CTP Security & Risk Management Flashcards
6 cards from real CTP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CTP Security & Risk Management flashcards as text
What is the primary goal of a Business Impact Analysis (BIA) in a continuity planning program?
Answer: To identify critical business functions and quantify the impact of disruptions on them
A BIA identifies which business processes are most critical and determines the financial and operational consequences of their disruption.
In the context of secure software development, what does OWASP Top 10 represent?
Answer: A list of the most critical web application security risks, updated periodically by OWASP
The OWASP Top 10 is a widely referenced awareness document listing the ten most critical and prevalent web application security vulnerabilities.
What is the difference between symmetric and asymmetric encryption?
Answer: Symmetric uses one shared key for both encryption and decryption; asymmetric uses a public/private key pair
Symmetric encryption is faster but requires secure key exchange, while asymmetric encryption uses mathematically linked key pairs to solve the key distribution problem.
A CTP professional is asked to implement Role-Based Access Control (RBAC). What is the core concept of RBAC?
Answer: Permissions are assigned to roles, and users are assigned to roles rather than getting permissions directly
RBAC simplifies access management by grouping permissions into roles so administrators manage roles rather than individual user permissions.
What is the purpose of an incident response plan (IRP) in a technical organization?
Answer: To define procedures for detecting, containing, eradicating, and recovering from security incidents
An IRP establishes clear roles, procedures, and communication steps so the organization can respond swiftly and effectively to security incidents.
Which concept describes the practice of layering multiple independent security controls so that failure of one does not compromise overall security?
Answer: Defense in depth
Defense in depth layers multiple security controls (network, host, application, data) so that an attacker must bypass several barriers to reach a target.