Cybersecurity Principles & Risk Management Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cybersecurity Principles & Risk Management flashcards as text
Which attack exploits the trust relationship between a user's browser and a web application to perform unauthorized actions on behalf of an authenticated user?
Answer: Cross-Site Request Forgery (CSRF)
CSRF tricks an authenticated user's browser into sending forged requests to a web application, exploiting the session trust already established.
An organization applies the principle of least privilege. What does this mean in practice?
Answer: Users are granted only the minimum access required to perform their job functions
Least privilege limits user and system access rights to only what is strictly necessary, reducing the attack surface and potential damage from compromised accounts.
What is the purpose of a Disaster Recovery Plan (DRP)?
Answer: Restore IT systems and operations after a disruptive event
A DRP outlines procedures for recovering IT infrastructure, systems, and data following a disaster or major disruption to restore normal operations.
Which type of control is designed to DISCOVER security incidents after they have occurred?
Answer: Detective control
Detective controls, such as intrusion detection systems and log monitoring, identify and alert on security events after they have taken place.
A security analyst calculates that a vulnerability has a CVSS base score of 9.8. How should this be prioritized?
Answer: Critical priority — remediate immediately or apply compensating controls
A CVSS score of 9.8 falls in the Critical range (9.0–10.0), requiring immediate remediation or compensating controls due to high exploitability and impact.
Which term describes an attack that takes advantage of a software vulnerability before the vendor has released a patch?
Answer: Zero-day exploit
A zero-day exploit targets a previously unknown vulnerability for which no official patch exists, giving defenders zero days of advance warning.
Which document defines the security requirements and expectations between a service provider and a customer?
Answer: Service Level Agreement (SLA)
An SLA is a contract specifying the expected service levels, including security requirements, responsibilities, and remedies if those levels are not met.