CTP Security & Risk Management Flashcards
6 cards from real CTP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CTP Security & Risk Management flashcards as text
Which security principle dictates that users and systems should only be granted the minimum level of access required to perform their job functions?
Answer: Principle of least privilege
The principle of least privilege minimizes the attack surface by restricting access rights to only those necessary for legitimate work.
In risk management, what does the formula Risk = Likelihood × Impact represent?
Answer: A qualitative method to prioritize risks by combining their probability and consequence
Multiplying likelihood by impact produces a risk score that allows teams to rank and prioritize risks for mitigation efforts.
What is the purpose of a penetration test in a technical security program?
Answer: To simulate real-world attacks to identify exploitable vulnerabilities before malicious actors do
Penetration testing proactively identifies security weaknesses by simulating attacker techniques in a controlled, authorized environment.
Which cryptographic concept ensures that a sender cannot later deny having sent a message?
Answer: Non-repudiation
Non-repudiation, typically achieved through digital signatures, provides proof of origin so senders cannot deny having sent a message.
A CTP professional is implementing a disaster recovery plan. What does RTO (Recovery Time Objective) define?
Answer: The maximum acceptable time to restore a system after a failure
RTO defines how quickly a system must be restored and operational after an outage to meet business continuity requirements.
What is a threat model, and how is it used in secure system design?
Answer: A structured analysis of potential threats, attack surfaces, and mitigations for a system
Threat modeling systematically identifies assets, threats, and countermeasures during design to proactively reduce security risks before deployment.