Practice for the CC Exam Preparation exam with 20 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which of these is not a common goal of a threat actor?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the #2: CC Exam Preparation (100) practice test →
What you will practice
- Which of these is not a common goal of a threat actor?
- Data stored on a USB drive being passed around an office is an example of:
- When an incident occurs, which of the following is NOT a primary responsibility of an organization's incident…
- An authorized employee swipes their badge to unlock the door to a secure research facility. A second individu…
- What does the term 'data remanence' refer to?
- What is the primary objective of degaussing?
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. Which of these is not a common goal of a threat actor?
Answer: D. Allocation
Allocation is not a standard threat actor goal, as malicious actors typically focus on disclosure, alteration, or denial of service. Allocation is a routine administrative task, which helps eliminate the other options.
Q2. Data stored on a USB drive being passed around an office is an example of:
Answer: A. Data at rest
Data at rest refers to information residing on storage media, such as a USB drive sitting on a desk. Data in transit applies to data actively moving across a network, which rules out the network options.
Q3. When an incident occurs, which of the following is NOT a primary responsibility of an organization's incident response team?
Answer: D. Communicating with top management regarding the circumstances of the cybersecurity event
Incident response teams focus on technical containment, assessing damage, and restoring secure operations. Executive communication is typically handled by designated management or public relations roles, rather than the technical responders.
Q4. An authorized employee swipes their badge to unlock the door to a secure research facility. A second individual, who appears to be an employee but does not present a badge, catches the door before it closes and walks in directly behind the…
Answer: C. Tailgating
Tailgating is an unauthorized person following an authorized user through a secure door without their consent. Distinguishing this from piggybacking relies on whether the authorized user knowingly held the door, which can be highly subjective.
Q5. What does the term 'data remanence' refer to?
Answer: A. Data left over after routine removal and deletion
Data remanence refers to the residual data left on storage media after standard deletion methods are used. Because deletion often only marks space as available, forensic tools can recover this remanent data without proper sanitization.
Q6. What is the primary objective of degaussing?
Answer: D. Erasing the data on a disk
Degaussing exposes magnetic storage media to a powerful magnetic field to securely erase data and prevent recovery. Options mentioning noise reduction or side channel attacks describe unrelated concepts that do not support secure sanitization.
Q7. At which of the OSI layers do TCP and UDP work?
Answer: A. Transport Layer
TCP and UDP are core protocols that operate at the transport layer of the OSI model. The other layers listed handle different functions, such as raw data transmission at the physical layer or application services at the application layer.
Q8. Which of these is an example of a MAC address?
Answer: B. 00-51-02-1F-58-F6
A Media Access Control address is a hardware identifier formatted as six groups of two hexadecimal digits. The other options represent an IPv6 address, an IPv4 address, and an invalid short string.
Q9. As an (ISC)² member, you are expected to perform with due care. What does 'due care' specifically mean?
Answer: D. Do what is right in each situation you encounter on the job
Due care is the prudent person rule, meaning you must take reasonable steps to protect organizational assets. While patching and research are important tasks, the core concept is simply doing what is right in any given professional situation.
Q10. Which of these is NOT a characteristic of the cloud?
Answer: A. Zero Customer Responsibility
Cloud computing operates on a shared responsibility model, meaning the customer always retains some accountability. Rapid elasticity, measured service, and broad network access are all essential cloud characteristics defined by the ISC2 study guide.
Q11. Which of these attacks take advantage of inadequate input validation on websites?
Answer: A. Cross-Site Scripting
Cross-Site Scripting exploits vulnerabilities where a website fails to sanitize user input before displaying it. Phishing, Trojans, and rootkits rely on social engineering or system compromise rather than direct web input validation flaws.
Q12. Which of these is NOT one of the ISC2 ethics canons?
Answer: C. Consider the social consequences of the systems you are designing
Considering social consequences is a good practice, but it is not one of the four official ISC2 ethics canons. The actual canons mandate protecting society, acting honorably, providing diligent service, and advancing the profession.
Q13. Which of the following threat-to-location pairings is correct?
Answer: A. Ransomware → File Server
Ransomware most logically targets a file server because it stores shared documents and critical data. The other options are mismatched physical threats, such as a blizzard impacting a data center rather than a reception desk.
Q14. Which of these is an attack whose PRIMARY goal is to gain access to a target system through falsified identity?
Answer: B. Spoofing
Spoofing is an attack whose primary goal is to gain unauthorized access by falsifying identity. The other attack types listed have different primary goals, such as overwhelming a target to disrupt operations in a distributed denial of service attack.
Q15. Which of these terms refers to a collection of fixes?
Answer: B. Service Pack
A service pack comprises a collection of updates, fixes, or enhancements delivered as a single installable package. A patch or hotfix is typically an individual quick-repair job for a specific software issue, rather than a comprehensive cumulative bundle.
Q16. In an Access Control List (ACL), the element that determines what permissions you have is:
Answer: A. The rule
An Access Control List consists of rules that specify the permissions granted or denied to a subject for a particular object. Firmware is irrelevant here, while the subject and object represent the user and the resource rather than the permissions themselves.
Q17. Which of these tools is MOST likely to detect an XSS vulnerability?
Answer: C. Web application vulnerability scanner
A web application vulnerability scanner interacts dynamically with a web application to identify runtime flaws like cross-site scripting. Network scanners and intrusion detection systems focus on network infrastructure and traffic, while static testing examines source code without executing it.
Q18. What does the term LAN refer to?
Answer: A. A network on a building or limited geographical area
A Local Area Network connects devices within a limited geographical area, such as a single building. Wide area networks cover large geographical distances, while the other options describe networking hardware like switches or security appliances like firewalls.
Q19. Which of these is NOT a typical component of a comprehensive Business Continuity Plan (BCP)?
Answer: B. A cost prediction of the immediate response procedures
A business continuity plan focuses on restoring operations and includes team lists, response checklists, and notification call trees. Predicting the immediate response costs is a financial exercise, not a standard operational component of a continuity plan during a disaster.
Q20. During a strategic planning meeting, an organization's leadership discusses how much risk the business can reasonably accept while pursuing its goals. The leadership team agrees on a specific level of potential data or financial loss that…
Answer: C. Risk Threshold
Risk tolerance is the acceptable level of variance an organization is willing to accept around its broader risk appetite. The wording describing an agreed limit blurs the line between tolerance and threshold, making tolerance a highly defensible answer on certification exams.
More #2: CC Exam Preparation (100) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.