Mixed Deck — All CCP Topics Flashcards
100 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CCP Topics flashcards as text
A security team discovers that a vendor patch breaks a critical business application. What is the BEST immediate course of action?
Answer: Apply compensating controls and document a risk acceptance while working with the vendor on a fix
When a patch causes incompatibility, applying compensating controls (e.g., WAF rules, network segmentation) and formally accepting residual risk is the recommended risk management approach.
Which privacy and security concept calls for limiting the collection and retention of personal data to only what is necessary?
Answer: Data minimization
Data minimization restricts the collection and storage of personal data to only what is necessary for a defined purpose, reducing exposure risk.
What does Certificate Transparency (CT) primarily protect against?
Answer: Misissued or fraudulent certificates that CAs issue without domain owner knowledge
CT requires CAs to log all issued certificates to public append-only logs, enabling domain owners and monitors to detect unauthorized or misissued certificates quickly.
Which type of attack is specifically designed to exhaust firewall connection table resources?
Answer: SYN flood
A SYN flood sends a high volume of TCP SYN packets without completing the handshake, filling the firewall's connection state table and denying service to legitimate users.
Which Zero Trust principle requires that all network traffic be verified regardless of whether it originates inside or outside the corporate perimeter?
Answer: Never trust, always verify
The Zero Trust principle of 'never trust, always verify' eliminates implicit trust based on network location, requiring continuous verification of all connections.
A cloud service provider wants ISO 27001 certification. Which additional ISO standard specifically extends 27001 for cloud security?
Answer: ISO 27017
ISO/IEC 27017 provides guidelines for information security controls applicable to the provision and use of cloud services, extending ISO 27001.
Which quality assurance method is most commonly applied in tls, pki & encryption standards to verify that CCP professional standards are being met?
Answer: Structured audits, peer reviews, and performance metrics aligned with industry benchmarks
Structured audits, peer reviews, and performance metrics aligned with industry benchmarks are the most effective quality assurance methods in tls, pki & encryption standards, providing objective, measurable evidence that CCP standards are consistently met.
Under the NIST SP 800-40 guidance on patch management, what is the recommended maximum timeframe to patch critical vulnerabilities in internet-facing systems?
Answer: Within days to a few weeks, depending on risk
NIST SP 800-40 recommends patching critical vulnerabilities in exposed systems as quickly as possible, typically within days to weeks, based on assessed risk.
A network engineer implements 802.1X on switch ports. Which component acts as the intermediary that forwards authentication requests to the authentication server?
Answer: Authenticator
In 802.1X, the authenticator (switch or AP) passes credentials from the supplicant (client) to the authentication server (RADIUS) without processing them.
A security engineer wants to prevent a compromised container from accessing the EC2 instance metadata service. What is the MOST effective control?
Answer: Block the metadata endpoint (169.254.169.254) using iptables rules or IMDSv2 enforcement
Blocking access to the metadata service endpoint prevents containers from retrieving instance credentials that could be used for further attacks.
A company maps its controls to both NIST CSF and ISO 27001. Which NIST CSF function aligns most closely with ISO 27001's risk treatment process?
Answer: Protect
The Protect function, which implements safeguards to ensure delivery of services, most closely maps to ISO 27001's risk treatment where controls are selected and implemented.
An attacker intercepts communications between two parties without their knowledge. This is an example of what attack?
Answer: Man-in-the-Middle (MitM)
A Man-in-the-Middle attack involves secretly intercepting and potentially altering communications between two parties.
In a federated identity model, what role does the Identity Provider (IdP) play?
Answer: It authenticates users and issues tokens that Service Providers trust
The IdP authenticates users and issues assertions or tokens (e.g., SAML assertions, JWTs) that Service Providers accept as proof of authentication.
In the NIST Risk Management Framework (RMF), which step involves choosing appropriate security controls?
Answer: Select
The Select step in NIST RMF involves choosing security controls tailored to the system's risk categorization.
Which Kerberos component issues Ticket Granting Tickets (TGTs) after verifying user credentials?
Answer: Key Distribution Center – Authentication Service (KDC-AS)
The Authentication Service (AS) component of the KDC verifies the user's credentials and issues a TGT, which is then used to request service tickets from the TGS.
Which approach best addresses the security challenge of workloads that auto-scale dynamically in cloud environments?
Answer: Immutable infrastructure with security baked into the image pipeline
Immutable infrastructure ensures every auto-scaled instance starts from a pre-hardened image, eliminating configuration drift and manual security gaps.
What does the MITRE ATT&CK technique T1055 (Process Injection) help an attacker achieve?
Answer: Evading defenses and escalating privileges by running code within the context of another process
Process injection allows attackers to execute malicious code within the memory space of a legitimate process, inheriting its privileges and evading process-based security controls.
Which cipher suite component in TLS 1.2 provides forward secrecy?
Answer: Ephemeral Diffie-Hellman (DHE or ECDHE)
Ephemeral Diffie-Hellman key exchange generates a new key pair per session, so compromising the server's long-term key cannot decrypt previously captured traffic.
Which API security best practice prevents attackers from enumerating all resources by exploiting predictable identifiers?
Answer: Implementing rate limiting and randomized resource identifiers
Rate limiting prevents automated enumeration, and randomized (non-sequential) identifiers make it impractical to guess valid resource IDs.
Which step in the NIST RMF involves determining if the controls implemented are effective?
Answer: Assess
The Assess step (Step 4) evaluates whether security and privacy controls are implemented correctly, operating as intended, and producing desired outcomes.