Governance, Compliance & Ethical Hacking Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Governance, Compliance & Ethical Hacking flashcards as text
Which law requires US federal agencies and their contractors to implement specific security controls for protecting Controlled Unclassified Information (CUI) in non-federal systems?
Answer: NIST SP 800-171 / CMMC
NIST SP 800-171 and its enforcement mechanism CMMC (Cybersecurity Maturity Model Certification) mandate controls for DoD contractors handling Controlled Unclassified Information.
During a web application penetration test, a tester injects `' OR '1'='1` into a login field and gains unauthorized access. This exploits which vulnerability?
Answer: SQL Injection
The classic `' OR '1'='1` payload is a SQL injection technique that manipulates the SQL query logic to bypass authentication by making the WHERE clause always evaluate to true.
A Chief Information Security Officer (CISO) reports directly to the CEO and Board of Directors. This reporting structure BEST supports which governance principle?
Answer: Security independence and board-level accountability
Having the CISO report to the CEO or board ensures security has executive visibility and authority, avoids conflicts of interest with IT, and establishes board-level accountability for cyber risk.
Which ethical hacking technique involves sending a carefully crafted email to an employee, impersonating a trusted entity, to capture their credentials?
Answer: Spear phishing
Spear phishing is a targeted form of phishing that uses personalized messages impersonating trusted individuals or organizations to trick specific victims into revealing credentials or installing malware.
The concept of 'privacy by design' requires that privacy protections be:
Answer: Embedded into system design and architecture from the outset
Privacy by design (PbD) mandates that privacy controls and data minimization principles are built into systems and processes proactively from the design phase, not bolted on afterward.
In a penetration test report, a finding is rated 'Critical' with a CVSS score of 9.8. This score is derived from which scoring system?
Answer: Common Vulnerability Scoring System (CVSS)
CVSS (Common Vulnerability Scoring System) is the industry-standard scoring system that rates vulnerability severity on a 0–10 scale based on exploitability, scope, and impact metrics.
Which governance document provides step-by-step instructions for implementing a specific security control, such as configuring multi-factor authentication on a VPN?
Answer: Security procedure
A security procedure provides detailed, step-by-step instructions for performing a specific task, sitting below policies (what must be done) and standards (how well it must be done) in the governance hierarchy.