Mixed Deck — All CCP Topics Flashcards
100 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CCP Topics flashcards as text
What is the function of a Registration Authority (RA) within a PKI hierarchy?
Answer: To validate the identity of certificate requestors and forward approved requests to the CA for issuance
An RA performs identity vetting and approves or rejects certificate requests, offloading validation tasks from the CA while the CA retains signing authority.
Which metric is MOST useful for evaluating IDS tuning effectiveness over time?
Answer: False positive rate and mean time to detect (MTTD)
False positive rate and MTTD together measure both accuracy and speed of detection, making them the best indicators of tuning effectiveness.
What is a 'false positive' in vulnerability scanning?
Answer: A scan result that reports a vulnerability that does not actually exist on the target
A false positive occurs when a vulnerability scanner incorrectly reports a vulnerability that does not actually exist on the scanned system, requiring manual validation to filter out inaccurate findings.
An analyst notices that a threat actor's TTPs closely match MITRE ATT&CK technique T1566 (Phishing). In which CTI lifecycle phase would this technique mapping most likely occur?
Answer: Analysis
Mapping observed behaviors to ATT&CK techniques is an analytical task performed during the Analysis phase to contextualize adversary actions.
What is the primary difference between symmetric and asymmetric encryption?
Answer: Symmetric uses one key for encryption and decryption; asymmetric uses a public/private key pair
Symmetric encryption uses a single shared secret key for both encryption and decryption, while asymmetric encryption uses a mathematically linked key pair — one public, one private.
Which tool is most commonly used for automated network vulnerability scanning in enterprise environments?
Answer: Nessus
Nessus (by Tenable) is the industry-standard automated vulnerability scanner used to detect misconfigurations, missing patches, and known CVEs across network hosts.
When building a phishing playbook, which enrichment action adds the most contextual value to a suspicious URL before escalation?
Answer: Checking the URL against a threat intelligence reputation feed
Querying reputation feeds provides categorization, maliciousness scores, and historical context that inform whether the URL warrants escalation.
What is the primary purpose of a Cloud Workload Protection Platform (CWPP)?
Answer: Secure compute workloads (VMs, containers, serverless) against runtime threats and vulnerabilities
CWPP solutions protect cloud workloads at runtime by providing vulnerability scanning, threat detection, and behavioral monitoring for VMs, containers, and serverless functions.
Under NIST CSF's 'Respond' function, which category focuses on executing a response plan and coordinating with stakeholders during an incident?
Answer: Communications
The 'Communications' category ensures that response activities are coordinated with internal and external stakeholders, including law enforcement and media as appropriate.
A SOC analyst observes a spike in outbound traffic to multiple external IPs on port 443 late at night. What threat scenario should be prioritized?
Answer: Beaconing behavior associated with malware C2 communication
Regular outbound connections to many external IPs on port 443 during off-hours is characteristic of malware beaconing to command-and-control infrastructure.
Which quality assurance method is most commonly applied in nist csf & cis controls to verify that CCP professional standards are being met?
Answer: Structured audits, peer reviews, and performance metrics aligned with industry benchmarks
Structured audits, peer reviews, and performance metrics aligned with industry benchmarks are the most effective quality assurance methods in nist csf & cis controls, providing objective, measurable evidence that CCP standards are consistently met.
In FAIR methodology, 'Threat Capability' is compared against 'Resistance Strength' to estimate:
Answer: Vulnerability (probability of control failure)
In FAIR, vulnerability is the probability that a threat actor's capability will overcome the resistance strength of controls.
When documenting activities related to soc operations & alert triage, which practice is considered essential for CCP certification holders?
Answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in soc operations & alert triage. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
What is the primary ethical obligation of a CCP professional when a conflict of interest arises during cyber threat intelligence lifecycle activities?
Answer: Disclose the conflict to all relevant parties and recuse from the decision if necessary
The primary ethical obligation when a conflict of interest arises in cyber threat intelligence lifecycle is to disclose it to all relevant parties and, if necessary, recuse from the decision. This maintains professional integrity and stakeholder trust.
Which feedback mechanism in the CTI lifecycle ensures intelligence products remain aligned with stakeholder needs over time?
Answer: Post-dissemination feedback loops
Post-dissemination feedback loops allow consumers to evaluate the intelligence's relevance and accuracy, informing future Direction phase decisions.
What is 'loss exceedance probability' (LEP) and how is it used in cyber risk quantification?
Answer: A curve showing the probability that losses will exceed various threshold amounts
A loss exceedance curve plots probability on one axis against loss amounts on the other, showing the chance losses surpass any given threshold.
Which IDS/IPS evasion technique involves splitting malicious payload across multiple TCP segments to avoid signature matching?
Answer: Fragmentation and session splicing
Session splicing breaks a payload across multiple small TCP segments, exploiting IDS systems that do not reassemble streams before pattern matching.
What protocol is most commonly used to enable Single Sign-On (SSO) across web applications using token-based assertions?
Answer: SAML 2.0
SAML 2.0 (Security Assertion Markup Language) is the predominant standard for SSO, exchanging XML-based authentication and authorization assertions between identity providers and service providers.
What security mechanism does DNSSEC provide to protect DNS infrastructure?
Answer: Digitally signs DNS records to verify their authenticity and integrity
DNSSEC uses digital signatures to cryptographically verify the authenticity and integrity of DNS records, protecting against cache poisoning and spoofing.
What is the purpose of the CVE (Common Vulnerabilities and Exposures) system?
Answer: To provide a publicly available catalog of known cybersecurity vulnerabilities with unique identifiers
CVE provides a standardized list of publicly disclosed cybersecurity vulnerabilities, each assigned a unique identifier (e.g., CVE-2021-44228), enabling consistent communication across tools, vendors, and security teams.