for faster triage
Threat intelligence feeds provide context such as known malicious IPs, hashes, and TTPs that help analysts quickly assess severity and attribution.
Question 88: What is two-factor authentication?
- Requiring a fingerprint for system access.
- Requiring only a password to access an account.
- Requiring two forms of verification, such as a password and a code sent to your phone. (Correct answer)
- Requiring an IP address for verification.
Correct answer: Requiring two forms of verification, such as a password and a code sent to your phone.
Two-factor authentication (2FA) significantly enhances security by requiring users to provide two different types of credentials to verify their identity. This typically combines something the user knows (like a password) with something the user has (like a phone or a token) or something the user is (like a fingerprint). Even if one factor is compromised, the second factor prevents unauthorized access, making accounts much more secure.
Question 89: Which security control verifies device identity and health posture before granting access to any organizational resource?
- Zero Trust Network Access (ZTNA) (Correct answer)
- Data Loss Prevention (DLP)
- Web Application Firewall (WAF)
- Security Information and Event Management (SIEM)
Correct answer: Zero Trust Network Access (ZTNA)
ZTNA enforces the zero-trust principle by continuously verifying device health and user identity before allowing resource access.
Question 90: Which component of the Common Platform Enumeration (CPE) naming scheme identifies the specific version of an affected product?
- The version field in the CPE URI, e.g., cpe:/a:vendor:product:version (Correct answer)
- The CVSS Attack Vector field
- The CVE reference in the NVD entry
- The CWE identifier linked to the CVE
Correct answer: The version field in the CPE URI, e.g., cpe:/a:vendor:product:version
CPE URIs include a version field that specifies the exact product version affected, enabling precise matching of CVEs to installed software inventories.
Question 91: When documenting activities related to cloud workload protection, which practice is considered essential for CCP certification holders?
- Completing documentation only when requested by auditors or supervisors
- Recording only outcomes while omitting the methods and processes used
- Maintaining comprehensive records that include procedures, observations, results, and any anomalies (Correct answer)
- Keeping documentation in personal notes that are not accessible to other team members
Correct answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in cloud workload protection. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
Question 92: When a TLS session is resumed using a pre-shared key (PSK) in TLS 1.3, what security property is potentially weakened?
- Authentication of the server identity
- Forward secrecy for the resumed session (Correct answer)
- Confidentiality of the session data
- Integrity checking via AEAD ciphers
Correct answer: Forward secrecy for the resumed session
PSK-only resumption reuses keying material from a prior session, so compromising that PSK can expose the resumed session's traffic, weakening forward secrecy.
Question 93: What is the primary purpose of a Cloud Workload Protection Platform (CWPP)?
- To provide visibility and protection for workloads across hybrid and multi-cloud environments (Correct answer)
- To manage user identity and access provisioning
- To manage cloud billing and cost optimization
- To configure cloud network topology
Correct answer: To provide visibility and protection for workloads across hybrid and multi-cloud environments
CWPPs are designed to secure workloads (VMs, containers, serverless) across hybrid and multi-cloud environments with unified visibility.
Question 94: When a CVE has a CVSS Base Score of 9.8 but the organization's risk-based assessment downgrades priority, which factor MOST justifies that decision?
- The vendor has not yet released a patch
- The vulnerable service is not exposed to untrusted networks and no compensating controls are bypassed (Correct answer)
- The CVE was published more than 90 days ago
- Another team owns the affected system
Correct answer: The vulnerable service is not exposed to untrusted networks and no compensating controls are bypassed
Even a Critical CVE poses reduced risk if the vulnerable component is isolated from attack vectors (e.g., no internet exposure, network segmentation), justifying lower remediation urgency.
Question 95: What is the primary ethical obligation of a CCP professional when a conflict of interest arises during cve assessment & patch management activities?
- Proceed while favoring the outcome that benefits the professional personally
- Resolve the conflict privately without informing stakeholders
- Ignore the conflict if it does not directly affect the current task
- Disclose the conflict to all relevant parties and recuse from the decision if necessary (Correct answer)
Correct answer: Disclose the conflict to all relevant parties and recuse from the decision if necessary
The primary ethical obligation when a conflict of interest arises in cve assessment & patch management is to disclose it to all relevant parties and, if necessary, recuse from the decision. This maintains professional integrity and stakeholder trust.
Question 96: What is 'continuous authentication' in modern IAM?
- Requiring users to re-enter their password every 15 minutes
- Authenticating using a continuous biometric stream
- Sending OTPs every few minutes during an active session
- Ongoing risk-based verification of user identity throughout a session using behavioral signals (Correct answer)
Correct answer: Ongoing risk-based verification of user identity throughout a session using behavioral signals
Continuous authentication monitors behavioral signals (typing patterns, mouse movement, location) throughout a session and triggers re-authentication if risk indicators change.
Question 97: Which vulnerability class occurs when an application deserializes untrusted data, allowing attackers to execute arbitrary code?
- Insecure Deserialization (Correct answer)
- Server-Side Request Forgery (SSRF)
- Path Traversal
- XML External Entity (XXE) Injection
Correct answer: Insecure Deserialization
Insecure Deserialization allows attackers to manipulate serialized objects to alter application logic or achieve remote code execution during the deserialization process.
Question 98: What is the primary function of a Mobile Device Management (MDM) solution?
- To provide encrypted VPN connectivity for mobile users
- To encrypt mobile application data while in transit
- To centrally manage and enforce security policies on mobile devices (Correct answer)
- To monitor mobile data traffic for intrusions
Correct answer: To centrally manage and enforce security policies on mobile devices
MDM solutions allow IT administrators to remotely manage configurations, enforce policies, and wipe or lock mobile devices as needed.
Question 99: In the context of cloud workload protection, what role does continuous professional development play for CCP practitioners?
- It serves primarily as a networking opportunity with no practical benefit
- It is required only during the first year of certification
- It is optional and only needed for career advancement
- It ensures practitioners remain current with evolving standards, technologies, and best practices (Correct answer)
Correct answer: It ensures practitioners remain current with evolving standards, technologies, and best practices
Continuous professional development is essential in cloud workload protection because it ensures CCP practitioners remain current with evolving standards, technologies, and best practices, maintaining competency throughout their careers.
Question 100: A company wants to ensure that only authenticated and policy-compliant devices can connect to the corporate network. Which technology enforces this?
- RADIUS accounting only
- Spanning Tree Protocol
- Network Access Control (NAC) (Correct answer)
- SNMP
Correct answer: Network Access Control (NAC)
NAC evaluates device health posture and authentication status before granting network access, quarantining non-compliant endpoints.
Question 101: What is the primary ethical obligation of a CCP professional when a conflict of interest arises during tls, pki & encryption standards activities?
- Proceed while favoring the outcome that benefits the professional personally
- Resolve the conflict privately without informing stakeholders
- Ignore the conflict if it does not directly affect the current task
- Disclose the conflict to all relevant parties and recuse from the decision if necessary (Correct answer)
Correct answer: Disclose the conflict to all relevant parties and recuse from the decision if necessary
The primary ethical obligation when a conflict of interest arises in tls, pki & encryption standards is to disclose it to all relevant parties and, if necessary, recuse from the decision. This maintains professional integrity and stakeholder trust.
Question 102: Which of the following is a fundamental principle of siem & threat detection as it applies to Certified Cybersecurity Professional?
- Relying solely on personal experience without reference to guidelines
- Prioritizing speed of completion over accuracy and compliance
- Systematic evaluation and adherence to established industry standards (Correct answer)
- Avoiding documentation to streamline workflow efficiency
Correct answer: Systematic evaluation and adherence to established industry standards
A fundamental principle of siem & threat detection in Certified Cybersecurity Professional is the systematic evaluation and adherence to established industry standards, which ensures consistency, quality, and regulatory compliance across all professional activities.
Question 103: In a layered security architecture, what is the purpose of a bastion host?
- Provide cloud backup for critical servers
- Monitor user behavior analytics
- Run antivirus scans across all endpoints
- Serve as a hardened gateway for administrative access to internal networks (Correct answer)
Correct answer: Serve as a hardened gateway for administrative access to internal networks
A bastion host is a specially hardened server that provides a secure and monitored entry point for administrative access, reducing the internal attack surface.
Question 104: A user's TOTP app generates a code that the server rejects despite correct time sync. What is the MOST likely cause?
- The user is using an IPv6 connection
- The server's HMAC algorithm is SHA-512 instead of SHA-1
- The TOTP secret was provisioned with an incorrect shared key (Correct answer)
- The session cookie has expired
Correct answer: The TOTP secret was provisioned with an incorrect shared key
If the shared secret between the TOTP app and the server does not match, generated codes will never validate regardless of correct time synchronization.
Question 105: An attacker uses DNS TXT records to exfiltrate data. Which detection technique is MOST effective against this method?
- Blocking all TXT record queries at the firewall
- Deploying a web application firewall
- Analyzing DNS query length and frequency anomalies (Correct answer)
- Enabling DNSSEC on internal zones
Correct answer: Analyzing DNS query length and frequency anomalies
DNS exfiltration typically produces unusually long TXT queries or high query frequency that can be detected through behavioral DNS analytics.
Question 106: What does EPSS (Exploit Prediction Scoring System) provide that CVSS does not?
- A probability estimate that a CVE will be exploited in the wild within the next 30 days (Correct answer)
- A list of affected product versions
- A severity score based on technical impact
- An official vendor patch status
Correct answer: A probability estimate that a CVE will be exploited in the wild within the next 30 days
EPSS produces a daily probability score (0β1) predicting likelihood of exploitation in the wild, complementing CVSS severity with real-world threat intelligence.
Question 107: ISO/IEC 27001 requires organizations to establish an ISMS. What does ISMS stand for?
- Infrastructure Security Measurement Standard
- Incident and Security Mitigation Strategy
- Information Security Management System (Correct answer)
- Integrated Security Monitoring System
Correct answer: Information Security Management System
An Information Security Management System (ISMS) is a systematic approach to managing sensitive company information, as defined in ISO/IEC 27001.
Question 108: What is a 'golden image' in the context of cloud workload security?
- A hardened, pre-approved VM or container image used as a secure baseline for deployments (Correct answer)
- An image with maximum performance settings enabled
- A cloud provider's premium support tier
- A backup snapshot stored in object storage
Correct answer: A hardened, pre-approved VM or container image used as a secure baseline for deployments
A golden image is a hardened, security-vetted baseline image that serves as the approved template for cloud workload deployments.
Question 109: Which protocol is commonly used by modern firewalls and routers to share threat intelligence and dynamically update access control lists?
- SNMP v3
- BGP Flowspec (Correct answer)
- RADIUS
- LDAP over SSL
Correct answer: BGP Flowspec
BGP Flowspec allows routers and firewalls to receive and propagate traffic filtering rules dynamically, enabling rapid response to distributed threats like DDoS.
Question 110: What is the key difference between symmetric and asymmetric encryption?
- Symmetric uses one shared key; asymmetric uses a public-private key pair (Correct answer)
- Symmetric uses no keys; asymmetric uses one key
- Symmetric is only for data at rest
- Symmetric is slower; asymmetric is faster
Correct answer: Symmetric uses one shared key; asymmetric uses a public-private key pair
Symmetric encryption uses the same key for encryption and decryption, while asymmetric uses mathematically related public and private keys.
Question 111: A CCP professional encounters an unfamiliar situation while performing siem & threat detection duties. What is the most appropriate first action?
- Consult relevant standards, guidelines, or a qualified supervisor before proceeding (Correct answer)
- Proceed based on general assumptions to avoid delays
- Skip the task entirely and move to the next assignment
- Apply a solution from an unrelated field without verification
Correct answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in siem & threat detection, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Question 112: Which patch management process step ensures that applied patches have not been tampered with during distribution?
- Cryptographic hash or digital signature verification of patch packages before installation (Correct answer)
- Reviewing the vendor's public changelog
- Running a vulnerability scan after patching
- Checking patch release notes for CVE references
Correct answer: Cryptographic hash or digital signature verification of patch packages before installation
Verifying SHA-256 hashes or vendor digital signatures before applying patches ensures the patch package has not been modified or corrupted in transit, preventing supply-chain tampering.
Question 113: Which phase of incident response involves analyzing SIEM data to understand the full scope of a breach?
- Preparation
- Detection and Analysis (Correct answer)
- Post-Incident Activity
- Containment
Correct answer: Detection and Analysis
The Detection and Analysis phase involves examining SIEM alerts, logs, and correlated events to confirm the incident, determine its scope, and understand the attack vector.
Question 114: Why is it important to regularly update software in cybersecurity?
- To prevent cyberattacks by patching security flaws and vulnerabilities. (Correct answer)
- To improve system aesthetics.
- To improve data storage capacity.
- To ensure software runs faster.
Correct answer: To prevent cyberattacks by patching security flaws and vulnerabilities.
Regularly updating software is critical in cybersecurity because updates often include patches for newly discovered security flaws and vulnerabilities. Attackers frequently exploit these weaknesses to gain unauthorized access or deploy malware. By applying updates promptly, organizations and individuals can close these security gaps, significantly reducing their risk of cyberattacks and maintaining system integrity.
Question 115: When the cost of mitigating a risk exceeds the value of the asset at risk, which risk response is most appropriate?
- Risk transference
- Risk acceptance (Correct answer)
- Risk mitigation
- Risk avoidance
Correct answer: Risk acceptance
Risk acceptance is rational when the cost to mitigate a risk outweighs the potential financial loss from the risk event.
Question 116: Which framework specifically guides U.S. federal agencies through a structured risk management process?
- OCTAVE
- ISO 31000
- NIST Risk Management Framework (RMF) (Correct answer)
- FAIR (Factor Analysis of Information Risk)
Correct answer: NIST Risk Management Framework (RMF)
The NIST RMF is mandatory for U.S. federal agencies and provides a structured process for managing information security risk.
Question 117: What is the primary ethical obligation of a CCP professional when a conflict of interest arises during nist & iso 27001 compliance activities?
- Proceed while favoring the outcome that benefits the professional personally
- Resolve the conflict privately without informing stakeholders
- Disclose the conflict to all relevant parties and recuse from the decision if necessary (Correct answer)
- Ignore the conflict if it does not directly affect the current task
Correct answer: Disclose the conflict to all relevant parties and recuse from the decision if necessary
The primary ethical obligation when a conflict of interest arises in nist & iso 27001 compliance is to disclose it to all relevant parties and, if necessary, recuse from the decision. This maintains professional integrity and stakeholder trust.
Question 118: Which cryptographic concept ensures that a sender cannot deny having sent a message?
- Confidentiality
- Non-repudiation (Correct answer)
- Availability
- Integrity
Correct answer: Non-repudiation
Non-repudiation ensures that a party cannot deny the authenticity of their signature or the sending of a message.
Question 119: A security team is performing lessons learned after a breach. Which output is MOST valuable for improving future IR capability?
- Metrics on mean time to detect and respond
- A list of all IOCs discovered during the incident
- A timeline of attacker actions for law enforcement
- Updated playbooks reflecting gaps identified during the response (Correct answer)
Correct answer: Updated playbooks reflecting gaps identified during the response
Updated playbooks directly improve future response speed and consistency by codifying what worked and fixing what failed during the incident.
Question 120: A CCP professional encounters an unfamiliar situation while performing defense-in-depth architecture duties. What is the most appropriate first action?
- Apply a solution from an unrelated field without verification
- Skip the task entirely and move to the next assignment
- Consult relevant standards, guidelines, or a qualified supervisor before proceeding (Correct answer)
- Proceed based on general assumptions to avoid delays
Correct answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in defense-in-depth architecture, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Question 121: Which NIST document provides guidelines for applying the Risk Management Framework to federal information systems?
- SP 800-171
- SP 800-53
- SP 800-30
- SP 800-37 (Correct answer)
Correct answer: SP 800-37
NIST SP 800-37 (Risk Management Framework for Information Systems and Organizations) provides the six-step RMF process for federal systems.
Question 122: What is encryption in network security?
- Compressing data to save storage space.
- Converting data into readable format.
- Storing data in cloud servers.
- Converting data into unreadable format to protect it from unauthorized access. (Correct answer)
Correct answer: Converting data into unreadable format to protect it from unauthorized access.
Encryption is a fundamental cybersecurity process that transforms readable data (plaintext) into an unreadable format (ciphertext) using an algorithm and a key. This conversion ensures that even if unauthorized individuals intercept the data, they cannot understand its content without the correct decryption key. Its primary purpose is to protect data confidentiality and integrity during transmission and storage.
Question 123: Which scenario represents a 'virtual patch' or 'shield' in patch management?
- Deploying a new server version to replace the vulnerable one
- A WAF or IPS rule that blocks exploitation of a vulnerability without modifying the vulnerable system itself (Correct answer)
- Installing a vendor-provided hotfix
- Applying an operating system kernel patch
Correct answer: A WAF or IPS rule that blocks exploitation of a vulnerability without modifying the vulnerable system itself
A virtual patch uses a WAF, IPS, or network control to detect and block exploit attempts against a vulnerability, providing protection when the actual system patch cannot be immediately applied.
Question 124: An attacker exploits a misconfigured open DNS resolver to amplify a DDoS attack. What makes DNS suitable for amplification attacks?
- DNS uses TCP which is easier to spoof
- DNS servers lack rate limiting by design
- Small DNS queries can return much larger responses (Correct answer)
- DNS traffic bypasses firewalls automatically
Correct answer: Small DNS queries can return much larger responses
DNS amplification works because a small forged query (e.g., ANY record request) can return a response many times larger, overwhelming the spoofed victim's bandwidth.
Question 125: What is the CIA Triad's relevance when classifying a DDoS attack?
- It equally affects all three pillars
- It primarily affects Integrity
- It primarily affects Availability (Correct answer)
- It primarily affects Confidentiality
Correct answer: It primarily affects Availability
A DDoS (Distributed Denial of Service) attack overwhelms systems to make services unavailable, directly targeting the Availability pillar of the CIA Triad.
Question 126: Which technique can attackers use to exploit the gap between vulnerability disclosure and patch deployment?
- Zero-trust architecture bypass
- N-day exploit development targeting the disclosed CVE before patching is complete (Correct answer)
- Certificate pinning attacks
- Patch diffing to discover new attack surfaces
Correct answer: N-day exploit development targeting the disclosed CVE before patching is complete
After a CVE is disclosed, attackers develop N-day exploits targeting unpatched systems, making rapid patch deployment critical during the exposure window.
Question 127: A CA issues a wildcard certificate for *.example.com. Which hostname would NOT be covered by this certificate?
- mail.example.com
- sub.mail.example.com (Correct answer)
- www.example.com
- api.example.com
Correct answer: sub.mail.example.com
Wildcard certificates cover only one level of subdomain depth; *.example.com matches mail.example.com but not sub.mail.example.com (two levels deep).
Question 128: A threat agent is best defined as:
- A technical safeguard deployed against attacks
- A weakness in a system that can be exploited
- An entity capable of deliberately or accidentally exploiting a vulnerability (Correct answer)
- The quantified impact of a security breach
Correct answer: An entity capable of deliberately or accidentally exploiting a vulnerability
A threat agent is the individual, group, or environmental force that has the potential to exploit a vulnerability.
Question 129: Under the Computer Fraud and Abuse Act (CFAA), which activity is explicitly prohibited?
- Accessing a protected computer without authorization (Correct answer)
- Monitoring your own network traffic
- Performing authorized penetration tests
- Encrypting data on your own systems
Correct answer: Accessing a protected computer without authorization
The CFAA prohibits unauthorized access to protected computers, including federal and financial systems and those used in interstate commerce.
Question 130: Which perimeter defense technology creates an encrypted tunnel between a remote user and the corporate network, extending the trusted perimeter?
- Port-based NAC
- Web application firewall
- Virtual Private Network (VPN) (Correct answer)
- VLAN segmentation
Correct answer: Virtual Private Network (VPN)
A VPN establishes an encrypted tunnel that allows remote users to securely access internal resources as if they were on the corporate network.
Question 131: An organization uses data classification, DLP tools, and encryption to protect sensitive files. Which defense-in-depth layer is being addressed?
- Application layer
- Data layer (Correct answer)
- Network layer
- Physical layer
Correct answer: Data layer
Data layer controls protect information itself through classification, encryption, and loss prevention regardless of the transport path.
Question 132: What does 'event enrichment' mean in the context of SIEM?
- Adding contextual information (e.g., geolocation, asset criticality) to raw events (Correct answer)
- Compressing logs to reduce storage overhead
- Encrypting log data before storage
- Filtering out low-priority events before ingestion
Correct answer: Adding contextual information (e.g., geolocation, asset criticality) to raw events
Event enrichment adds contextual metadata such as user identity, asset ownership, geolocation, or threat intelligence data to raw log events, improving analyst decision-making.
Question 133: What is the role of endpoint detection and response (EDR) in a defense-in-depth architecture?
- Encrypt data at rest on servers
- Manage firewall rule sets centrally
- Provide VPN tunneling for remote users
- Monitor and respond to threats on end-user devices (Correct answer)
Correct answer: Monitor and respond to threats on end-user devices
EDR solutions monitor endpoint activity in real time and provide automated or analyst-driven response to threats at the host layer.
Question 134: In patch management, what is a 'patch window'?
- The time between vulnerability disclosure and patch release
- A GUI tool for reviewing patches
- A vulnerability in the patching software itself
- A scheduled maintenance period when patches are applied to minimize disruption (Correct answer)
Correct answer: A scheduled maintenance period when patches are applied to minimize disruption
A patch window is a predetermined maintenance window during which IT teams apply patches to minimize impact on business operations.
Question 135: A CCP professional encounters an unfamiliar situation while performing cve assessment & patch management duties. What is the most appropriate first action?
- Proceed based on general assumptions to avoid delays
- Skip the task entirely and move to the next assignment
- Consult relevant standards, guidelines, or a qualified supervisor before proceeding (Correct answer)
- Apply a solution from an unrelated field without verification
Correct answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in cve assessment & patch management, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Question 136: Why are legal and ethical considerations important in cybersecurity?
- Legal and ethical considerations are irrelevant in cybersecurity.
- Legal and ethical considerations only apply to financial transactions.
- Legal and ethical considerations focus solely on employee behavior.
- Legal and ethical considerations ensure that organizations protect data, comply with laws, and maintain trust. (Correct answer)
Correct answer: Legal and ethical considerations ensure that organizations protect data, comply with laws, and maintain trust.
Legal and ethical considerations are paramount in cybersecurity because they guide responsible data handling, privacy protection, and the appropriate use of security tools and techniques. Adhering to laws like GDPR and ethical principles ensures organizations protect data, comply with legal obligations, and maintain the trust of their customers and stakeholders. Failing to do so can lead to severe legal penalties, reputational damage, and erosion of public confidence.
Question 137: Which approach best addresses the security challenge of workloads that auto-scale dynamically in cloud environments?
- Immutable infrastructure with security baked into the image pipeline (Correct answer)
- Manual security review of each new instance
- Applying security patches after each scale-out event
- Disabling auto-scaling to maintain a fixed number of instances
Correct answer: Immutable infrastructure with security baked into the image pipeline
Immutable infrastructure ensures every auto-scaled instance starts from a pre-hardened image, eliminating configuration drift and manual security gaps.
Question 138: Which log source is most valuable for detecting lateral movement within a Windows environment?
- DHCP server lease logs
- Windows Security Event logs (e.g., Event ID 4624, 4648) (Correct answer)
- Web server access logs
- DNS query logs from the perimeter firewall
Correct answer: Windows Security Event logs (e.g., Event ID 4624, 4648)
Windows Security Event logs capture authentication events (logon types, source IPs, account names) that are essential for detecting lateral movement via credential reuse or pass-the-hash.
Question 139: Which serverless security concern is unique compared to traditional VM-based workload protection?
- Ephemeral execution environment making persistent agent-based protection impractical (Correct answer)
- No support for IAM roles
- Inability to use encryption
- Lack of network connectivity
Correct answer: Ephemeral execution environment making persistent agent-based protection impractical
Serverless functions are ephemeral and short-lived, making traditional persistent agent-based security tools impractical for protection.
Question 140: A security team discovers that a cloud VM is exfiltrating data to an unknown IP address. What is the BEST immediate containment action?
- Terminate the VM immediately
- Reboot the VM to clear the malware
- Take a snapshot and continue monitoring
- Isolate the VM using security group rules to block outbound traffic (Correct answer)
Correct answer: Isolate the VM using security group rules to block outbound traffic
Isolating the VM via security group rules stops the exfiltration while preserving forensic evidence for investigation.
Question 141: Which firewall architecture uses a DMZ to host public-facing services while protecting the internal network?
- Host-based firewall
- Packet-filtering router
- Circuit-level gateway
- Three-legged firewall (Correct answer)
Correct answer: Three-legged firewall
A three-legged (screened subnet) firewall architecture creates a DMZ as a separate network segment between external and internal zones.
Question 142: Which IPsec mode encapsulates the entire original IP packet, including its header, making it suitable for site-to-site VPN tunnels?
- Transport mode
- Aggressive mode
- Tunnel mode (Correct answer)
- Main mode
Correct answer: Tunnel mode
Tunnel mode wraps the entire original IP packet in a new IP header, hiding internal addressing and making it ideal for gateway-to-gateway VPNs.
Question 143: A security analyst discovers that a colleague is exfiltrating customer data. The analyst reports this to management, but no action is taken. What is the MOST ethical next step?
- Confront the colleague directly
- Delete the exfiltrated data themselves
- Escalate to legal, compliance, or a regulatory authority (Correct answer)
- Ignore it since management has been informed
Correct answer: Escalate to legal, compliance, or a regulatory authority
When internal escalation fails, ethical duty requires reporting to appropriate external authorities such as legal counsel, compliance officers, or regulators.
Question 144: A security researcher discovers a zero-day vulnerability in a vendor's product. According to responsible disclosure ethics, what should they do FIRST?
- Notify the vendor privately and allow time to patch (Correct answer)
- Sell the exploit to the highest bidder
- Report it directly to law enforcement
- Publish full exploit details immediately to warn the public
Correct answer: Notify the vendor privately and allow time to patch
Responsible disclosure requires notifying the vendor first and providing reasonable time to develop and release a patch before any public disclosure.
Question 145: In the context of tls, pki & encryption standards, what role does continuous professional development play for CCP practitioners?
- It is optional and only needed for career advancement
- It serves primarily as a networking opportunity with no practical benefit
- It is required only during the first year of certification
- It ensures practitioners remain current with evolving standards, technologies, and best practices (Correct answer)
Correct answer: It ensures practitioners remain current with evolving standards, technologies, and best practices
Continuous professional development is essential in tls, pki & encryption standards because it ensures CCP practitioners remain current with evolving standards, technologies, and best practices, maintaining competency throughout their careers.
Question 146: What risk does 'shadow IT' pose to an organization's IAM program?
- Shadow IT only affects network performance, not IAM
- It reduces the load on the Identity Provider
- It increases the number of approved applications needing SSO
- Users accessing unsanctioned applications bypass IAM controls, creating ungoverned access and credential exposure (Correct answer)
Correct answer: Users accessing unsanctioned applications bypass IAM controls, creating ungoverned access and credential exposure
Shadow IT creates accounts and access outside of IT governance, meaning those accounts are not subject to deprovisioning, MFA enforcement, or access reviews.
Question 147: Which of the following is a fundamental principle of cve assessment & patch management as it applies to Certified Cybersecurity Professional?
- Relying solely on personal experience without reference to guidelines
- Avoiding documentation to streamline workflow efficiency
- Prioritizing speed of completion over accuracy and compliance
- Systematic evaluation and adherence to established industry standards (Correct answer)
Correct answer: Systematic evaluation and adherence to established industry standards
A fundamental principle of cve assessment & patch management in Certified Cybersecurity Professional is the systematic evaluation and adherence to established industry standards, which ensures consistency, quality, and regulatory compliance across all professional activities.
Question 148: What is 'lateral movement' in the context of a cloud workload breach?
- An attacker moving from one compromised workload to other systems within the environment (Correct answer)
- Migrating workloads between cloud regions
- Load balancing traffic across multiple availability zones
- Rotating credentials across multiple cloud accounts
Correct answer: An attacker moving from one compromised workload to other systems within the environment
Lateral movement occurs when an attacker uses a compromised workload as a pivot point to access other systems or data within the cloud environment.
Question 149: What artifact produced during risk management records identified risks along with their likelihood, impact, and treatment plans?
- Business Continuity Plan
- Incident Response Plan
- System Security Plan
- Risk Register (Correct answer)
Correct answer: Risk Register
A risk register is a living document that logs all identified risks, their ratings, and the actions planned or taken to address them.
Question 150: ISO 27001 requires organizations to set information security objectives. Which characteristic must these objectives have?
- They must be approved by external auditors
- They must align with international regulations only
- They must be measurable and monitored (Correct answer)
- They must be reviewed quarterly without exception
Correct answer: They must be measurable and monitored
Clause 6.2 requires information security objectives to be measurable (where practicable), monitored, communicated, and updated as appropriate.
Question 151: A security team discovers that an attacker has been silently collecting data for months. This is characteristic of which threat type?
- Advanced Persistent Threat (APT) (Correct answer)
- Ransomware
- Script Kiddie attack
- Denial of Service
Correct answer: Advanced Persistent Threat (APT)
An APT is a prolonged, stealthy attack where an adversary remains undetected while continuously exfiltrating data.
Question 152: Which of the following best describes the 'people' layer in a defense-in-depth model?
- Security awareness training and insider threat programs (Correct answer)
- Encryption keys and certificate management
- Antivirus software and patch management
- Firewalls and intrusion prevention systems
Correct answer: Security awareness training and insider threat programs
The people layer focuses on human controls such as security awareness training, policies, and insider threat programs to reduce human-related risk.
Question 153: When documenting activities related to network perimeter defense, which practice is considered essential for CCP certification holders?
- Keeping documentation in personal notes that are not accessible to other team members
- Recording only outcomes while omitting the methods and processes used
- Maintaining comprehensive records that include procedures, observations, results, and any anomalies (Correct answer)
- Completing documentation only when requested by auditors or supervisors
Correct answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in network perimeter defense. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
Question 154: What is 'defense in depth' as a cybersecurity strategy?
- Layering multiple security controls so that failure of one does not compromise the system (Correct answer)
- Encrypting data at all storage depths
- Deeply inspecting all network packets
- Using a single strong firewall to protect the network
Correct answer: Layering multiple security controls so that failure of one does not compromise the system
Defense in depth uses multiple overlapping security controls so an attacker must defeat several layers to succeed.
Question 155: What does multi-factor authentication (MFA) provide in terms of security?
- MFA is not used for network security.
- MFA is only applicable to mobile devices.
- MFA requires only one password for authentication.
- MFA requires two or more authentication methods for enhanced security. (Correct answer)
Correct answer: MFA requires two or more authentication methods for enhanced security.
Multi-factor authentication (MFA) significantly enhances security by requiring users to verify their identity using two or more distinct authentication methods. These methods typically come from different categories, such as something you know (password), something you have (token), and something you are (biometric). This layered approach makes it much harder for unauthorized individuals to gain access, even if one factor is compromised.
Question 156: Which organization is the primary CVE Numbering Authority (CNA) responsible for assigning CVE IDs to vulnerabilities in Microsoft products?
- NIST
- MITRE
- US-CERT
- Microsoft Corporation (Correct answer)
Correct answer: Microsoft Corporation
Microsoft is a CVE Numbering Authority (CNA) and assigns CVE IDs for vulnerabilities discovered in its own products, while MITRE oversees the overall CVE program.
Question 157: Which access control model assigns permissions based on user attributes and environmental conditions rather than predefined roles?
- Role-Based Access Control (RBAC)
- Discretionary Access Control (DAC)
- Mandatory Access Control (MAC)
- Attribute-Based Access Control (ABAC) (Correct answer)
Correct answer: Attribute-Based Access Control (ABAC)
ABAC evaluates policies against attributes of the user, resource, and environment (e.g., time, location) to make dynamic access decisions.
Question 158: An attacker intercepts communications between two parties without their knowledge. This is an example of what attack?
- Phishing
- Brute Force
- Man-in-the-Middle (MitM) (Correct answer)
- Denial of Service
Correct answer: Man-in-the-Middle (MitM)
A Man-in-the-Middle attack involves secretly intercepting and potentially altering communications between two parties.
Question 159: A company wants to prevent employees from uploading sensitive files to personal cloud storage services. Which perimeter control is MOST effective?
- SSL/TLS inspection combined with a data loss prevention (DLP) proxy (Correct answer)
- Deploying a host-based IDS on all endpoints
- DNS sinkholing for cloud storage domains
- Blocking all outbound port 80 traffic
Correct answer: SSL/TLS inspection combined with a data loss prevention (DLP) proxy
SSL/TLS inspection decrypts HTTPS traffic at the proxy, enabling DLP policies to inspect content and block unauthorized uploads to cloud storage.
Question 160: Which attack type exploits trust relationships between a user's browser and a website to perform unauthorized actions?
- Cross-Site Request Forgery (CSRF) (Correct answer)
- Buffer Overflow
- SQL Injection
- Man-in-the-Middle
Correct answer: Cross-Site Request Forgery (CSRF)
CSRF exploits the trust a web application has in an authenticated user's browser to perform unintended actions.
Question 161: Which NIST document provides a framework for improving critical infrastructure cybersecurity using a risk-based approach?
- NIST SP 800-53
- NIST SP 800-37
- NIST SP 800-171
- NIST Cybersecurity Framework (CSF) (Correct answer)
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) provides a risk-based approach organized around five core functions: Identify, Protect, Detect, Respond, and Recover.
Question 162: What is the PRIMARY advantage of using SOAR (Security Orchestration, Automation, and Response) during incident response?
- It automates repetitive tasks to reduce mean time to respond (Correct answer)
- It eliminates the need for human analysts in the SOC
- It provides real-time threat actor attribution
- It replaces the SIEM as the central event correlation engine
Correct answer: It automates repetitive tasks to reduce mean time to respond
SOAR platforms automate playbook steps like IOC enrichment, ticket creation, and initial containment actions, significantly reducing MTTR.
Question 163: What risk does applying a cumulative patch rollup introduce compared to individual patches?
- It may include previously deferred patches that were intentionally skipped due to compatibility concerns (Correct answer)
- It reduces the number of reboots required
- It eliminates the need for regression testing
- It always increases system performance
Correct answer: It may include previously deferred patches that were intentionally skipped due to compatibility concerns
Cumulative rollups bundle multiple patches together, which may force installation of previously excluded patches, potentially reintroducing compatibility issues that were carefully managed.
Question 164: Which CVSS v3.1 metric describes whether an attacker needs to be on the same network segment as the vulnerable component?
- Attack Vector: Adjacent (Correct answer)
- Attack Vector: Network
- Privileges Required: Low
- Attack Vector: Local
Correct answer: Attack Vector: Adjacent
The 'Adjacent' value for Attack Vector means the attacker must be on the same physical or logical network as the target, such as Bluetooth or a local subnet.
Question 165: A company implements VLAN segmentation, DMZ zones, and internal firewalls. Which defense-in-depth principle does this best represent?
- Least functionality
- Defense by obscurity
- Single point of enforcement
- Network segmentation and zoning (Correct answer)
Correct answer: Network segmentation and zoning
Network segmentation and zoning divides the network into isolated areas so a breach in one zone does not immediately compromise others.
Question 166: Which X.509 certificate field is used to specify permitted and excluded DNS name subtrees in a CA certificate to constrain which domains it may issue certificates for?
- Extended Key Usage
- Name Constraints (Correct answer)
- Key Usage
- Subject Alternative Name
Correct answer: Name Constraints
The Name Constraints extension (critical) restricts the namespaces within which an intermediate CA may issue certificates, preventing it from signing certificates for unauthorized domains.
Question 167: What is 'patch diffing' used for in a security context?
- Validating patch authenticity via hash comparison
- Tracking which patches have been applied to a system
- Comparing patched and unpatched binaries to reverse-engineer the underlying vulnerability (Correct answer)
- Measuring patch deployment speed
Correct answer: Comparing patched and unpatched binaries to reverse-engineer the underlying vulnerability
Patch diffing is a reverse-engineering technique where attackers or researchers compare pre- and post-patch binaries to identify what changed and reconstruct the exploitable flaw.
Question 168: A security team discovers that a vendor patch breaks a critical business application. What is the BEST immediate course of action?
- Apply compensating controls and document a risk acceptance while working with the vendor on a fix (Correct answer)
- Deploy the patch anyway and accept application downtime
- Wait indefinitely until the vendor resolves the incompatibility
- Roll back all patches immediately without documentation
Correct answer: Apply compensating controls and document a risk acceptance while working with the vendor on a fix
When a patch causes incompatibility, applying compensating controls (e.g., WAF rules, network segmentation) and formally accepting residual risk is the recommended risk management approach.
Question 169: Which control type in defense-in-depth is designed to minimize the impact of a security incident after it has occurred?
- Detective control
- Corrective control (Correct answer)
- Deterrent control
- Preventive control
Correct answer: Corrective control
Corrective controls, such as patch management and incident response procedures, reduce the damage after a security event has taken place.
Question 170: During an IR, the legal team requests a litigation hold. What is the IR team's IMMEDIATE obligation?
- Transfer all evidence to external legal counsel immediately
- Suspend normal log rotation and preserve all relevant data indefinitely until released (Correct answer)
- Accelerate evidence destruction per the normal retention schedule
- Anonymize personally identifiable information before handing to legal
Correct answer: Suspend normal log rotation and preserve all relevant data indefinitely until released
A litigation hold requires freezing evidence destruction processes and preserving all potentially relevant records to avoid spoliation claims.
Question 171: Which key derivation function does TLS 1.3 use to derive all symmetric keys from the shared secret?
- scrypt
- bcrypt
- HKDF (HMAC-based Key Derivation Function) (Correct answer)
- PBKDF2
Correct answer: HKDF (HMAC-based Key Derivation Function)
TLS 1.3 uses HKDF (RFC 5869) exclusively for deriving handshake keys, traffic keys, and resumption secrets from the ECDHE shared secret and transcript hash.
Question 172: ISO 27001 certification requires a Stage 1 and Stage 2 audit. What is primarily assessed during Stage 1?
- Documentation readiness and ISMS design (Correct answer)
- Operational effectiveness of all controls
- Physical security of data centers
- Employee security awareness scores
Correct answer: Documentation readiness and ISMS design
Stage 1 (document review) assesses whether the ISMS documentation is complete and the organization is ready for the full Stage 2 audit.
Question 173: A company enforces full-disk encryption on all laptops. If a laptop is stolen, which defense-in-depth outcome does this control achieve?
- Prevents the laptop from being powered on
- Protects data confidentiality even if physical security fails (Correct answer)
- Enables remote device tracking
- Ensures physical layer security is unnecessary
Correct answer: Protects data confidentiality even if physical security fails
Full-disk encryption protects data at the data layer so that theft (a physical control failure) does not result in data exposure to the unauthorized possessor.
Certified CMMC Professional (CCP)
The CCP validates foundational knowledge of the Cybersecurity Maturity Model Certification (CMMC) framework, covering ecosystem roles, governance, model implementation, assessment processes, and scoping for handling Federal Contract Information and Controlled Unclassified Information.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong β answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds