Practice for the #2: CC Exam Preparation (100) exam with 20 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: What does the double colon (::) in an IPv6 address notation represent?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the #2: CC Exam Preparation (100) practice test →
What you will practice
- What does the double colon (::) in an IPv6 address notation represent?
- Which of these is an example of a privacy breach?
- Which type of attack attempts to mislead the user into exposing personal information by sending fraudulent em…
- A security professional should report violations of a company's security policy to:
- A poster reminding users of best password management practices is an example of which type of learning activi…
- When looking for cybersecurity insurance, which of these is the most important objective?
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. What does the double colon (::) in an IPv6 address notation represent?
Answer: D. One or more groups of consecutive zeros
In IPv6 notation, the double colon represents one or more consecutive groups of sixteen-bit hexadecimal zeros. This shorthand rule can only be used once in an address to simplify long strings and improve overall readability without creating ambiguity.
Q2. Which of these is an example of a privacy breach?
Answer: A. Access of private information by an unauthorized person
A privacy breach specifically involves the unauthorized access or exposure of personally identifiable information. Unavailable critical systems represent an availability loss, and general system occurrences or potential exposures do not inherently indicate a privacy compromise.
Q3. Which type of attack attempts to mislead the user into exposing personal information by sending fraudulent emails?
Answer: C. Phishing
Phishing uses fraudulent emails to trick recipients into disclosing sensitive personal information. Cross-site scripting targets website code, while denial-of-service attacks disrupt availability, eliminating those options.
Q4. A security professional should report violations of a company's security policy to:
Answer: B. Company management
Company policy violations must be reported internally to company management for proper handling. Reporting to external authorities or courts is reserved for legal violations, while ethics committees handle individual professional misconduct.
Q5. A poster reminding users of best password management practices is an example of which type of learning activity?
Answer: D. Awareness
Security awareness aims to capture attention and remind users of best practices, which a poster accomplishes perfectly. Training builds specific skills, while education focuses on deeper conceptual understanding.
Q6. When looking for cybersecurity insurance, which of these is the most important objective?
Answer: B. Risk transference
Risk transference is the primary objective of cybersecurity insurance because it shifts the financial burden of a potential loss to a third party. Mitigation reduces risk, while avoidance and acceptance do not involve purchasing insurance.
Q7. What does redundancy mean in the context of cybersecurity?
Answer: C. Conceiving systems with duplicate components so that, if a failure occurs, there will be a backup
Redundancy involves implementing duplicate system components to ensure continuous operation during a failure. Options describing reduced attack surfaces or robust single components focus on system hardening rather than fault tolerance.
Q8. Which type of attack PRIMARILY aims to consume all the available resources, thereby making an organization's service inaccessible to its intended users?
Answer: B. Denial of Service
A denial of service attack overwhelms a target with illegitimate traffic to exhaust its resources and disrupt service availability. Trojans and cross site scripting target system integrity or theft rather than resource exhaustion.
Q9. Which of these types of layers is NOT part of the TCP/IP model?
Answer: C. Physical
The standard four layer TCP IP model consists of Application, Transport, Internet, and Network Interface. The Physical layer is explicitly defined in the seven layer OSI model rather than the TCP IP suite.
Q10. Which of these is an example of an exploit?
Answer: D. A sequence of commands to take advantage of a bug
An exploit is a specific sequence of commands or code designed to take advantage of a vulnerability. Options describing exposure or unauthorized access define risks and impacts rather than the exploit mechanism itself.
Q11. Which of these access control models is commonly used in the military?
Answer: C. Mandatory Access Control (MAC)
Mandatory Access Control uses strict centralized classification labels and user clearances, making it ideal for military environments. Discretionary and role based models allow decentralized or broad access that lacks this rigid structure.
Q12. Which of these types of documents is usually THE LEAST formal?
Answer: B. Guidelines
Guidelines offer flexible recommendations and represent the least formal layer of security documentation. Regulations and policies are mandatory rules, while standards enforce strict technical requirements, making them significantly more formal.
Q13. Which of these pairs does NOT constitute Multi-Factor Authentication (MFA)?
Answer: D. Password and username
Multifactor authentication requires combining two or more distinct validation categories. A username and password are both something you know, so they only provide single-factor authentication rather than meeting multifactor requirements.
Q14. What is the PRIMARY purpose of IPSec?
Answer: D. To secure IP communications at the network layer
Internet Protocol Security operates at the network layer to secure communications. The protocol encrypts and authenticates data packets rather than handling user authentication or protecting data stored locally on disk.
Q15. Which of these technologies is the LEAST effective means of preventing shared accounts?
Answer: A. Password complexity requirements
Requiring complex passwords does not stop someone from sharing that password with others. Multifactor methods like biometrics or one-time passwords are far more effective at preventing shared accounts because they require physical presence or dynamic codes.
Q16. When a company collects PII, which policy is required?
Answer: C. Privacy Policy
Organizations must publish a privacy policy detailing how personal information is collected and handled. Acceptable use and remote access policies govern employee behavior, while regulations like GDPR provide legal compliance frameworks.
Q17. Which of these types of credentials is NOT used in multi-factor authentication?
Answer: B. Something you trust
Valid authentication factors are strictly categorized as something you know, something you have, or something you are. Something you trust is not an authentication factor and is merely a distractor designed to confuse test takers.
Q18. Which of these is a COMMON mistake made when implementing record retention policies?
Answer: C. Applying the longest retention periods to the information
A common mistake in records retention is keeping all data for the longest possible period. Over-retention increases storage costs and legal liabilities, which is why organizations must categorize data and apply specific retention schedules.
Q19. A backup that captures the changes made since the latest full backup is an example of:
Answer: B. A differential backup
A differential backup specifically captures all changes made since the last full backup. An incremental backup is the trap here, as it only captures changes made since the most recent backup of any type, not just the full backup.
Q20. After an administrator logs into a secure server, the system automatically captures and stores information about the session, including who accessed the system, when access occurred, and what actions were performed. This information is lat…
Answer: C. Auditing
Auditing is the process of capturing, logging, and preserving security-relevant events to support investigations. Authentication verifies identity, and authorization determines access rights, but neither inherently records the session activities for later review.
More #2: CC Exam Preparation (100) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.