Certified CMMC Professional (CCP) — Questions and Answers
Question 1: What is the security advantage of deploying both signature-based and behavior-based detection in an endpoint security solution?
- It replaces the need for user training
- It eliminates the need for network firewalls
- It reduces false positives to zero
- It provides complementary detection so known and unknown threats are both covered (Correct answer)
Correct answer: It provides complementary detection so known and unknown threats are both covered
Combining signature-based and behavior-based detection creates defense-in-depth at the endpoint, covering known malware and novel or zero-day attacks.
Question 2: In patch management, what is the primary purpose of maintaining a Software Bill of Materials (SBOM)?
- To enable rapid identification of which systems are affected when a CVE is published for a specific component (Correct answer)
- To store CVSS scores for installed software
- To document the patch deployment schedule
- To track software license costs across the organization
Correct answer: To enable rapid identification of which systems are affected when a CVE is published for a specific component
An SBOM catalogs all software components and dependencies in an application, enabling security teams to quickly identify exposure when a new CVE targets a specific library or component.
Question 3: When documenting activities related to cve assessment & patch management, which practice is considered essential for CCP certification holders?
- Completing documentation only when requested by auditors or supervisors
- Maintaining comprehensive records that include procedures, observations, results, and any anomalies (Correct answer)
- Recording only outcomes while omitting the methods and processes used
- Keeping documentation in personal notes that are not accessible to other team members
Correct answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in cve assessment & patch management. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
Question 4: What is the primary purpose of a network access control (NAC) solution at the perimeter?
- Block all inbound connections from untrusted networks
- Enforce endpoint health checks before granting network access (Correct answer)
- Encrypt all traffic between network segments
- Manage firewall rule sets across multiple devices
Correct answer: Enforce endpoint health checks before granting network access
NAC enforces posture assessment (patch level, AV status, etc.) on endpoints before allowing them onto the network.
Question 5: A security analyst notices a cloud function is making unexpected outbound connections to a cryptocurrency mining pool. This is an example of which threat?
- Denial of Service
- Ransomware
- Data exfiltration
- Cryptojacking (Correct answer)
Correct answer: Cryptojacking
Cryptojacking involves attackers hijacking cloud compute resources to mine cryptocurrency, often resulting in unexpected outbound connections to mining pools.
Question 6: An organization requires that all outbound web traffic be inspected for data exfiltration. Which perimeter control BEST fulfills this requirement?
- Network-based IDS in passive mode
- Split DNS configuration
- Egress filtering with a secure web gateway (SWG) (Correct answer)
- Inbound web application firewall (WAF)
Correct answer: Egress filtering with a secure web gateway (SWG)
A secure web gateway with egress filtering inspects and controls outbound HTTP/HTTPS traffic, enabling DLP and content inspection.
Question 7: In the context of tls, pki & encryption standards, what role does continuous professional development play for CCP practitioners?
- It is required only during the first year of certification
- It ensures practitioners remain current with evolving standards, technologies, and best practices (Correct answer)
- It serves primarily as a networking opportunity with no practical benefit
- It is optional and only needed for career advancement
Correct answer: It ensures practitioners remain current with evolving standards, technologies, and best practices
Continuous professional development is essential in tls, pki & encryption standards because it ensures CCP practitioners remain current with evolving standards, technologies, and best practices, maintaining competency throughout their careers.
Question 8: What does a high false negative rate in a SIEM indicate?
- The SIEM is missing real attacks that should have been detected (Correct answer)
- The SIEM is generating too many irrelevant alerts
- The SIEM log collection is duplicating events
- The SIEM correlation rules are overly sensitive
Correct answer: The SIEM is missing real attacks that should have been detected
A high false negative rate means the system fails to alert on actual malicious activity, leaving real threats undetected — a critical gap in security coverage.
Question 9: During a threat hunt, an analyst searches for processes making DNS queries to randomly generated domain names. What threat does this technique help identify?
- ARP poisoning attacks
- Man-in-the-middle SSL stripping
- SQL injection attacks
- Domain Generation Algorithm (DGA) malware (Correct answer)
Correct answer: Domain Generation Algorithm (DGA) malware
Domain Generation Algorithms (DGAs) are used by malware to generate many pseudo-random domain names as potential C2 contact points, making them hard to blacklist.
Question 10: What is the primary purpose of a threat intelligence feed in an IR workflow?
- To generate compliance reports for auditors
- To enrich IOCs with known adversary TTPs for faster triage (Correct answer)
- To replace manual log review in the SOC
- To automate patch deployment on vulnerable systems
Correct answer: To enrich IOCs with known adversary TTPs for faster triage
Threat intelligence feeds provide context such as known malicious IPs, hashes, and TTPs that help analysts quickly assess severity and attribution.
Question 11: Which NVD data field provides a standardized list of weakness types associated with a CVE, helping analysts understand root causes?
- CPE (Common Platform Enumeration)
- CWE (Common Weakness Enumeration) (Correct answer)
- CAPEC ID
- CVSS Base Score
Correct answer: CWE (Common Weakness Enumeration)
CWE entries linked to a CVE describe the underlying software weakness category (e.g., CWE-79 for XSS), aiding root-cause analysis and remediation prioritization.
Question 12: When performing a NIST-based risk assessment, which document specifically guides the risk assessment process?
- NIST SP 800-37
- NIST SP 800-53A
- NIST SP 800-30 (Correct answer)
- NIST SP 800-137
Correct answer: NIST SP 800-30
NIST SP 800-30 (Guide for Conducting Risk Assessments) provides the process for conducting risk assessments of federal information systems.
Question 13: Which of the following is a fundamental principle of defense-in-depth architecture as it applies to Certified Cybersecurity Professional?
- Relying solely on personal experience without reference to guidelines
- Systematic evaluation and adherence to established industry standards (Correct answer)
- Avoiding documentation to streamline workflow efficiency
- Prioritizing speed of completion over accuracy and compliance
Correct answer: Systematic evaluation and adherence to established industry standards
A fundamental principle of defense-in-depth architecture in Certified Cybersecurity Professional is the systematic evaluation and adherence to established industry standards, which ensures consistency, quality, and regulatory compliance across all professional activities.
Question 14: What is the primary function of threat intelligence feeds integrated into a SIEM?
- To automatically patch vulnerable systems
- To provide indicators of compromise (IOCs) for matching against collected log data (Correct answer)
- To encrypt sensitive log data during transmission
- To train machine learning models for anomaly detection
Correct answer: To provide indicators of compromise (IOCs) for matching against collected log data
Threat intelligence feeds supply known malicious IOCs (IPs, domains, file hashes) that the SIEM matches against ingested logs to identify connections to known threat actors.
Question 15: Risk appetite is best described as:
- The total number of active threat agents an organization faces
- The maximum risk that would cause organizational bankruptcy
- The amount of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The residual risk remaining after all controls are applied
Correct answer: The amount of risk an organization is willing to accept in pursuit of its objectives
Risk appetite defines the level of risk an organization consciously accepts while pursuing its strategic and operational goals.
Question 16: An organization uses data classification, DLP tools, and encryption to protect sensitive files. Which defense-in-depth layer is being addressed?
- Data layer (Correct answer)
- Application layer
- Physical layer
- Network layer
Correct answer: Data layer
Data layer controls protect information itself through classification, encryption, and loss prevention regardless of the transport path.
Question 17: A security engineer needs to ensure that a set of TLS certificates cannot be misused after their private keys are stolen, even retroactively for past captured traffic. Which property addresses this?
- Extended validation certificates
- Online Certificate Status Protocol
- Certificate transparency logging
- Perfect Forward Secrecy (PFS) (Correct answer)
Correct answer: Perfect Forward Secrecy (PFS)
PFS, achieved via ephemeral key exchange (ECDHE/DHE), ensures that session keys are not derivable from the server's long-term private key, protecting past sessions even if that key is later compromised.
Question 18: What is the role of a reverse proxy in perimeter defense?
- It provides VPN connectivity for remote users
- It sits in front of internal servers and forwards external client requests to them (Correct answer)
- It encrypts traffic between two internal network segments
- It routes outbound client requests to external servers anonymously
Correct answer: It sits in front of internal servers and forwards external client requests to them
A reverse proxy accepts inbound connections on behalf of backend servers, hiding internal server details and enabling inspection or load balancing.
Question 19: What does UEBA (User and Entity Behavior Analytics) add to traditional SIEM capabilities?
- Improved network packet capture and deep inspection
- Machine learning-based profiling of user and device behavior to detect insider threats and compromised accounts (Correct answer)
- Faster log ingestion and parsing
- Automated vulnerability scanning and patch management
Correct answer: Machine learning-based profiling of user and device behavior to detect insider threats and compromised accounts
UEBA uses machine learning to build behavioral profiles of users and entities, detecting anomalies like unusual access times, data exfiltration patterns, or impossible travel scenarios.
Question 20: What is the primary purpose of a Business Impact Analysis (BIA)?
- To determine critical business functions and their recovery priorities (Correct answer)
- To identify all network vulnerabilities
- To calculate the total cost of security controls
- To assess employee cybersecurity awareness levels
Correct answer: To determine critical business functions and their recovery priorities
A BIA identifies critical business functions, their dependencies, and the impact of disruptions to guide recovery prioritization.
Question 21: Which concept describes the ability to verify that a specific user performed a specific action, preventing them from later denying it?
- Non-repudiation (Correct answer)
- Integrity
- Availability
- Confidentiality
Correct answer: Non-repudiation
Non-repudiation uses mechanisms like digital signatures and audit logs to ensure a user cannot deny having performed an action.
Question 22: Which component of the Common Platform Enumeration (CPE) naming scheme identifies the specific version of an affected product?
- The CWE identifier linked to the CVE
- The CVSS Attack Vector field
- The version field in the CPE URI, e.g., cpe:/a:vendor:product:version (Correct answer)
- The CVE reference in the NVD entry
Correct answer: The version field in the CPE URI, e.g., cpe:/a:vendor:product:version
CPE URIs include a version field that specifies the exact product version affected, enabling precise matching of CVEs to installed software inventories.
Question 23: Which type of risk assessment assigns numerical probabilities and financial values to risk outcomes?
- Qualitative
- Hybrid
- Quantitative (Correct answer)
- Subjective
Correct answer: Quantitative
Quantitative risk assessments use numerical data and monetary metrics to express risk in measurable financial terms.
Question 24: A CCP professional encounters an unfamiliar situation while performing cloud workload protection duties. What is the most appropriate first action?
- Consult relevant standards, guidelines, or a qualified supervisor before proceeding (Correct answer)
- Apply a solution from an unrelated field without verification
- Skip the task entirely and move to the next assignment
- Proceed based on general assumptions to avoid delays
Correct answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in cloud workload protection, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Question 25: Which SIEM component is responsible for normalizing log data from disparate sources into a common format?
- Threat intelligence feed
- Event correlation engine
- Data normalization parser (Correct answer)
- Log aggregator
Correct answer: Data normalization parser
Data normalization parsers translate raw logs from different formats (syslog, Windows Event Log, JSON) into a unified schema for consistent analysis.
Question 26: Which Kerberos component issues Ticket Granting Tickets (TGTs) after verifying user credentials?
- Key Distribution Center – Authentication Service (KDC-AS) (Correct answer)
- Ticket Granting Service (TGS)
- Resource Server
- Service Principal
Correct answer: Key Distribution Center – Authentication Service (KDC-AS)
The Authentication Service (AS) component of the KDC verifies the user's credentials and issues a TGT, which is then used to request service tickets from the TGS.
Question 27: Which process systematically identifies, documents, and prioritizes risks to organizational assets?
- Risk assessment (Correct answer)
- Incident response
- Penetration testing
- Vulnerability scanning
Correct answer: Risk assessment
Risk assessment is the structured process of identifying threats and vulnerabilities, then evaluating their likelihood and impact to prioritize treatment.
Question 28: Which OpenID Connect component provides verifiable claims about the authenticated user to the client application?
- Refresh token
- Authorization code
- Access token
- ID token (Correct answer)
Correct answer: ID token
The ID token is a JWT issued by the OpenID Provider containing claims about the authenticated user (e.g., sub, email) that the client can verify.
Question 29: An organization's SIEM detects an internal host communicating with a known Tor exit node. What is the most likely security concern?
- The host is running a legitimate privacy-preserving web browser for research
- The host is being used as a Tor relay to support internet freedom
- A misconfigured proxy is routing corporate traffic through Tor unintentionally
- Data exfiltration or C2 communication being tunneled through Tor to evade detection (Correct answer)
Correct answer: Data exfiltration or C2 communication being tunneled through Tor to evade detection
Internal systems communicating with Tor exit nodes most commonly indicate malware using Tor for anonymous C2 communications or an insider exfiltrating data through an anonymization network.
Question 30: An employee uses company resources to run a personal cryptocurrency mining operation. Which ethical violation has primarily occurred?
- Unauthorized use of resources (Correct answer)
- Failure to report a security incident
- Breach of confidentiality
- Violation of need-to-know principle
Correct answer: Unauthorized use of resources
Using organizational resources for personal financial gain without authorization violates the ethical obligation to use employer resources only for authorized purposes.
Question 31: In the NIST Risk Management Framework (RMF), which step involves choosing appropriate security controls?
- Select (Correct answer)
- Categorize
- Implement
- Assess
Correct answer: Select
The Select step in NIST RMF involves choosing security controls tailored to the system's risk categorization.
Question 32: A security researcher discovers a zero-day vulnerability in a vendor's product. According to responsible disclosure ethics, what should they do FIRST?
- Sell the exploit to the highest bidder
- Notify the vendor privately and allow time to patch (Correct answer)
- Report it directly to law enforcement
- Publish full exploit details immediately to warn the public
Correct answer: Notify the vendor privately and allow time to patch
Responsible disclosure requires notifying the vendor first and providing reasonable time to develop and release a patch before any public disclosure.
Question 33: Which tool category is MOST appropriate for correlating events across multiple log sources to detect multi-stage attacks?
- PAM (Privileged Access Management)
- SIEM (Security Information and Event Management) (Correct answer)
- DLP (Data Loss Prevention)
- Vulnerability scanner
Correct answer: SIEM (Security Information and Event Management)
A SIEM aggregates and correlates log data from diverse sources, enabling detection of attack patterns that span multiple systems and time windows.
Question 34: A security team discovers that a vendor patch breaks a critical business application. What is the BEST immediate course of action?
- Roll back all patches immediately without documentation
- Apply compensating controls and document a risk acceptance while working with the vendor on a fix (Correct answer)
- Deploy the patch anyway and accept application downtime
- Wait indefinitely until the vendor resolves the incompatibility
Correct answer: Apply compensating controls and document a risk acceptance while working with the vendor on a fix
When a patch causes incompatibility, applying compensating controls (e.g., WAF rules, network segmentation) and formally accepting residual risk is the recommended risk management approach.
Question 35: Why is patch management considered an important defense-in-depth control?
- It primarily addresses physical security gaps
- It replaces the need for network segmentation
- It reduces known vulnerabilities that attackers could exploit at multiple layers (Correct answer)
- It is only relevant to the application layer
Correct answer: It reduces known vulnerabilities that attackers could exploit at multiple layers
Patch management reduces exploitable vulnerabilities across operating systems, applications, and firmware, strengthening multiple defense layers simultaneously.
Question 36: A SOC analyst receives an alert that a privileged account logged in from two geographically impossible locations within 10 minutes. This is an example of which threat indicator?
- Impossible travel anomaly (Correct answer)
- Beaconing pattern
- Credential stuffing
- Lateral movement
Correct answer: Impossible travel anomaly
Impossible travel anomaly flags authentication events from locations that cannot be physically reached within the observed time window.
Question 37: What is a firewall?
- A device that monitors physical hardware conditions.
- A device that speeds up network connections.
- A system that monitors and controls network traffic to prevent unauthorized access. (Correct answer)
- A tool for storing network data.
Correct answer: A system that monitors and controls network traffic to prevent unauthorized access.
A firewall serves as a critical security barrier, inspecting all incoming and outgoing network traffic against a defined set of security rules. Its main function is to block unauthorized access attempts and prevent malicious data from entering or leaving a private network. By filtering traffic, firewalls protect systems and data from external threats and enforce network security policies, acting as a crucial gatekeeper.
Question 38: What is the standard formula for calculating risk in cybersecurity?
- Vulnerability - Threat
- Threat × Vulnerability × Asset Value (Correct answer)
- Threat + Vulnerability
- Asset Value / Threat
Correct answer: Threat × Vulnerability × Asset Value
Risk is commonly expressed as the product of threat likelihood, vulnerability severity, and asset value.
Question 39: A CA issues a wildcard certificate for *.example.com. Which hostname would NOT be covered by this certificate?
- sub.mail.example.com (Correct answer)
- www.example.com
- mail.example.com
- api.example.com
Correct answer: sub.mail.example.com
Wildcard certificates cover only one level of subdomain depth; *.example.com matches mail.example.com but not sub.mail.example.com (two levels deep).
Question 40: A CCP professional encounters an unfamiliar situation while performing defense-in-depth architecture duties. What is the most appropriate first action?
- Skip the task entirely and move to the next assignment
- Apply a solution from an unrelated field without verification
- Consult relevant standards, guidelines, or a qualified supervisor before proceeding (Correct answer)
- Proceed based on general assumptions to avoid delays
Correct answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in defense-in-depth architecture, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Question 41: In a defense-in-depth model, what is the primary purpose of an intrusion detection system (IDS) deployed inside the network perimeter?
- Detect threats that bypassed perimeter controls (Correct answer)
- Replace the need for a firewall
- Encrypt internal communications
- Block all inbound traffic
Correct answer: Detect threats that bypassed perimeter controls
An IDS deployed internally acts as a secondary control to detect malicious activity that has already passed through perimeter defenses.
Question 42: What does the MITRE ATT&CK technique T1055 (Process Injection) help an attacker achieve?
- Exfiltrating data through covert network channels
- Discovering network topology through active scanning
- Evading defenses and escalating privileges by running code within the context of another process (Correct answer)
- Establishing persistence by modifying system startup keys
Correct answer: Evading defenses and escalating privileges by running code within the context of another process
Process injection allows attackers to execute malicious code within the memory space of a legitimate process, inheriting its privileges and evading process-based security controls.
Question 43: Which of the following is a fundamental principle of cve assessment & patch management as it applies to Certified Cybersecurity Professional?
- Systematic evaluation and adherence to established industry standards (Correct answer)
- Relying solely on personal experience without reference to guidelines
- Avoiding documentation to streamline workflow efficiency
- Prioritizing speed of completion over accuracy and compliance
Correct answer: Systematic evaluation and adherence to established industry standards
A fundamental principle of cve assessment & patch management in Certified Cybersecurity Professional is the systematic evaluation and adherence to established industry standards, which ensures consistency, quality, and regulatory compliance across all professional activities.
Question 44: Which vulnerability class occurs when an application deserializes untrusted data, allowing attackers to execute arbitrary code?
- XML External Entity (XXE) Injection
- Path Traversal
- Insecure Deserialization (Correct answer)
- Server-Side Request Forgery (SSRF)
Correct answer: Insecure Deserialization
Insecure Deserialization allows attackers to manipulate serialized objects to alter application logic or achieve remote code execution during the deserialization process.
Question 45: When the cost of mitigating a risk exceeds the value of the asset at risk, which risk response is most appropriate?
- Risk transference
- Risk acceptance (Correct answer)
- Risk avoidance
- Risk mitigation
Correct answer: Risk acceptance
Risk acceptance is rational when the cost to mitigate a risk outweighs the potential financial loss from the risk event.
Question 46: What is network segmentation?
- Limiting access to only certain network protocols.
- Dividing a network into smaller, isolated segments to improve security and performance. (Correct answer)
- Connecting all devices in a single network.
- Allowing all devices to share the same IP address.
Correct answer: Dividing a network into smaller, isolated segments to improve security and performance.
Network segmentation involves dividing a larger network into smaller, isolated subnetworks. This strategy improves security by limiting the lateral movement of attackers, as a breach in one segment does not automatically grant access to others. It also enhances network performance by reducing broadcast traffic and allowing for more granular security controls.
Question 47: Which ethical principle requires a cybersecurity professional to avoid conflicts of interest and remain objective in assessments?
- Objectivity (Correct answer)
- Non-maleficence
- Integrity
- Confidentiality
Correct answer: Objectivity
Objectivity requires professionals to provide unbiased assessments free from personal or financial conflicts of interest.
Question 48: Which attack exploits the trust relationship between a user's browser and a web application to perform unauthorized actions using the user's authenticated session?
- SQL Injection
- Session fixation
- Man-in-the-Middle
- Cross-Site Request Forgery (CSRF) (Correct answer)
Correct answer: Cross-Site Request Forgery (CSRF)
CSRF tricks an authenticated user's browser into sending forged requests to a trusted site, leveraging the existing session cookie to perform unauthorized actions.
Question 49: NIST SP 800-53A is used for which purpose?
- Managing insider threat programs
- Conducting privacy impact assessments
- Assessing the effectiveness of security and privacy controls (Correct answer)
- Selecting baseline controls for information systems
Correct answer: Assessing the effectiveness of security and privacy controls
NIST SP 800-53A provides procedures for assessing the security and privacy controls defined in SP 800-53 to determine their effectiveness.
Question 50: In the context of nist & iso 27001 compliance, what role does continuous professional development play for CCP practitioners?
- It ensures practitioners remain current with evolving standards, technologies, and best practices (Correct answer)
- It is optional and only needed for career advancement
- It serves primarily as a networking opportunity with no practical benefit
- It is required only during the first year of certification
Correct answer: It ensures practitioners remain current with evolving standards, technologies, and best practices
Continuous professional development is essential in nist & iso 27001 compliance because it ensures CCP practitioners remain current with evolving standards, technologies, and best practices, maintaining competency throughout their careers.
Question 51: Which Windows Event ID should an analyst prioritize when investigating potential credential dumping via LSASS?
- Event ID 10 in Sysmon (Process accessed) (Correct answer)
- Event ID 4625 (Failed logon)
- Event ID 4776 (Credential validation)
- Event ID 4688 (Process creation)
Correct answer: Event ID 10 in Sysmon (Process accessed)
Sysmon Event ID 10 logs when one process opens a handle to another, making it critical for detecting tools like Mimikatz accessing the LSASS process memory.
Question 52: What does the term 'attack surface' refer to?
- The physical area around a server
- The tools used in a cyberattack
- All the points where an attacker could try to enter or extract data from an environment (Correct answer)
- The damage caused after a successful attack
Correct answer: All the points where an attacker could try to enter or extract data from an environment
The attack surface encompasses all the different points of entry an attacker could exploit to compromise a system or network.
Question 53: What is the role of threat intelligence in cybersecurity operations?
- To train employees on phishing awareness
- To provide context about threats enabling informed defensive decisions (Correct answer)
- To encrypt sensitive data
- To automatically patch vulnerabilities
Correct answer: To provide context about threats enabling informed defensive decisions
Threat intelligence aggregates information about adversaries, TTPs, and indicators of compromise to help organizations anticipate and respond to threats.
Question 54: Which log source is most valuable for detecting lateral movement within a Windows environment?
- DHCP server lease logs
- Windows Security Event logs (e.g., Event ID 4624, 4648) (Correct answer)
- DNS query logs from the perimeter firewall
- Web server access logs
Correct answer: Windows Security Event logs (e.g., Event ID 4624, 4648)
Windows Security Event logs capture authentication events (logon types, source IPs, account names) that are essential for detecting lateral movement via credential reuse or pass-the-hash.
Question 55: Which framework specifically guides U.S. federal agencies through a structured risk management process?
- ISO 31000
- OCTAVE
- FAIR (Factor Analysis of Information Risk)
- NIST Risk Management Framework (RMF) (Correct answer)
Correct answer: NIST Risk Management Framework (RMF)
The NIST RMF is mandatory for U.S. federal agencies and provides a structured process for managing information security risk.
Question 56: What is 'patch diffing' used for in a security context?
- Validating patch authenticity via hash comparison
- Measuring patch deployment speed
- Comparing patched and unpatched binaries to reverse-engineer the underlying vulnerability (Correct answer)
- Tracking which patches have been applied to a system
Correct answer: Comparing patched and unpatched binaries to reverse-engineer the underlying vulnerability
Patch diffing is a reverse-engineering technique where attackers or researchers compare pre- and post-patch binaries to identify what changed and reconstruct the exploitable flaw.
Question 57: In Zero Trust Architecture, what does 'never trust, always verify' mean for IAM?
- Users must re-enroll MFA devices weekly
- Disabling all trusted certificates in the environment
- Every access request must be authenticated and authorized regardless of network location or prior session (Correct answer)
- Network perimeter firewalls replace identity checks
Correct answer: Every access request must be authenticated and authorized regardless of network location or prior session
Zero Trust eliminates implicit trust based on network location; every request requires explicit identity verification, device health validation, and authorization before access is granted.
Question 58: Which threat modeling framework uses the categories Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?
- VAST
- DREAD
- PASTA
- STRIDE (Correct answer)
Correct answer: STRIDE
STRIDE is a Microsoft-developed threat classification model where each letter represents a category of security threat used to identify risks during design.
Question 59: A security team discovers that an attacker has been silently collecting data for months. This is characteristic of which threat type?
- Denial of Service
- Advanced Persistent Threat (APT) (Correct answer)
- Script Kiddie attack
- Ransomware
Correct answer: Advanced Persistent Threat (APT)
An APT is a prolonged, stealthy attack where an adversary remains undetected while continuously exfiltrating data.
Question 60: An attacker performs a BGP hijack to redirect traffic for an OCSP responder's IP address. What is the likely goal of this attack in the context of PKI?
- Steal the OCSP responder's private signing key
- Obtain a fraudulent certificate from the target CA
- Cause OCSP responses to return 'good' for revoked certificates, enabling use of compromised credentials (Correct answer)
- Force clients to fall back to CRL checking instead of OCSP
Correct answer: Cause OCSP responses to return 'good' for revoked certificates, enabling use of compromised credentials
By intercepting OCSP traffic, an attacker can return forged 'good' responses for revoked certificates, allowing continued use of compromised client or server certificates that should have been rejected.
Question 61: Which metric defines the maximum acceptable downtime for a system following a disaster?
- Mean Time to Repair (MTTR)
- Recovery Time Objective (RTO) (Correct answer)
- Recovery Point Objective (RPO)
- Maximum Tolerable Downtime (MTD)
Correct answer: Recovery Time Objective (RTO)
The Recovery Time Objective (RTO) specifies the maximum time allowed to restore a system or process after a disruption.
Question 62: In cloud workload security, what is 'drift detection'?
- Tracking cost increases in cloud spending
- Monitoring network latency between cloud regions
- Detecting data exfiltration to foreign IP ranges
- Identifying changes to a workload's configuration or state that deviate from its approved baseline (Correct answer)
Correct answer: Identifying changes to a workload's configuration or state that deviate from its approved baseline
Drift detection identifies when a running workload's configuration, files, or behavior has changed from its approved secure baseline.
Question 63: What is the key difference between symmetric and asymmetric encryption?
- Symmetric uses no keys; asymmetric uses one key
- Symmetric is only for data at rest
- Symmetric uses one shared key; asymmetric uses a public-private key pair (Correct answer)
- Symmetric is slower; asymmetric is faster
Correct answer: Symmetric uses one shared key; asymmetric uses a public-private key pair
Symmetric encryption uses the same key for encryption and decryption, while asymmetric uses mathematically related public and private keys.
Question 64: Which approach to application security testing simulates real-world attackers by actively probing a running application for exploitable vulnerabilities?
- Code Review
- Dynamic Application Security Testing (DAST) (Correct answer)
- Design Review
- Static Application Security Testing (SAST)
Correct answer: Dynamic Application Security Testing (DAST)
DAST tests the running application from the outside by simulating attacker behavior, identifying vulnerabilities like injection flaws and authentication weaknesses that only appear at runtime.
Question 65: A healthcare organization implements de-identification to share patient data for research. Under HIPAA, which method involves removing 18 specific identifiers?
- Safe Harbor method (Correct answer)
- Data masking
- Pseudonymization
- Statistical expert determination
Correct answer: Safe Harbor method
HIPAA's Safe Harbor de-identification method requires removal of 18 specific categories of identifiers, after which data is no longer considered PHI.
Question 66: What is the primary difference between a self-signed certificate and a certificate issued by a trusted CA for establishing a public TLS service?
- Self-signed certificates are not trusted by browsers/OS trust stores, causing warnings for end users (Correct answer)
- Self-signed certificates expire after 30 days by default
- Self-signed certificates cannot contain Subject Alternative Names
- Self-signed certificates use weaker encryption algorithms
Correct answer: Self-signed certificates are not trusted by browsers/OS trust stores, causing warnings for end users
Self-signed certificates are not chained to any CA in a client's trust store, so browsers display security warnings; CA-issued certificates inherit trust from a pre-installed root CA.
Question 67: During a ransomware incident, the IR team isolates affected hosts but discovers the malware has a kill-switch domain. What is the BEST immediate action?
- Reimage all affected hosts immediately
- Pay the ransom to obtain the decryption key
- Block all outbound DNS at the perimeter firewall
- Sinkhole the kill-switch domain to prevent detonation (Correct answer)
Correct answer: Sinkhole the kill-switch domain to prevent detonation
Sinkholing the kill-switch domain redirects C2 traffic to a controlled server, potentially halting further encryption while preserving forensic evidence.
Question 68: In the NIST Cybersecurity Framework, 'Tiers' describe what aspect of an organization's cybersecurity program?
- The rigor and sophistication of cybersecurity risk management practices (Correct answer)
- The specific technical controls implemented
- The number of employees in the security team
- Compliance status with specific regulations
Correct answer: The rigor and sophistication of cybersecurity risk management practices
CSF Tiers (1-Partial through 4-Adaptive) characterize how an organization views cybersecurity risk and the processes in place to manage it.
Question 69: What is the security benefit of implementing microsegmentation in a data center as part of defense-in-depth?
- It encrypts all data leaving the data center
- It eliminates the need for perimeter firewalls
- It replaces the need for endpoint security
- It limits lateral movement by isolating individual workloads (Correct answer)
Correct answer: It limits lateral movement by isolating individual workloads
Microsegmentation creates granular security zones around individual workloads, preventing attackers from freely moving laterally even after breaching one segment.
Question 70: A CCP professional encounters an unfamiliar situation while performing nist & iso 27001 compliance duties. What is the most appropriate first action?
- Apply a solution from an unrelated field without verification
- Proceed based on general assumptions to avoid delays
- Skip the task entirely and move to the next assignment
- Consult relevant standards, guidelines, or a qualified supervisor before proceeding (Correct answer)
Correct answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in nist & iso 27001 compliance, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Question 71: What is the role of endpoint detection and response (EDR) in a defense-in-depth architecture?
- Encrypt data at rest on servers
- Provide VPN tunneling for remote users
- Manage firewall rule sets centrally
- Monitor and respond to threats on end-user devices (Correct answer)
Correct answer: Monitor and respond to threats on end-user devices
EDR solutions monitor endpoint activity in real time and provide automated or analyst-driven response to threats at the host layer.
Question 72: A security engineer needs to determine if a CVE affects their environment without a scanner. Which artifact provides the most authoritative list of affected product versions?
- The CVE description text alone
- The vendor security advisory and associated CPE list in the NVD entry (Correct answer)
- The CVSS vector string
- Third-party blog posts about the vulnerability
Correct answer: The vendor security advisory and associated CPE list in the NVD entry
Vendor security advisories combined with NVD CPE data provide authoritative, versioned product lists to determine applicability without relying on scanner output.
Question 73: Which approach prioritizes patching assets based on their exposure to the internet and business criticality?
- Alphabetical system patching
- Chronological patch ordering
- Vendor severity-only ranking
- Risk-based patch prioritization (Correct answer)
Correct answer: Risk-based patch prioritization
Risk-based patch prioritization factors in asset exposure, exploitability (e.g., EPSS score), and business criticality rather than relying solely on vendor severity ratings.
Question 74: Which NIST document provides guidelines for applying the Risk Management Framework to federal information systems?
- SP 800-53
- SP 800-171
- SP 800-37 (Correct answer)
- SP 800-30
Correct answer: SP 800-37
NIST SP 800-37 (Risk Management Framework for Information Systems and Organizations) provides the six-step RMF process for federal systems.
Question 75: Which vulnerability management framework uses 'Required Action' deadlines and is enforced by CISA for US federal agencies?
- CVSSv3.1 temporal scoring
- NIST NVD scoring system
- CISA Known Exploited Vulnerabilities (KEV) catalog (Correct answer)
- MITRE ATT&CK framework
Correct answer: CISA Known Exploited Vulnerabilities (KEV) catalog
The CISA KEV catalog lists vulnerabilities with evidence of active exploitation and mandates remediation deadlines for US federal civilian agencies under BOD 22-01.
Question 76: When documenting activities related to iam & multi-factor authentication, which practice is considered essential for CCP certification holders?
- Maintaining comprehensive records that include procedures, observations, results, and any anomalies (Correct answer)
- Recording only outcomes while omitting the methods and processes used
- Completing documentation only when requested by auditors or supervisors
- Keeping documentation in personal notes that are not accessible to other team members
Correct answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in iam & multi-factor authentication. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
Question 77: What is the function of the TLS Server Name Indication (SNI) extension?
- Negotiates the cipher suite before the ClientHello
- Allows the client to specify which hostname it is connecting to so the server can present the correct certificate (Correct answer)
- Encrypts the server's certificate during transit
- Provides the server's OCSP stapling response
Correct answer: Allows the client to specify which hostname it is connecting to so the server can present the correct certificate
SNI allows multiple TLS-enabled virtual hosts to share a single IP address by letting the client declare the target hostname in the ClientHello before the server selects which certificate to present.
Question 78: What is the primary ethical obligation of a CCP professional when a conflict of interest arises during defense-in-depth architecture activities?
- Disclose the conflict to all relevant parties and recuse from the decision if necessary (Correct answer)
- Resolve the conflict privately without informing stakeholders
- Ignore the conflict if it does not directly affect the current task
- Proceed while favoring the outcome that benefits the professional personally
Correct answer: Disclose the conflict to all relevant parties and recuse from the decision if necessary
The primary ethical obligation when a conflict of interest arises in defense-in-depth architecture is to disclose it to all relevant parties and, if necessary, recuse from the decision. This maintains professional integrity and stakeholder trust.
Question 79: What is the primary security risk of using SMS as an MFA factor?
- SIM swapping attacks can redirect messages to an attacker (Correct answer)
- SMS is encrypted end-to-end
- SMS OTPs are too long to intercept
- SMS codes expire too quickly
Correct answer: SIM swapping attacks can redirect messages to an attacker
SIM swapping allows attackers to convince carriers to transfer a victim's phone number to an attacker-controlled SIM, intercepting all SMS messages including OTPs.
Question 80: A user receives an email appearing to be from their bank asking them to click a link and enter credentials. This is an example of:
- Spear phishing
- Phishing (Correct answer)
- Vishing
- Smishing
Correct answer: Phishing
Phishing is a broad social engineering attack using fraudulent emails to trick users into revealing sensitive information.
Question 81: Cross-Site Request Forgery (CSRF) attacks are best defended against using which mechanism?
- Anti-CSRF tokens synchronized between client and server (Correct answer)
- Input length restrictions
- Rate limiting login attempts
- Encrypting all cookies
Correct answer: Anti-CSRF tokens synchronized between client and server
Anti-CSRF (synchronizer) tokens are unique, secret values embedded in forms that the server validates on submission, ensuring the request originated from the legitimate site.
Question 82: What is the primary ethical obligation of a CCP professional when a conflict of interest arises during cve assessment & patch management activities?
- Ignore the conflict if it does not directly affect the current task
- Resolve the conflict privately without informing stakeholders
- Disclose the conflict to all relevant parties and recuse from the decision if necessary (Correct answer)
- Proceed while favoring the outcome that benefits the professional personally
Correct answer: Disclose the conflict to all relevant parties and recuse from the decision if necessary
The primary ethical obligation when a conflict of interest arises in cve assessment & patch management is to disclose it to all relevant parties and, if necessary, recuse from the decision. This maintains professional integrity and stakeholder trust.
Question 83: Which AWS service provides managed threat detection for EC2 instances, containers, and serverless workloads by analyzing CloudTrail, VPC Flow Logs, and DNS logs?
- AWS Macie
- AWS GuardDuty (Correct answer)
- AWS Inspector
- AWS Shield
Correct answer: AWS GuardDuty
AWS GuardDuty is a managed threat detection service that continuously monitors and analyzes data sources to identify malicious activity across workloads.
Question 84: In secure session management, what is the recommended action immediately after a user successfully authenticates?
- Issue a new session ID to prevent session fixation attacks (Correct answer)
- Extend the session timeout to 24 hours
- Store credentials in the session object
- Reuse the existing session ID for convenience
Correct answer: Issue a new session ID to prevent session fixation attacks
Generating a new session ID after authentication prevents session fixation, where an attacker pre-sets a known session ID to hijack the session after the user logs in.
Question 85: In SAML 2.0, what is the function of the XML signature on an assertion?
- It ensures integrity and authenticity, proving the assertion was issued by the trusted IdP and not tampered with (Correct answer)
- It encrypts the assertion contents from the Service Provider
- It binds the assertion to a specific IP address
- It compresses the assertion to reduce transmission size
Correct answer: It ensures integrity and authenticity, proving the assertion was issued by the trusted IdP and not tampered with
The XML digital signature on a SAML assertion allows the Service Provider to verify that the assertion was created by the trusted IdP and has not been modified in transit.
Question 86: In the context of cve assessment & patch management, what role does continuous professional development play for CCP practitioners?
- It serves primarily as a networking opportunity with no practical benefit
- It is optional and only needed for career advancement
- It is required only during the first year of certification
- It ensures practitioners remain current with evolving standards, technologies, and best practices (Correct answer)
Correct answer: It ensures practitioners remain current with evolving standards, technologies, and best practices
Continuous professional development is essential in cve assessment & patch management because it ensures CCP practitioners remain current with evolving standards, technologies, and best practices, maintaining competency throughout their careers.
Question 87: An IDS alert fires on a signature for a known vulnerability, but the target system is running a patched OS version that is not susceptible. This is an example of which IDS issue?
- False positive (Correct answer)
- False negative
- True positive
- True negative
Correct answer: False positive
A false positive occurs when an IDS generates an alert for traffic that is not actually a successful or viable attack, such as detecting an exploit signature against a patched target.
Question 88: Which attack exploits the trust relationship between a DNS resolver and its cache by injecting forged DNS responses?
- ARP spoofing
- IP spoofing
- DNS cache poisoning (Correct answer)
- BGP hijacking
Correct answer: DNS cache poisoning
DNS cache poisoning corrupts a resolver's cache with fraudulent records, redirecting users to attacker-controlled servers without their knowledge.
Question 89: The term 'threat landscape' refers to:
- The list of known malware signatures in a database
- A visual diagram of the network topology
- The complete range of potential threats facing an organization (Correct answer)
- The physical geography of network infrastructure assets
Correct answer: The complete range of potential threats facing an organization
The threat landscape encompasses all known and emerging threats that an organization may face at a given point in time.
Question 90: ISO/IEC 27001 requires organizations to establish an ISMS. What does ISMS stand for?
- Infrastructure Security Measurement Standard
- Information Security Management System (Correct answer)
- Incident and Security Mitigation Strategy
- Integrated Security Monitoring System
Correct answer: Information Security Management System
An Information Security Management System (ISMS) is a systematic approach to managing sensitive company information, as defined in ISO/IEC 27001.
Question 91: What is the CIA Triad's relevance when classifying a DDoS attack?
- It equally affects all three pillars
- It primarily affects Integrity
- It primarily affects Confidentiality
- It primarily affects Availability (Correct answer)
Correct answer: It primarily affects Availability
A DDoS (Distributed Denial of Service) attack overwhelms systems to make services unavailable, directly targeting the Availability pillar of the CIA Triad.
Question 92: Which type of attack is specifically designed to exhaust firewall connection table resources?
- Pass-the-hash
- Cross-site scripting (XSS)
- SYN flood (Correct answer)
- SQL injection
Correct answer: SYN flood
A SYN flood sends a high volume of TCP SYN packets without completing the handshake, filling the firewall's connection state table and denying service to legitimate users.
Question 93: Why are legal and ethical considerations important in cybersecurity?
- Legal and ethical considerations only apply to financial transactions.
- Legal and ethical considerations ensure that organizations protect data, comply with laws, and maintain trust. (Correct answer)
- Legal and ethical considerations focus solely on employee behavior.
- Legal and ethical considerations are irrelevant in cybersecurity.
Correct answer: Legal and ethical considerations ensure that organizations protect data, comply with laws, and maintain trust.
Legal and ethical considerations are paramount in cybersecurity because they guide responsible data handling, privacy protection, and the appropriate use of security tools and techniques. Adhering to laws like GDPR and ethical principles ensures organizations protect data, comply with legal obligations, and maintain the trust of their customers and stakeholders. Failing to do so can lead to severe legal penalties, reputational damage, and erosion of public confidence.
Question 94: What is two-factor authentication?
- Requiring an IP address for verification.
- Requiring a fingerprint for system access.
- Requiring two forms of verification, such as a password and a code sent to your phone. (Correct answer)
- Requiring only a password to access an account.
Correct answer: Requiring two forms of verification, such as a password and a code sent to your phone.
Two-factor authentication (2FA) significantly enhances security by requiring users to provide two different types of credentials to verify their identity. This typically combines something the user knows (like a password) with something the user has (like a phone or a token) or something the user is (like a fingerprint). Even if one factor is compromised, the second factor prevents unauthorized access, making accounts much more secure.
Question 95: A network security engineer deploys honeypots on the internal network. What is the PRIMARY purpose of these systems?
- Detect and analyze attacker behavior after perimeter breach (Correct answer)
- Provide redundant network paths
- Cache DNS queries
- Absorb DDoS traffic
Correct answer: Detect and analyze attacker behavior after perimeter breach
Honeypots are decoy systems designed to attract attackers, allowing defenders to detect lateral movement and study attacker techniques in a controlled environment.
Question 96: Under the NIST SP 800-40 guidance on patch management, what is the recommended maximum timeframe to patch critical vulnerabilities in internet-facing systems?
- Within 6 months
- Only during the next scheduled maintenance window
- Within 12 months
- Within days to a few weeks, depending on risk (Correct answer)
Correct answer: Within days to a few weeks, depending on risk
NIST SP 800-40 recommends patching critical vulnerabilities in exposed systems as quickly as possible, typically within days to weeks, based on assessed risk.
Question 97: What is a Security Information and Event Management (SIEM) system?
- A SIEM system is only used for storing data.
- A SIEM system collects and analyzes security event data to detect threats and vulnerabilities. (Correct answer)
- A SIEM system is used for data backup only.
- A SIEM system only manages network traffic.
Correct answer: A SIEM system collects and analyzes security event data to detect threats and vulnerabilities.
A Security Information and Event Management (SIEM) system is a comprehensive security solution that centralizes and analyzes security event data from various sources across an organization's IT infrastructure. It collects logs from servers, network devices, and applications, then uses correlation rules and analytics to detect patterns, identify potential threats, and provide real-time alerts. This offers a holistic view of the security posture and aids in compliance reporting.
Question 98: A company implements VLAN segmentation, DMZ zones, and internal firewalls. Which defense-in-depth principle does this best represent?
- Network segmentation and zoning (Correct answer)
- Least functionality
- Single point of enforcement
- Defense by obscurity
Correct answer: Network segmentation and zoning
Network segmentation and zoning divides the network into isolated areas so a breach in one zone does not immediately compromise others.
Question 99: Which protocol is used to securely exchange encryption keys over an insecure channel without prior shared secrets?
- Diffie-Hellman (Correct answer)
- MD5
- AES
- RSA
Correct answer: Diffie-Hellman
Diffie-Hellman key exchange allows two parties to establish a shared secret over an untrusted channel without transmitting the secret itself.
Question 100: A security engineer wants to prevent external attackers from mapping internal IP addresses using ICMP. Which firewall rule best addresses this?
- Disable ARP on the perimeter router
- Block all outbound TCP port 80 traffic
- Block all inbound ICMP echo requests at the perimeter (Correct answer)
- Enable NAT overload on the internal interface
Correct answer: Block all inbound ICMP echo requests at the perimeter
Blocking inbound ICMP echo requests prevents external parties from using ping sweeps to discover live internal hosts.
Question 101: What does EPSS (Exploit Prediction Scoring System) provide that CVSS does not?
- A severity score based on technical impact
- A list of affected product versions
- A probability estimate that a CVE will be exploited in the wild within the next 30 days (Correct answer)
- An official vendor patch status
Correct answer: A probability estimate that a CVE will be exploited in the wild within the next 30 days
EPSS produces a daily probability score (0–1) predicting likelihood of exploitation in the wild, complementing CVSS severity with real-world threat intelligence.
Question 102: An attacker compromises a low-privileged user account but cannot escalate privileges due to strict role-based access controls. Which defense-in-depth principle does this illustrate?
- Perimeter defense
- Least privilege and access control layers (Correct answer)
- Detective-only controls
- Security through obscurity
Correct answer: Least privilege and access control layers
Least privilege limits account permissions so that even a compromised account cannot perform privileged actions, containing the blast radius of the breach.
Question 103: What is the purpose of network segmentation in cybersecurity?
- To simplify network management
- To increase internet bandwidth
- To divide a network into zones to contain breaches and limit lateral movement (Correct answer)
- To reduce hardware costs
Correct answer: To divide a network into zones to contain breaches and limit lateral movement
Network segmentation creates isolated zones so that if one segment is compromised, an attacker cannot freely move to other parts of the network.
Question 104: Which SIEM tuning approach reduces false positives without increasing false negatives?
- Disabling low-priority correlation rules to reduce alert volume
- Whitelisting known-good activity while refining detection logic based on environmental context (Correct answer)
- Raising all alert thresholds globally to reduce noise
- Increasing log retention periods to capture more historical data
Correct answer: Whitelisting known-good activity while refining detection logic based on environmental context
Whitelisting verified legitimate activity (like scheduled maintenance scripts or known admin accounts) reduces false positives while preserving detection capability for genuine threats.
Question 105: In CVSS v3.1, a vulnerability with Integrity Impact: High means that:
- Only low-sensitivity data can be modified
- There is total loss of integrity; the attacker can modify any or all files protected by the vulnerable component (Correct answer)
- System availability is severely impacted
- Authentication data can be stolen
Correct answer: There is total loss of integrity; the attacker can modify any or all files protected by the vulnerable component
Integrity Impact: High in CVSS v3.1 means the attacker can completely modify protected data or system files, resulting in total loss of integrity.
Question 106: Which endpoint security technique detects unknown malware by analyzing suspicious behaviors rather than known signatures?
- Cryptographic hash comparison
- Signature-based detection
- Blacklisting
- Heuristic and behavioral analysis (Correct answer)
Correct answer: Heuristic and behavioral analysis
Heuristic and behavioral analysis identifies threats based on suspicious activities, enabling detection of zero-day and novel malware.
Question 107: What does 'microsegmentation' achieve in a cloud workload protection strategy?
- Divides storage into smaller performance segments
- Splits compute costs across business units
- Segments encryption keys by workload type
- Creates fine-grained network zones that limit lateral movement between workloads (Correct answer)
Correct answer: Creates fine-grained network zones that limit lateral movement between workloads
Microsegmentation enforces granular network access policies between individual workloads, containing breaches and limiting an attacker's ability to move laterally.
Question 108: What does Single Loss Expectancy (SLE) represent?
- The total value of all organizational assets
- The probability of a threat occurring within one year
- The annual cost of all security controls
- The expected monetary loss from one occurrence of a specific risk event (Correct answer)
Correct answer: The expected monetary loss from one occurrence of a specific risk event
SLE is the estimated dollar loss associated with a single occurrence of a given risk event.
Question 109: In the MITRE ATT&CK framework, which tactic describes an adversary's actions to maintain access after initial compromise?
- Initial Access
- Privilege Escalation
- Defense Evasion
- Persistence (Correct answer)
Correct answer: Persistence
The Persistence tactic covers techniques like scheduled tasks, registry run keys, and backdoors that allow attackers to survive reboots or credential changes.
Question 110: When a vendor releases a patch marked 'Defense in Depth' rather than a direct fix, it typically means:
- The patch only applies to non-production systems
- The vulnerability has no known exploit
- The patch completely remediates the vulnerability
- The patch adds mitigating controls that reduce attack surface without fully eliminating the vulnerability (Correct answer)
Correct answer: The patch adds mitigating controls that reduce attack surface without fully eliminating the vulnerability
Defense-in-depth patches add hardening measures (e.g., additional validation, ASLR improvements) that reduce exploitability without resolving the underlying root cause.
Question 111: Which technique can attackers use to exploit the gap between vulnerability disclosure and patch deployment?
- Patch diffing to discover new attack surfaces
- N-day exploit development targeting the disclosed CVE before patching is complete (Correct answer)
- Certificate pinning attacks
- Zero-trust architecture bypass
Correct answer: N-day exploit development targeting the disclosed CVE before patching is complete
After a CVE is disclosed, attackers develop N-day exploits targeting unpatched systems, making rapid patch deployment critical during the exposure window.
Question 112: Which MFA method is considered MOST resistant to real-time phishing attacks?
- FIDO2/WebAuthn hardware key (Correct answer)
- SMS one-time password
- Time-based OTP app
- Email-based OTP
Correct answer: FIDO2/WebAuthn hardware key
FIDO2/WebAuthn binds authentication to the specific origin domain, making real-time phishing ineffective because stolen credentials cannot be replayed on a different site.
Question 113: What is encryption in network security?
- Storing data in cloud servers.
- Compressing data to save storage space.
- Converting data into readable format.
- Converting data into unreadable format to protect it from unauthorized access. (Correct answer)
Correct answer: Converting data into unreadable format to protect it from unauthorized access.
Encryption is a fundamental cybersecurity process that transforms readable data (plaintext) into an unreadable format (ciphertext) using an algorithm and a key. This conversion ensures that even if unauthorized individuals intercept the data, they cannot understand its content without the correct decryption key. Its primary purpose is to protect data confidentiality and integrity during transmission and storage.
Question 114: Which patch management metric measures the average time from patch availability to deployment across all systems?
- Mean Time to Patch (MTTP) (Correct answer)
- Mean Time to Detect (MTTD)
- Patch Compliance Rate
- Vulnerability Density
Correct answer: Mean Time to Patch (MTTP)
Mean Time to Patch (MTTP) measures the average elapsed time from when a patch becomes available to when it is deployed across target systems.
Question 115: An attacker sends a crafted XML document containing an external entity reference that causes the server to read a local file. Which vulnerability is being exploited?
- Template Injection
- LDAP Injection
- SSRF
- XXE (XML External Entity) Injection (Correct answer)
Correct answer: XXE (XML External Entity) Injection
XXE Injection exploits XML parsers that process external entity declarations, allowing attackers to read local files, perform SSRF, or execute denial-of-service attacks.
Question 116: A company stores sensitive data encrypted at rest. Which security property is being protected?
- Confidentiality (Correct answer)
- Authentication
- Non-repudiation
- Availability
Correct answer: Confidentiality
Encrypting data at rest protects confidentiality by preventing unauthorized access to stored information.
Question 117: What is the primary ethical obligation of a CCP professional when a conflict of interest arises during iam & multi-factor authentication activities?
- Disclose the conflict to all relevant parties and recuse from the decision if necessary (Correct answer)
- Ignore the conflict if it does not directly affect the current task
- Proceed while favoring the outcome that benefits the professional personally
- Resolve the conflict privately without informing stakeholders
Correct answer: Disclose the conflict to all relevant parties and recuse from the decision if necessary
The primary ethical obligation when a conflict of interest arises in iam & multi-factor authentication is to disclose it to all relevant parties and, if necessary, recuse from the decision. This maintains professional integrity and stakeholder trust.
Question 118: Which organization is the primary CVE Numbering Authority (CNA) responsible for assigning CVE IDs to vulnerabilities in Microsoft products?
- Microsoft Corporation (Correct answer)
- US-CERT
- NIST
- MITRE
Correct answer: Microsoft Corporation
Microsoft is a CVE Numbering Authority (CNA) and assigns CVE IDs for vulnerabilities discovered in its own products, while MITRE oversees the overall CVE program.
Question 119: Which protocol is specifically designed to delegate authorization (not authentication) between services?
- Kerberos
- OAuth 2.0 (Correct answer)
- SAML 2.0
- OpenID Connect
Correct answer: OAuth 2.0
OAuth 2.0 is an authorization framework that allows a resource owner to grant limited access to their resources to a third party without sharing credentials.
Question 120: A patch released outside of the normal patch cycle to address a critical zero-day vulnerability is called a:
- Rollup patch
- Hotfix or out-of-band patch (Correct answer)
- Feature update
- Service pack
Correct answer: Hotfix or out-of-band patch
An out-of-band or hotfix patch is released urgently outside the scheduled patch cycle to address actively exploited or critical vulnerabilities.
Question 121: Which patch management process step ensures that applied patches have not been tampered with during distribution?
- Cryptographic hash or digital signature verification of patch packages before installation (Correct answer)
- Running a vulnerability scan after patching
- Reviewing the vendor's public changelog
- Checking patch release notes for CVE references
Correct answer: Cryptographic hash or digital signature verification of patch packages before installation
Verifying SHA-256 hashes or vendor digital signatures before applying patches ensures the patch package has not been modified or corrupted in transit, preventing supply-chain tampering.
Question 122: When a TLS session is resumed using a pre-shared key (PSK) in TLS 1.3, what security property is potentially weakened?
- Integrity checking via AEAD ciphers
- Forward secrecy for the resumed session (Correct answer)
- Authentication of the server identity
- Confidentiality of the session data
Correct answer: Forward secrecy for the resumed session
PSK-only resumption reuses keying material from a prior session, so compromising that PSK can expose the resumed session's traffic, weakening forward secrecy.
Question 123: Which cipher suite component in TLS 1.2 provides forward secrecy?
- RSA key exchange
- SHA-384 MAC
- AES-256-GCM encryption
- Ephemeral Diffie-Hellman (DHE or ECDHE) (Correct answer)
Correct answer: Ephemeral Diffie-Hellman (DHE or ECDHE)
Ephemeral Diffie-Hellman key exchange generates a new key pair per session, so compromising the server's long-term key cannot decrypt previously captured traffic.
Question 124: Which of the following is a fundamental principle of cloud workload protection as it applies to Certified Cybersecurity Professional?
- Relying solely on personal experience without reference to guidelines
- Systematic evaluation and adherence to established industry standards (Correct answer)
- Avoiding documentation to streamline workflow efficiency
- Prioritizing speed of completion over accuracy and compliance
Correct answer: Systematic evaluation and adherence to established industry standards
A fundamental principle of cloud workload protection in Certified Cybersecurity Professional is the systematic evaluation and adherence to established industry standards, which ensures consistency, quality, and regulatory compliance across all professional activities.
Question 125: In patch management, what is a 'patch window'?
- A GUI tool for reviewing patches
- The time between vulnerability disclosure and patch release
- A scheduled maintenance period when patches are applied to minimize disruption (Correct answer)
- A vulnerability in the patching software itself
Correct answer: A scheduled maintenance period when patches are applied to minimize disruption
A patch window is a predetermined maintenance window during which IT teams apply patches to minimize impact on business operations.
Question 126: Which phase of the Cyber Kill Chain does spear-phishing with a malicious attachment PRIMARILY represent?
- Reconnaissance
- Delivery (Correct answer)
- Weaponization
- Exploitation
Correct answer: Delivery
Delivery is the phase where the adversary transmits the weaponized payload to the victim, such as via email attachment, link, or USB drop.
Question 127: Which NIST document provides a framework for improving critical infrastructure cybersecurity using a risk-based approach?
- NIST SP 800-53
- NIST Cybersecurity Framework (CSF) (Correct answer)
- NIST SP 800-171
- NIST SP 800-37
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) provides a risk-based approach organized around five core functions: Identify, Protect, Detect, Respond, and Recover.
Question 128: What is the primary security advantage of using image signing in a container supply chain?
- It automatically patches known vulnerabilities in images
- It ensures only cryptographically verified, trusted images are deployed to production (Correct answer)
- It compresses images to reduce deployment time
- It encrypts image layers at rest in the registry
Correct answer: It ensures only cryptographically verified, trusted images are deployed to production
Image signing (e.g., using Notary or Cosign) ensures integrity and authenticity so only approved images from trusted sources reach production.
Question 129: In a defense-in-depth model, what is the primary purpose of a Security Operations Center (SOC)?
- Design network topology
- Continuously monitor, detect, and respond to threats across all layers (Correct answer)
- Conduct annual penetration tests only
- Manage software licensing
Correct answer: Continuously monitor, detect, and respond to threats across all layers
A SOC provides continuous monitoring and incident response across all security layers, acting as the operational hub of a defense-in-depth strategy.
Question 130: Which term describes the practice of testing an application by sending unexpected, random, or malformed inputs?
- Penetration testing
- Regression testing
- Fuzzing (Correct answer)
- Code review
Correct answer: Fuzzing
Fuzzing (fuzz testing) involves injecting invalid or unexpected data into a program to discover bugs, crashes, or security vulnerabilities.
Question 131: What is an intrusion detection system (IDS)?
- A system that detects hardware failures.
- A software used to track user activity.
- A tool for storing backup copies of data.
- A system that monitors network traffic for signs of unauthorized access or malicious activity. (Correct answer)
Correct answer: A system that monitors network traffic for signs of unauthorized access or malicious activity.
An Intrusion Detection System (IDS) is a security technology designed to monitor network or system activities for malicious behavior or policy violations. It analyzes traffic patterns and system logs, alerting administrators to potential security incidents or attacks. While an IDS detects, it typically does not prevent the intrusion, but rather provides crucial information for rapid response and mitigation.
Question 132: Which act prohibits intercepting electronic communications in transit without proper authorization and governs wiretapping?
- Electronic Communications Privacy Act (ECPA) (Correct answer)
- Computer Fraud and Abuse Act
- Stored Communications Act
- USA PATRIOT Act
Correct answer: Electronic Communications Privacy Act (ECPA)
ECPA Title I (Wiretap Act) prohibits the intentional interception of wire, oral, or electronic communications in transit without authorization.
Question 133: What is 'alert fatigue' in a SOC environment?
- A SIEM performance issue caused by too many correlation rules
- Physical exhaustion of SOC analysts from overnight shifts
- Network congestion caused by excessive log forwarding
- Desensitization of analysts due to an overwhelming volume of low-quality alerts (Correct answer)
Correct answer: Desensitization of analysts due to an overwhelming volume of low-quality alerts
Alert fatigue occurs when analysts receive so many alerts — especially false positives — that they become desensitized and may miss genuine threats buried in the noise.
Question 134: A company wants to prevent employees from uploading sensitive files to personal cloud storage services. Which perimeter control is MOST effective?
- Blocking all outbound port 80 traffic
- DNS sinkholing for cloud storage domains
- SSL/TLS inspection combined with a data loss prevention (DLP) proxy (Correct answer)
- Deploying a host-based IDS on all endpoints
Correct answer: SSL/TLS inspection combined with a data loss prevention (DLP) proxy
SSL/TLS inspection decrypts HTTPS traffic at the proxy, enabling DLP policies to inspect content and block unauthorized uploads to cloud storage.
Question 135: Which standard mandates security controls for systems that process, store, or transmit payment card data?
- HIPAA
- PCI DSS (Correct answer)
- SOX
- FERPA
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) requires organizations that handle payment card data to implement specific security controls.
Question 136: In Kubernetes security, what does a PodSecurityAdmission (PSA) policy enforce?
- Security standards for pod configurations, such as restricting privileged containers and host namespace access (Correct answer)
- Network encryption between pods
- RBAC permissions for service accounts
- Automated vulnerability scanning of container images
Correct answer: Security standards for pod configurations, such as restricting privileged containers and host namespace access
PodSecurityAdmission enforces security profiles (privileged, baseline, restricted) on pod specs to prevent insecure configurations from being deployed.
Question 137: A threat agent is best defined as:
- An entity capable of deliberately or accidentally exploiting a vulnerability (Correct answer)
- A weakness in a system that can be exploited
- The quantified impact of a security breach
- A technical safeguard deployed against attacks
Correct answer: An entity capable of deliberately or accidentally exploiting a vulnerability
A threat agent is the individual, group, or environmental force that has the potential to exploit a vulnerability.
Question 138: A CISO wants to ensure the organization's security controls align with NIST SP 800-53. What does this framework primarily provide?
- Incident response playbooks
- Payment card industry compliance requirements
- A catalog of security and privacy controls for federal information systems (Correct answer)
- Vulnerability scoring metrics
Correct answer: A catalog of security and privacy controls for federal information systems
NIST SP 800-53 provides a comprehensive catalog of security and privacy controls designed to protect federal information systems and organizations.
Question 139: Which protocol was specifically designed to replace SSL/TLS for IoT constrained devices, offering similar security guarantees over UDP?
- DTLS (Datagram TLS) (Correct answer)
- QUIC
- SSH
- IPsec/IKEv2
Correct answer: DTLS (Datagram TLS)
DTLS (RFC 6347) adapts the TLS record layer for datagram transport (UDP), handling packet reordering and loss to provide TLS-equivalent security for IoT and real-time applications.
Question 140: When documenting activities related to siem & threat detection, which practice is considered essential for CCP certification holders?
- Maintaining comprehensive records that include procedures, observations, results, and any anomalies (Correct answer)
- Completing documentation only when requested by auditors or supervisors
- Recording only outcomes while omitting the methods and processes used
- Keeping documentation in personal notes that are not accessible to other team members
Correct answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in siem & threat detection. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
Question 141: Which quality assurance method is most commonly applied in siem & threat detection to verify that CCP professional standards are being met?
- Relying on client satisfaction surveys as the sole measure of quality
- Structured audits, peer reviews, and performance metrics aligned with industry benchmarks (Correct answer)
- Informal self-assessment without external validation
- Annual reviews conducted exclusively by non-technical management
Correct answer: Structured audits, peer reviews, and performance metrics aligned with industry benchmarks
Structured audits, peer reviews, and performance metrics aligned with industry benchmarks are the most effective quality assurance methods in siem & threat detection, providing objective, measurable evidence that CCP standards are consistently met.
Question 142: In the context of vulnerability management, what is a 'false positive'?
- A patch that fails to remediate the vulnerability
- A CVE with an incorrect severity score
- A scanner reports a vulnerability that does not actually exist on the target system (Correct answer)
- A critical vulnerability that is not detected by the scanner
Correct answer: A scanner reports a vulnerability that does not actually exist on the target system
A false positive occurs when a vulnerability scanner incorrectly identifies a vulnerability on a system where it does not actually exist or is not exploitable in that configuration.
Question 143: Which scenario represents a 'virtual patch' or 'shield' in patch management?
- Deploying a new server version to replace the vulnerable one
- A WAF or IPS rule that blocks exploitation of a vulnerability without modifying the vulnerable system itself (Correct answer)
- Applying an operating system kernel patch
- Installing a vendor-provided hotfix
Correct answer: A WAF or IPS rule that blocks exploitation of a vulnerability without modifying the vulnerable system itself
A virtual patch uses a WAF, IPS, or network control to detect and block exploit attempts against a vulnerability, providing protection when the actual system patch cannot be immediately applied.
Question 144: Which control type is a security awareness training program?
- Technical control
- Detective control
- Physical control
- Administrative control (Correct answer)
Correct answer: Administrative control
Administrative controls are policies, procedures, and training programs that govern how people behave and manage security.
Question 145: What is 'defense in depth' as a cybersecurity strategy?
- Using a single strong firewall to protect the network
- Layering multiple security controls so that failure of one does not compromise the system (Correct answer)
- Encrypting data at all storage depths
- Deeply inspecting all network packets
Correct answer: Layering multiple security controls so that failure of one does not compromise the system
Defense in depth uses multiple overlapping security controls so an attacker must defeat several layers to succeed.
Question 146: A CVE marked 'DISPUTED' in the NVD indicates:
- The CVE ID has been reserved but not yet published
- At least one party disagrees that the reported issue is a vulnerability or that the details are accurate (Correct answer)
- The vulnerability is under active exploitation
- The CVE has been patched by the vendor
Correct answer: At least one party disagrees that the reported issue is a vulnerability or that the details are accurate
A DISPUTED status means there is disagreement between the reporter and vendor (or other parties) about whether the issue constitutes a valid exploitable vulnerability.
Question 147: A qualitative risk assessment is best characterized by the use of:
- Statistical probability tables
- Descriptive ratings such as High, Medium, and Low (Correct answer)
- Exact monetary values
- Precise numerical formulas
Correct answer: Descriptive ratings such as High, Medium, and Low
Qualitative risk assessments use descriptive categories rather than precise numerical or financial values.
Question 148: Which secure coding principle dictates that security controls should fail in a safe manner, denying access when an error occurs?
- Open Design
- Economy of Mechanism
- Complete Mediation
- Fail-Safe Defaults (Correct answer)
Correct answer: Fail-Safe Defaults
Fail-Safe Defaults means that when a system fails or encounters an error, it defaults to a secure state (access denied) rather than an insecure state (access granted).
Question 149: Which ISO 27001 clause addresses management review of the ISMS?
- Clause 10.1
- Clause 6.1
- Clause 8.2
- Clause 9.3 (Correct answer)
Correct answer: Clause 9.3
Clause 9.3 requires top management to review the ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness.
Question 150: A CCP professional encounters an unfamiliar situation while performing iam & multi-factor authentication duties. What is the most appropriate first action?
- Skip the task entirely and move to the next assignment
- Consult relevant standards, guidelines, or a qualified supervisor before proceeding (Correct answer)
- Apply a solution from an unrelated field without verification
- Proceed based on general assumptions to avoid delays
Correct answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in iam & multi-factor authentication, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Question 151: What is the purpose of application whitelisting on endpoints?
- To allow only explicitly pre-approved applications to execute (Correct answer)
- To encrypt application data stored on the endpoint
- To monitor application performance and resource usage
- To block all internet access for unapproved applications
Correct answer: To allow only explicitly pre-approved applications to execute
Application whitelisting permits only authorized applications to run, blocking all unauthorized executables including malware by default.
Question 152: A penetration tester discovers that a web application reflects user input directly in HTTP responses. Which network-layer control would BEST limit exploitation?
- Network Access Control (NAC)
- IDS in detection mode
- Web Application Firewall (WAF) (Correct answer)
- VLAN isolation
Correct answer: Web Application Firewall (WAF)
A WAF inspects HTTP/HTTPS traffic and can detect and block XSS and injection attacks by filtering malicious input patterns before they reach the application.
Question 153: In a federated identity model, what role does the Identity Provider (IdP) play?
- It authenticates users and issues tokens that Service Providers trust (Correct answer)
- It manages firewall rules for authenticated sessions
- It encrypts data between the user and Service Provider
- It stores user passwords locally at each service
Correct answer: It authenticates users and issues tokens that Service Providers trust
The IdP authenticates users and issues assertions or tokens (e.g., SAML assertions, JWTs) that Service Providers accept as proof of authentication.
Question 154: Which DMZ architecture places web servers between two separate firewalls with different vendors?
- Bastion host DMZ
- Dual-homed host DMZ
- Screened subnet DMZ
- Dual-firewall DMZ (Correct answer)
Correct answer: Dual-firewall DMZ
A dual-firewall DMZ uses two firewalls (often from different vendors) to isolate the DMZ, reducing the risk of a single firewall compromise exposing internal networks.
Question 155: A SIEM rule triggers an alert every time a user accesses more than 50 files within 5 minutes. What type of detection logic is this?
- Heuristic behavioral analysis
- Signature-based detection
- Machine learning classification
- Anomaly threshold detection (Correct answer)
Correct answer: Anomaly threshold detection
Triggering on a fixed count threshold (50 files in 5 minutes) is anomaly threshold detection, which flags activity exceeding defined limits.
Question 156: What is the purpose of a 'patch staging environment' in the patch management process?
- To notify stakeholders about upcoming patches
- To store backup copies of original software before patching
- To test patches on representative systems before production deployment to catch regressions (Correct answer)
- To generate compliance reports on patch status
Correct answer: To test patches on representative systems before production deployment to catch regressions
A staging environment mirrors production and is used to validate patches for compatibility and stability before they are pushed to live systems.
Question 157: What is the role of compliance in cybersecurity?
- Compliance only applies to financial systems.
- Compliance is not important in cybersecurity.
- Compliance ensures organizations meet legal and regulatory requirements for securing data and networks. (Correct answer)
- Compliance focuses on employee behavior only.
Correct answer: Compliance ensures organizations meet legal and regulatory requirements for securing data and networks.
Compliance in cybersecurity ensures that organizations adhere to various legal, regulatory, and industry-specific requirements for securing data and networks. By meeting these mandates, such as GDPR or HIPAA, organizations avoid legal penalties, build trust with customers, and implement a baseline level of security best practices. It demonstrates due diligence in protecting sensitive information.
Question 158: What is the primary purpose of a Cloud Workload Protection Platform (CWPP)?
- To provide visibility and protection for workloads across hybrid and multi-cloud environments (Correct answer)
- To manage user identity and access provisioning
- To configure cloud network topology
- To manage cloud billing and cost optimization
Correct answer: To provide visibility and protection for workloads across hybrid and multi-cloud environments
CWPPs are designed to secure workloads (VMs, containers, serverless) across hybrid and multi-cloud environments with unified visibility.
Question 159: An organization wants to measure how quickly it identifies a breach after it occurs. Which metric directly reflects this capability?
- Recovery Time Objective (RTO)
- Mean Time to Detect (MTTD) (Correct answer)
- Mean Time to Respond (MTTR)
- Recovery Point Objective (RPO)
Correct answer: Mean Time to Detect (MTTD)
Mean Time to Detect (MTTD) measures the average elapsed time between when an intrusion begins and when the security team first identifies it.
Question 160: What is incident response in cybersecurity?
- Incident response refers to network monitoring only.
- Incident response involves solely tracking network performance.
- Incident response includes identifying, managing, and mitigating security incidents. (Correct answer)
- Incident response involves creating backup copies of data.
Correct answer: Incident response includes identifying, managing, and mitigating security incidents.
Incident response is a structured approach to handling and managing the aftermath of a security breach or cyberattack. It encompasses a series of steps, including identifying the incident, containing its spread, eradicating the threat, recovering affected systems, and conducting post-incident analysis. The goal is to minimize damage, restore normal operations swiftly, and learn from the event to prevent future occurrences.
Question 161: What is 'log normalization' and why is it critical for SIEM effectiveness?
- Removing duplicate log entries to improve query performance
- Compressing logs to reduce storage costs, enabling more data to be retained
- Converting logs from various formats into a consistent schema so correlation rules can work across all sources (Correct answer)
- Encrypting logs at rest to meet compliance requirements
Correct answer: Converting logs from various formats into a consistent schema so correlation rules can work across all sources
Log normalization converts heterogeneous log formats into a standard schema, enabling correlation rules to reference consistent field names regardless of the originating source.
Question 162: A CCP professional encounters an unfamiliar situation while performing network perimeter defense duties. What is the most appropriate first action?
- Consult relevant standards, guidelines, or a qualified supervisor before proceeding (Correct answer)
- Skip the task entirely and move to the next assignment
- Proceed based on general assumptions to avoid delays
- Apply a solution from an unrelated field without verification
Correct answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in network perimeter defense, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Question 163: Which legal theory allows a plaintiff to sue for damages when a data breach results from a defendant's failure to meet an industry standard of care?
- Tortious interference
- Unjust enrichment
- Res ipsa loquitur
- Negligence per se (Correct answer)
Correct answer: Negligence per se
Negligence per se applies when a defendant violates a statute or regulation that establishes the standard of care, and that violation causes harm.
Question 164: What is the primary purpose of a Privileged Identity Management (PIM) solution?
- To automate SSO configuration across cloud providers
- To enforce MFA for standard user accounts
- To manage end-user password resets
- To provide on-demand, time-limited elevation of privileged access with full audit trails (Correct answer)
Correct answer: To provide on-demand, time-limited elevation of privileged access with full audit trails
PIM solutions like Azure AD PIM enable just-in-time privileged access, requiring approval and time-bounding elevated rights to minimize standing privilege exposure.
Question 165: What does the CVE identifier format CVE-2023-12345 indicate?
- The vulnerability severity score is 12,345
- The CVE was patched in 2023
- The vulnerability was assigned in 2023 with sequence number 12345 (Correct answer)
- The vendor ID is 12345
Correct answer: The vulnerability was assigned in 2023 with sequence number 12345
CVE identifiers follow the format CVE-[year]-[sequence], where the year reflects when the CVE ID was assigned, not when the vulnerability was discovered or patched.
Question 166: How is Annual Loss Expectancy (ALE) calculated?
- Asset value minus controls cost
- ARO divided by asset value
- SLE divided by ARO
- SLE multiplied by ARO (Correct answer)
Correct answer: SLE multiplied by ARO
ALE equals Single Loss Expectancy (SLE) multiplied by Annual Rate of Occurrence (ARO), representing expected yearly financial loss.
Question 167: Which TLS component proves the server's identity to the client during the handshake process?
- Cipher suite
- Session key
- Digital certificate (Correct answer)
- MAC address
Correct answer: Digital certificate
The server presents a digital certificate signed by a trusted CA, allowing the client to verify the server's identity before establishing an encrypted session.
Question 168: What is the role of an Intrusion Detection System (IDS)?
- To monitor network traffic and detect potential security threats or breaches. (Correct answer)
- To store backup copies of network data.
- To increase the speed of network traffic.
- To prevent unauthorized network connections.
Correct answer: To monitor network traffic and detect potential security threats or breaches.
An Intrusion Detection System (IDS) plays a vital role by continuously monitoring network traffic and system activity for suspicious patterns, known attack signatures, or policy violations. When potential security threats or breaches are detected, the IDS generates alerts. This allows security teams to investigate and respond promptly, preventing or mitigating damage from cyberattacks.
Question 169: What is a 'push notification' MFA attack (also called MFA fatigue)?
- Intercepting push notifications over unencrypted Wi-Fi
- Exploiting push notification encryption weaknesses
- Sending phishing emails to override MFA settings
- Flooding a user's authenticator app with approval requests hoping the user approves one out of frustration (Correct answer)
Correct answer: Flooding a user's authenticator app with approval requests hoping the user approves one out of frustration
MFA fatigue attacks bombard users with repeated push authentication requests until the user accidentally or frustratedly approves one, granting attacker access.
Question 170: Which Zero Trust principle requires that all network traffic be verified regardless of whether it originates inside or outside the corporate perimeter?
- Least privilege access
- Never trust, always verify (Correct answer)
- Separation of duties
- Defense in depth
Correct answer: Never trust, always verify
The Zero Trust principle of 'never trust, always verify' eliminates implicit trust based on network location, requiring continuous verification of all connections.
Question 171: An organization deploys a network device that inspects traffic up to Layer 7 and can block application-specific threats. What type of device is this?
- Stateful firewall
- Load balancer
- Next-Generation Firewall (NGFW) (Correct answer)
- Packet filter
Correct answer: Next-Generation Firewall (NGFW)
NGFWs perform deep packet inspection at Layer 7, enabling application awareness and the ability to detect and block sophisticated application-layer threats.
Question 172: What is residual risk?
- Risk remaining after security controls have been applied (Correct answer)
- Risk associated only with third-party vendors
- The original risk before any assessment
- Risk completely eliminated by controls
Correct answer: Risk remaining after security controls have been applied
Residual risk is the level of risk that persists after all security controls have been implemented.
Question 173: What risk does applying a cumulative patch rollup introduce compared to individual patches?
- It reduces the number of reboots required
- It may include previously deferred patches that were intentionally skipped due to compatibility concerns (Correct answer)
- It always increases system performance
- It eliminates the need for regression testing
Correct answer: It may include previously deferred patches that were intentionally skipped due to compatibility concerns
Cumulative rollups bundle multiple patches together, which may force installation of previously excluded patches, potentially reintroducing compatibility issues that were carefully managed.
Certified CMMC Professional (CCP)
The CCP validates foundational knowledge of the Cybersecurity Maturity Model Certification (CMMC) framework, covering ecosystem roles, governance, model implementation, assessment processes, and scoping for handling Federal Contract Information and Controlled Unclassified Information.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds