Practice for the #2: CC Exam Preparation (100) exam with 20 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: What is the PRIMARY goal of a Change Management Policy?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the #2: CC Exam Preparation (100) practice test →
What you will practice
- What is the PRIMARY goal of a Change Management Policy?
- Which of the following is NOT typically installed as a result of an infection?
- Which of these terms refers to threats with unusually high technical and operational sophistication, spanning…
- Which protocol is responsible for negotiating security associations and cryptographic keys in IPSec?
- Which of the following is NOT a part of risk assessment?
- Requiring a specific user role to access resources is an example of which access control model?
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. What is the PRIMARY goal of a Change Management Policy?
Answer: D. To guarantee that system changes are performed without negatively affecting business operations
A change management policy ensures that system modifications occur smoothly without negatively affecting business operations. Options describing network usage, system creation, or patching confuse this process with acceptable use, system development, or patch management policies.
Q2. Which of the following is NOT typically installed as a result of an infection?
Answer: A. Logic Bomb
A logic bomb is malicious code intentionally inserted into software by an insider, rather than being installed remotely through an external infection. Trojans, keyloggers, and backdoors are typical malware payloads delivered through standard infection vectors like phishing.
Q3. Which of these terms refers to threats with unusually high technical and operational sophistication, spanning months or even years?
Answer: C. APT
An advanced persistent threat describes a highly sophisticated, stealthy attack that maintains unauthorized access for extended periods. The other options represent specific attack techniques or malware types rather than long-term operational campaigns.
Q4. Which protocol is responsible for negotiating security associations and cryptographic keys in IPSec?
Answer: B. IKE
Internet Key Exchange handles security association and cryptographic key negotiations for IPsec VPN tunnels. Diffie-Hellman is just one cryptographic algorithm used within IKE, while SSL and TLS secure application-level traffic instead.
Q5. Which of the following is NOT a part of risk assessment?
Answer: A. Risk mitigation
Risk mitigation is the subsequent step where controls are implemented, rather than being part of the assessment phase. Risk identification, evaluation, and prioritization are the core analytical components used to understand threats before treatment.
Q6. Requiring a specific user role to access resources is an example of which access control model?
Answer: B. Role-Based Access Control (RBAC)
Role-based access control assigns permissions based on the user's organizational role or job function. Mandatory and discretionary models rely on data labels or owner discretion, while attribute-based uses complex rules involving multiple factors.
Q7. Which of these is NOT a best practice in access management?
Answer: A. Trust but verify
Trust but verify is an outdated concept replaced by the zero trust model, which requires continuous verification and never grants implicit trust. Granting minimal permissions, requiring justifications, and periodic reviews remain standard practices.
Q8. An organization with affiliates around the world wants to transfer clients personal data from Country A (EU) to Country B (US). What must the organization ensure before transferring the data?
Answer: D. An appropriate legal transfer mechanism is in place
Cross-border data transfers require an appropriate legal safeguard, such as Standard Contractual Clauses or Binding Corporate Rules. The trap is choosing technical controls like encryption, which do not provide a legal basis for international data transfer.
Q9. Which of these CANNOT be a corrective security control?
Answer: C. Bollards
Corrective controls restore operations after an incident, making backups, patches, and recovery plans prime examples. Physical barriers like bollards are preventive controls designed to stop incidents before they occur.
Q10. Which method is COMMONLY used to map live hosts in the network?
Answer: A. Ping sweep
A ping sweep is a network scanning technique used to identify which hosts are actively responding on a network. Traceroute and Wireshark map topology and analyze traffic, whereas a ping sweep specifically finds live hosts.
Q11. Which of these documents is a non-binding agreement that outlines the intentions and terms of cooperation between parties?
Answer: C. MOU
A Memorandum of Understanding is a non-binding agreement documenting the intentions of cooperating parties. Watch out for the MOA trap, which serves a similar purpose but is typically a legally binding contract.
Q12. Which of these entities is responsible for signing an organization's policies?
Answer: B. Senior management
Senior management holds ultimate liability and is responsible for signing organizational security policies. While security engineers or HR may draft the documents, executive sign-off demonstrates required management commitment.
Q13. What is the most important difference between Mandatory Access Control (MAC) and Discretionary Access Control (DAC)?
Answer: A. In MAC, security administrators assign access permissions; in DAC, access permissions are set at the object owner's discretion
Mandatory Access Control relies on administrators enforcing strict security labels, while Discretionary Access Control allows object owners to decide access permissions. The core difference is who holds the decision-making power.
Q14. Which of the following types of malware self-replicates without the need for human intervention?
Answer: B. Worm
A worm is malware that self-replicates and spreads across networks without requiring any user interaction. A virus typically requires a human action to trigger it, whereas Trojans disguise themselves as legitimate software, and rootkits are designed to hide malicious activity.
Q15. The primary objective of a Business Continuity Plan (BCP) is:
Answer: C. To sustain business operations while recovering from a disruption
A Business Continuity Plan ensures that critical business operations continue during and after a disruption. Restoring infrastructure to a previous state is the goal of Disaster Recovery, which is a subset of broader continuity efforts, eliminating the distractors.
Q16. Which IPsec mode is commonly used to establish site-to-site VPNs?
Answer: D. Tunnel mode
IPsec tunnel mode encapsulates the entire original packet and adds a new header, making it ideal for securing traffic between two networks. Transport mode only encrypts the payload and is used for host-to-host communication, which weakens the distractors.
Q17. Which of the following is NOT a type of malware?
Answer: B. Spoofing
Spoofing is a deceptive attack technique used to falsify an identity, not a standalone malicious software program. Trojans, rootkits, and worms are all distinct categories of malware, which quickly eliminates them from consideration.
Q18. Which of these is NOT an effective way to protect an organization from cybercriminals?
Answer: A. Using out-dated anti-malware software
Using outdated anti-malware software fails to protect an organization because it lacks the latest threat definitions. The other options represent standard security controls, making them clearly incorrect for this negative question.
Q19. A high-level executive of an organization receives a malicious email that tries to trick them. Which attack is the perpetrator using?
Answer: A. Whaling
A whaling attack is a targeted phishing attempt aimed specifically at high-level executives or influential individuals. Spear phishing is less precise, and a distributed denial-of-service attack targets system availability rather than people.
Q20. Which of these is a type of detective access control?
Answer: D. Movement Sensors
Movement sensors act as detective controls by alerting security personnel to physical intrusions after they occur. Firewalls are technical preventative controls, while bollards and turnstiles prevent physical access.
More #2: CC Exam Preparation (100) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.