Governance, Compliance & Ethical Hacking Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Governance, Compliance & Ethical Hacking flashcards as text
An ethical hacker performs reconnaissance by analyzing publicly available DNS records, WHOIS data, and social media profiles without interacting with the target's systems. This technique is called:
Answer: Passive reconnaissance
Passive reconnaissance (also called OSINT gathering) collects information about a target using publicly available sources without directly interacting with or alerting the target.
Which of the following BEST describes the concept of 'due diligence' in cybersecurity governance?
Answer: Proactively researching and understanding risks before making security decisions
Due diligence in cybersecurity means actively researching threats, assessing risks, and evaluating controls before making decisions, whereas due care is the implementation of those measures.
A penetration tester uses a tool to automatically scan open ports and identify running services on target hosts. Which phase of the ethical hacking methodology does this represent?
Answer: Scanning and enumeration
Scanning and enumeration involves using tools like Nmap to discover open ports, running services, OS versions, and network topology to build an attack surface map.
Under GDPR, what is the maximum timeframe within which a data breach affecting EU residents must be reported to the relevant supervisory authority?
Answer: 72 hours
GDPR Article 33 requires organizations to notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, where feasible.
Which security governance model separates the duties of those who develop systems from those who deploy them to prevent fraud and errors?
Answer: Separation of duties
Separation of duties (SoD) ensures no single individual controls all steps of a critical process, reducing the risk of fraud, sabotage, or error.
A company hires a third-party firm to perform a red team exercise. Unlike a standard penetration test, red team exercises are BEST characterized by:
Answer: Simulating realistic adversary tactics, techniques, and procedures (TTPs) to test detection and response
Red team exercises simulate real-world adversaries using actual TTPs to evaluate the effectiveness of an organization's detection, response, and defensive capabilities holistically.
ISO/IEC 27001 is an international standard that specifies requirements for establishing, implementing, maintaining, and continually improving a(n):
Answer: Information Security Management System (ISMS)
ISO/IEC 27001 defines requirements for an Information Security Management System (ISMS), a systematic approach to managing sensitive information using risk management processes.