CC Practice Questions
Prepare for CC with more than an answer.
- Exam fee
- $175 USD
- Level
- Certificate-Level
- Valid for
- First renewal: 9-12 months after passing, then 3 years
Domains covered on the exam 5
- Initiating Cardiac Monitoring Services9%
- Administering Cardiac Tests9%
- Analyzing Normal Rhythms16%
- Analyzing Abnormal Rhythms60%
- Processing Cardiac Test Findings6%
- 1
A business process requires a Recovery Point Objective (RPO) of 10 minutes. Which backup strategy is most appropriate to meet this requirement?
Show answer details
Correct answer: C
RPO of 10 minutes means the business can only lose 10 minutes of data. Tape or daily backups have an RPO of 24 hours. Only continuous replication/mirroring can achieve a near-zero or low-minute RPO.
- 2
Select TWO characteristics that distinguish a 'Hot Site' from a 'Cold Site' in disaster recovery. (Select TWO)
Show answer details
Correct answer: A, C
A hot site is a mirror of the production environment with hardware and software ready to go.
Hot sites typically have current data loaded, allowing for immediate switchover. Cold sites have no data or hardware installed.
- 3
A system administrator needs to configure a network device. They want to ensure that if a change causes an error, the previous valid configuration can be restored immediately. This practice is part of:
Show answer details
Correct answer: B
Change Management processes include rollback plans (backout procedures) to restore systems to a known good state if a change fails.
- 4
Which of the following is an example of a 'Detective' physical control?
Show answer details
Correct answer: B
Detective controls identify and alert when an incident occurs. An alarm detects motion and alerts security. A fence is preventive (deterrent/delay). A lock is preventive.
- 5
In a Mandatory Access Control (MAC) environment, access is determined primarily by:
Show answer details
Correct answer: B
MAC uses security labels (e.g., Secret, Top Secret) assigned to objects and clearance levels assigned to subjects. The operating system enforces access based on these labels, not user discretion.
- 6
A secure facility uses a specialized entry system where a person must pass through a first door, which locks behind them, before the second door opens. This area allows for identity verification and prevents tailgating. What is this physical control called?
Show answer details
Correct answer: C
A mantrap (or access control vestibule) is a small room with two doors. The first must close and lock before the second opens, effectively preventing tailgating and allowing for secondary verification.
- 7
When implementing biometric authentication, the 'False Acceptance Rate' (FAR) refers to:
Show answer details
Correct answer: B
FAR (Type II error) is the likelihood that an unauthorized user is incorrectly identified as a valid user and granted access. This is a critical security risk.
- 8
A global financial institution is implementing a new security framework. The Chief Information Security Officer (CISO) emphasizes that while technical defenses are crucial, the organization must ensure that all employees understand their responsibilities and the consequences of non-compliance. Which governance document should be primarily established to provide this high-level authority and direction?
Show answer details
Correct answer: C
A security policy is a high-level document that outlines the organization's security goals, responsibilities, and enforcement. It provides the necessary authority and strategic direction. Standards are mandatory specific rules, and procedures are step-by-step instructions, both of which support the policy but do not provide the high-level authority themselves.
- 9
During a risk assessment meeting, the security team identifies a legacy server that contains non-critical data. The cost to upgrade the server's security controls exceeds the value of the data it processes. The management team decides to continue operating the server without additional controls. Which risk treatment strategy has management adopted?
Show answer details
Correct answer: C
Risk acceptance occurs when an organization decides that the cost of countermeasures outweighs the potential loss or impact of the risk, and therefore chooses to operate with the known risk. Mitigation would involve applying controls; avoidance would stop the activity; transfer would involve insurance.
- 10
A security consultant is explaining the concept of defense-in-depth to a client. The client recently installed a biometric scanner (Physical Control) and a firewall (Technical Control). To complete the triad of security control categories, which of the following should be implemented?
Show answer details
Correct answer: B
Security controls are categorized into Physical, Technical (Logical), and Administrative. The client has Physical and Technical controls. Employee background checks are an Administrative (or Managerial) control, completing the triad.
