#2: CC Exam Preparation (100) Practice Exam Questions and Answers – Part 5/5

Practice for the CC Exam Preparation exam with 19 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which video recording technology is MOST LIKELY to use less storage space?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the #2: CC Exam Preparation (100) practice test →

What you will practice

  • Which video recording technology is MOST LIKELY to use less storage space?
  • When analyzing risks, which of these activities is required?
  • Which of these is NOT a security principle?
  • Which of the following is one of the canons of the (ISC)² Code of Ethics?
  • Which port number corresponds to the Simple Mail Transfer Protocol (SMTP)?
  • Which of the following is NOT a characteristic of a Managed Service Provider (MSP) implementation?

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Which video recording technology is MOST LIKELY to use less storage space?

Answer: C. Motion detection

Motion detection records only when movement occurs, drastically reducing storage requirements. Biometric recognition technologies like facial, retina, and gait recognition require continuous capture and high-resolution imagery, which consumes significantly more data.

Q2. When analyzing risks, which of these activities is required?

Answer: D. Determining the likelihood of occurrence of a set of risks

Determining the likelihood of occurrence is a fundamental requirement of risk analysis to estimate potential impact. Selecting controls happens later during mitigation, and accepting all risks violates standard security policies.

Q3. Which of these is NOT a security principle?

Answer: C. Security Awareness Training

Security awareness training is an administrative control, whereas least privilege, separation of duties, and zero trust are foundational security principles. The key trap is confusing human-focused educational controls with core design principles.

Q4. Which of the following is one of the canons of the (ISC)² Code of Ethics?

Answer: C. Advance and protect the profession

The four canons of the ISC2 Code of Ethics require members to protect society, act honorably, provide competent service, and advance the profession. The other options are subtle distractors that mix in client interests and generic security tasks instead of stating the actual canons.

Q5. Which port number corresponds to the Simple Mail Transfer Protocol (SMTP)?

Answer: A. 25

Simple Mail Transfer Protocol, or SMTP, uses port 25 to route email messages between servers. For the exam, remember the core networking ports like 22 for SSH, 69 for TFTP, and 161 for SNMP to quickly eliminate the distractors.

Q6. Which of the following is NOT a characteristic of a Managed Service Provider (MSP) implementation?

Answer: B. Mediate, execute and decide top-level decisions

A Managed Service Provider handles day-to-day IT infrastructure, monitoring, and technical support, but does not make high-level strategic business decisions. Executive authority remains with the client's leadership, eliminating the other operational and technical duties.

Q7. Which type of exercise goes through a sample of an incident step-by-step, validating what each person will do?

Answer: C. A walk-through exercise

A walk-through exercise methodically reviews incident response steps so every participant understands their specific role. Tabletop exercises are more informal discussion-based scenarios, while simulations actively mimic real conditions to test technical response.

Q8. In the context of risk management, what does Annualized Loss Expectancy (ALE) represent?

Answer: B. The expected cost per year of not performing a given risk-mitigating action

Annualized Loss Expectancy calculates the expected financial cost of a specific risk over the course of a year. It is derived by multiplying the Single Loss Expectancy by the Annualized Rate of Occurrence, making the probability distractors incorrect.

Q9. Which type of recovery site has some or most systems in place, but does not have the data needed to take over operations?

Answer: A. A warm site

A warm site has the necessary hardware and infrastructure pre-installed, but lacks current data, requiring backups to become fully operational. Hot sites and mirrored sites have real-time data ready immediately, whereas cold sites lack equipment entirely.

Q10. Which of these is the primary objective of the PCI-DSS standard?

Answer: D. Secure Credit Cards Payments

The PCI-DSS standard is specifically designed to secure credit card payments and protect cardholder data. Protected health information and change management belong to other frameworks, allowing you to eliminate them immediately.

Q11. In a DAC policy scenario, which of these tasks can only be performed by the owner of the object?

Answer: A. Changing security attributes

Discretionary access control gives object owners the authority to set permissions. Only the owner can change security attributes, while standard actions like read or modify are granted to users based on those assigned permissions.

Q12. Which of these statements is true about cybersquatting?

Answer: C. It is an illegal practice

Cybersquatting is the practice of registering a domain name to profit from someone else's trademark. It is an illegal practice under laws like the Anticybersquatting Consumer Protection Act, which protects trademark owners from this deceptive behavior.

Q13. Which department in a company is NOT typically involved in a Disaster Recovery Plan (DRP)?

Answer: C. Financial

A disaster recovery plan is primarily an IT-focused extension of business continuity, so the financial department is typically not a core operational responder. However, because financial loss is central to disaster recovery, a reasonable test-taker could defend their involvement, creating slight ambiguity.

Q14. While performing background checks on new employees, which of these can NEVER be an attribute for discrimination?

Answer: C. References, education, political affiliation, employment history

Discriminating based on political affiliation is unacceptable, whereas credit, education, and employment history are legally reviewed depending on the role. Use the cue of protected personal beliefs to eliminate standard professional background factors.

Q15. Acting ethically is mandatory for ISC2 members. Which of these is NOT considered unethical?

Answer: D. Having fake social media profiles and accounts

The ISC2 Code of Ethics explicitly prohibits actions like compromising privacy, seeking unauthorized access, and disrupting internet services. Having a fake social media profile is not inherently an ethics violation under the canons, unlike the other listed activities.

Q16. Which of these social engineering attacks send emails to specific individuals who are not executives of the organization?

Answer: A. Spear phishing

Spear phishing targets specific individuals using gathered intelligence. Whaling is the trap here, but it specifically targets high-level executives, whereas spear phishing can target any employee within an organization.

Q17. Which of these properties is NOT guaranteed by a Message Authentication Code (MAC)?

Answer: A,D. Anonymity || Non-repudiation

A Message Authentication Code provides integrity and authenticity but does not provide non-repudiation because the symmetric key is shared. Non-repudiation requires asymmetric cryptography, like digital signatures, to prove origin uniquely.

Q18. The PRIMARY objective of a security baseline is to establish a minimum understood and acceptable level of security requirements.

Answer: B. … a minimum understood and acceptable level of security requirements

A security baseline establishes a minimum, agreed-upon level of security requirements for an organization. While baselines include configuration settings, their primary strategic goal is defining this acceptable minimum standard to ensure consistent protection across systems.

Q19. The BEST defense method to stop a replay attack is to:

Answer: B. Use an IPSec VPN

Using an IPsec VPN prevents replay attacks because the protocol tracks packet sequencing and drops captured packets that are resent. Message digesting alone cannot stop an attacker from resending a validly hashed message, making it an ineffective defense.

More #2: CC Exam Preparation (100) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top