โ† All CCP Flashcard Decks

Cybersecurity Principles & Risk Management Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cybersecurity Principles & Risk Management flashcards as text
  1. What is the primary goal of threat modeling during the software development lifecycle?

    Answer: Identify and prioritize potential threats to a system before they are exploited

    Threat modeling systematically identifies assets, potential threats, and vulnerabilities early in the SDLC so that security controls can be built in rather than bolted on.

  2. An organization's security policy requires that all sensitive data be encrypted at rest. Which security principle does this MOST directly support?

    Answer: Confidentiality

    Encrypting data at rest protects its confidentiality by ensuring unauthorized parties cannot read the data even if physical storage media is accessed.

  3. Which risk scenario is BEST addressed by implementing multi-factor authentication (MFA)?

    Answer: Unauthorized account access using stolen credentials

    MFA requires a second verification factor beyond a password, ensuring that stolen credentials alone are insufficient for an attacker to gain account access.

  4. What does the term 'defense in depth' mean in cybersecurity?

    Answer: Layering multiple security controls so that failure of one does not compromise overall security

    Defense in depth employs multiple overlapping security layers so that if one control fails or is bypassed, additional controls continue to protect the system.

  5. Which of the following is an example of a supply chain risk in cybersecurity?

    Answer: Malicious code inserted into a third-party software library used by the organization

    Supply chain attacks compromise third-party software, hardware, or services that an organization depends on, as seen in incidents like the SolarWinds attack.

  6. A CISO is presenting risk information to the board of directors. Which format is MOST appropriate for communicating residual risk?

    Answer: A risk register with business impact descriptions and residual risk ratings

    A risk register presented with business-context impact descriptions and residual risk ratings communicates risk in terms that executive stakeholders can understand and act upon.

  7. What is the purpose of a risk register in an information security program?

    Answer: Document identified risks, their owners, likelihood, impact, and treatment status

    A risk register is a centralized document that tracks identified risks along with their assessed likelihood, impact, assigned owner, and current treatment or mitigation status.