CC CC - Certified in Cybersecurity Questions and Answers
What is a security token used to authenticate a user to a web application, typically after they log in?
Which element of the security policy framework includes recommendations that are NOT binding?
A CISO documents a policy establishing acceptable cloud use for all staff. This is an example of:
A prolonged, targeted cyberattack where an intruder remains undetected for an extended period is called:
Information should be consistently and readily accessible for authorized parties.
Duke would like to restrict users from accessing a list of prohibited websites while connected to his network. Which control would BEST achieve this objective?
Which addresses are reserved for internal network use and are not routable on the Internet?
A collection of actions that must be followed to complete a task or process in accordance with a set of rules is known as:
Why is the recovery of IT often crucial to the recovery and sustainment of business operations?
Events with negative consequences such as crashes, floods, defacement, or malicious code execution are called:
A security event in which an intruder gains or attempts unauthorized access to a system is called:
A company wants employees to access resources from anywhere in the world. Which access control model is best?
You experienced a power outage that disrupted access to your data center. What type of security concern occurred?
An attack in which a user authenticated to a server unknowingly invokes unwanted actions after visiting a malicious website is known as:
A portion of the network exposed to the outside world with additional controls is called:
Exhibit.
What kind of vulnerability is typically not identifiable through a standard vulnerability assessment?
A centralized organizational function that monitors, detects, and analyzes security events to prevent disruptions is called:
How do IT professionals differentiate between IT problems and security incidents?
An approach using software-based controllers and APIs to direct network traffic:
Walmart has a large e-commerce presence worldwide. Which solution would ensure the LOWEST possible latency for customers using their services?
A company’s governing board decides that only legal services may review third-party contracts. They create a document stating that no other department has permission to do so. This document is a:
What is the term used to denote the inherent set of privileges assigned to a user upon the creation of a new account?
What is the main challenge in achieving non-repudiation in electronic transactions?
Raj wants aphysical deterrent controlto discourage unauthorized entry. Which option best serves this purpose?
Critical business functions are disrupted due to a system outage. Which plan sustains operations?
Communication between end systems is encrypted using a key, often known as ________?
A company wants to prevent employees from bringing unauthorized electronic devices into the workspace. Which physical control is best?
A hacker gains unauthorized access and steals confidential data. What term best describes this?
Which provides integrity services that allow a recipient to verify that a message has not been altered?
A company analyzes system requirements, functions, and interdependencies to prioritize contingency needs. What is this process called?
Which penetration testing technique requires the team to do the MOST work and effort?
Which type of network is set up similar to the internet but is private to an organization? Select the MOST appropriate answer.
To avoid bodily injury claims, a company decides not to offer high-risk services. This is an example of:
A DLP solution should be deployed so it can inspect all forms of data leaving the organization, including:
Which of these components is very likely to be instrumental to any disaster recovery (DR) effort?
The process of how an organization is managed and how decisions are made is called:
Which allows extremely granular restrictions down to individual machines or users?
An employee launched a privilege escalation attack to gain root access on one of the organization’s database servers. The employee has an authorized user account on the server. What log file would MOST likely contain relevant information?
An event that jeopardizes confidentiality, integrity, or availability is called:
A ________ creates an encrypted tunnel to protect your personal data and communications.
Uses multiple types of access controls in layered fashion to avoid monolithic security:
A scam where a malicious website is made to look exactly like a trusted site is called:
The method of distributing network traffic equally across a pool of resources is called:
Finance Server and Transaction Server have restored their original facility after a disaster. What should be moved in FIRST?
Which document identifies the principles and rules governing an organization’s protection of information systems and data?
A one-way spinning door or barrier that allows only one person at a time to enter a building or area.
