CRT Cybersecurity & Risk Management 3 — Questions and Answers
Question 1: A tobacco retailer discovers an unknown USB drive in the parking lot. The safest action is to:
- Plug it into the POS to see its contents
- Give it to a trusted employee to investigate
- Turn it over to IT security or destroy it without plugging it in (Correct answer)
- Use a personal device to check it first
Correct answer: Turn it over to IT security or destroy it without plugging it in
Found USB drives are a common attack vector; plugging them into any company device risks malware infection.
Question 2: What is a 'vulnerability assessment' in the context of a retail tobacco store's risk management plan?
- An employee performance review
- A systematic review identifying weaknesses in security systems and processes (Correct answer)
- A customer satisfaction survey
- A tobacco product quality inspection
Correct answer: A systematic review identifying weaknesses in security systems and processes
A vulnerability assessment identifies gaps in security posture before attackers can exploit them.
Question 3: A CRT candidate is reviewing incident response planning. Which element is MOST critical to include?
- A list of tobacco product SKUs
- Clear roles, responsibilities, and communication steps during a security incident (Correct answer)
- Employee vacation schedules
- Supplier discount codes
Correct answer: Clear roles, responsibilities, and communication steps during a security incident
An effective incident response plan defines who does what and how to communicate, enabling faster and less damaging responses.
Question 4: Encryption of customer data at rest means that data is scrambled when:
- Being sent over the internet
- Stored on a device or server, even when not in transit (Correct answer)
- Being processed by the POS terminal
- Viewed on screen by employees
Correct answer: Stored on a device or server, even when not in transit
Encryption at rest protects stored data so it is unreadable to unauthorized parties even if the storage device is stolen.
Question 5: Which of the following is the BEST description of a 'social engineering' attack?
- Hacking software vulnerabilities using code exploits
- Manipulating people into revealing confidential information or performing actions (Correct answer)
- Installing malware through email attachments only
- Flooding a network with traffic to cause downtime
Correct answer: Manipulating people into revealing confidential information or performing actions
Social engineering exploits human psychology rather than technical vulnerabilities to gain unauthorized access or information.
Question 6: A tobacco retailer's business continuity plan should PRIMARILY ensure:
- Products are discounted during emergencies
- Critical business operations can continue or quickly resume after a disruption (Correct answer)
- All employees work overtime during outages
- Suppliers are notified of inventory levels daily
Correct answer: Critical business operations can continue or quickly resume after a disruption
Business continuity planning minimizes operational downtime by establishing procedures to maintain essential functions during disruptions.
Question 7: An employee who leaves a tobacco company should have system access:
- Removed within 30 days
- Retained for one year in case they return
- Removed immediately upon departure (Correct answer)
- Transferred to their personal email
Correct answer: Removed immediately upon departure
Immediate access revocation prevents former employees from accessing systems with potentially malicious intent.
A tobacco retailer discovers an unknown USB drive in the parking lot.
The safest action is to: