โ† All CCP Flashcard Decks

Governance, Compliance & Ethical Hacking Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Governance, Compliance & Ethical Hacking flashcards as text
  1. A penetration tester successfully gains a foothold on a system and then uses that access to move to other internal systems. This technique is known as:

    Answer: Pivoting

    Pivoting uses a compromised host as a relay point to attack other systems on the internal network that are not directly accessible from the attacker's machine.

  2. Under the Health Insurance Portability and Accountability Act (HIPAA), which rule specifically addresses the security of electronic Protected Health Information (ePHI)?

    Answer: Security Rule

    The HIPAA Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of ePHI.

  3. An organization's risk register shows a vulnerability with high likelihood and high impact. After implementing compensating controls, the residual risk is documented as 'accepted.' This represents which risk treatment option?

    Answer: Risk acceptance

    Risk acceptance occurs when an organization consciously decides to accept the residual risk after controls are applied, because the cost of further mitigation exceeds the potential impact.

  4. Which ethical hacking methodology phase involves maintaining access to a compromised system by installing backdoors or rootkits?

    Answer: Maintaining access

    The maintaining access phase involves installing tools like backdoors, rootkits, or scheduled tasks to ensure the attacker can re-enter the system even if the initial vulnerability is patched.

  5. Which of the following BEST describes the difference between a vulnerability assessment and a penetration test?

    Answer: A vulnerability assessment identifies weaknesses; a penetration test actively exploits them to demonstrate impact

    A vulnerability assessment identifies and prioritizes potential weaknesses, while a penetration test goes further by actively exploiting vulnerabilities to demonstrate real-world attack impact and risk.

  6. The Sarbanes-Oxley Act (SOX) Section 404 is MOST relevant to cybersecurity because it requires:

    Answer: Management assessment and external audit of internal controls over financial reporting, including IT controls

    SOX Section 404 requires management and external auditors to assess the effectiveness of internal controls over financial reporting, which directly includes IT general controls such as access management and change control.

  7. A security team implements a policy requiring that all administrative access to production servers uses jump servers with session recording. This PRIMARILY addresses which security concern?

    Answer: Providing auditability and accountability for privileged access

    Jump servers with session recording create an auditable trail of all privileged actions, supporting accountability, forensic investigation, and compliance with least-privilege and separation of duties principles.