CCP Governance, Compliance & Ethical Hacking 2 — Questions and Answers
Question 1: Which framework provides a set of voluntary cybersecurity standards and best practices developed by NIST primarily for critical infrastructure protection?
- ISO 27001
- NIST CSF (Correct answer)
- COBIT 5
- PCI DSS
Correct answer: NIST CSF
The NIST Cybersecurity Framework (CSF) was developed to help critical infrastructure organizations manage cybersecurity risk using five core functions: Identify, Protect, Detect, Respond, and Recover.
Question 2: During a penetration test, a tester discovers a zero-day vulnerability in a client's production system. What is the MOST appropriate immediate action?
- Exploit it fully to demonstrate impact
- Document and immediately report it to the client's security team (Correct answer)
- Publish the finding publicly to pressure a fix
- Ignore it and focus on the original test scope
Correct answer: Document and immediately report it to the client's security team
Responsible disclosure requires immediately notifying the client's security team so they can assess risk and decide on remediation, staying within the rules of engagement.
Question 3: Which compliance regulation specifically mandates security controls for organizations that process, store, or transmit cardholder data?
- HIPAA
- SOX
- PCI DSS (Correct answer)
- GLBA
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) is the compliance framework specifically governing cardholder data protection for any entity that handles payment card information.
Question 4: A company's security policy states that all employees must complete annual security awareness training. Which governance element does this BEST represent?
- Risk appetite statement
- Security standard
- Security procedure
- Security policy (Correct answer)
Correct answer: Security policy
A security policy is a high-level document that mandates what must be done (such as annual training), while standards and procedures define how to implement those mandates.
Question 5: In ethical hacking, what does the term 'rules of engagement' define?
- The legal penalties for unauthorized access
- The specific boundaries, scope, and constraints agreed upon before testing begins (Correct answer)
- The tools and exploits permitted by open-source licenses
- The NDA terms between tester and client
Correct answer: The specific boundaries, scope, and constraints agreed upon before testing begins
Rules of engagement formally define the scope, allowed techniques, testing windows, and communication protocols that a penetration tester must follow during an engagement.
Question 6: Which type of audit evaluates whether an organization's security controls meet a specific external standard such as SOC 2 or ISO 27001?
- Internal audit
- Compliance audit (Correct answer)
- Operational audit
- Financial audit
Correct answer: Compliance audit
A compliance audit assesses whether an organization's controls and processes conform to external regulatory or standards-based requirements.
Question 7: What is the primary purpose of a Business Impact Analysis (BIA) in a cybersecurity governance program?
- To identify and rank vulnerabilities in software code
- To determine the financial and operational impact of disruptions to critical business functions (Correct answer)
- To assign blame when a security incident occurs
- To create firewall rules based on business needs
Correct answer: To determine the financial and operational impact of disruptions to critical business functions
A BIA identifies critical business functions, their dependencies, and the potential impacts (financial, reputational, legal) if those functions are disrupted, informing RTO and RPO targets.
Which framework provides a set of voluntary cybersecurity standards and best practices developed by NIST primarily for critical infrastructure protection?