Certified Cyber Resilience Professional (CCRP)
Exam QUESTIONS AND VERIFIED ANSWERS WITH
RATIONALES
Certified Cyber Resilience Professional (CCRP) Exam —Practice Questions
10 MOST-TESTED EXAM COVERAGE AREAS
1. Cyber Resilience Fundamentals — Meaning of cyber resilience, difference between
cybersecurity and resilience, resilience principles, business objectives, critical services,
dependencies, and maintaining operations during cyber disruption.
2. Governance, Leadership & Cyber Resilience Strategy — Executive leadership, roles and
responsibilities, policies, accountability, risk ownership, communication, program objectives,
resources, and alignment with organizational goals.
3. Risk Assessment, Business Impact & Prepare/Identify — Cyber risk identification, threat
assessment, vulnerabilities, business impact analysis, critical processes, assets, dependencies,
risk priorities, recovery needs, and resilience planning.
4. Protect & Preventive Controls — Access control, authentication, least privilege, security
awareness, data protection, system hardening, network protection, backup protection, vendor
controls, and preventive safeguards.
5. Detect & Continuous Monitoring — Security monitoring, logging, alerts, indicators of
compromise, anomaly detection, incident identification, threat intelligence, detection
processes, and escalation.
6. Incident Response & Crisis Management — Incident classification, response procedures,
containment, communication, decision-making, evidence preservation, crisis teams, stakeholder
coordination, and escalation.
7. Business Continuity & Disaster Recovery — Business continuity planning, recovery strategies,
RTO, RPO, alternate operations, backup and restoration, disaster recovery, continuity of critical
services, and dependencies.
8. Recover & Restoration — System recovery, data restoration, validation, return to normal
operations, recovery priorities, lessons learned, post-incident review, and improvement actions.
9. Exercises, Testing & Continuous Improvement — Tabletop exercises, simulations, testing,
metrics, maturity assessment, corrective actions, lessons learned, plan updates, and continuous
improvement.
10. Frameworks, Standards, Third Parties & Resilience Technology — NIST Cybersecurity
Framework, ISO/IEC 27001, NIST controls, COBIT, regulatory considerations, supply-chain risk,
cloud resilience, critical infrastructure, and technology dependencies. Public CCRP preparation
material also emphasizes integrating cybersecurity with business continuity and disaster
recovery. (Stuvia)
1.
, Page 2 of 150
An organization wants to continue its most important services after a serious cyberattack. Which
concept best supports this goal?
A. Cyber resilience
B. Password management
C. Software development
D. Network installation
Answer: A
Rationale: Cyber resilience combines security, continuity, response, and recovery so important business
services can continue during disruption.
2.
A company wants to understand which business activities would cause the greatest harm if unavailable
after a cyber incident. What should it perform?
A. Business impact analysis
B. Password audit
C. Software upgrade
D. Firewall replacement
, Page 3 of 150
Answer: A
Rationale: A business impact analysis identifies important activities and the effects of their disruption.
3.
A resilience manager is reviewing systems before creating recovery priorities. Which information is most
important to identify first?
A. Critical business services and their dependencies
B. Employee vacation schedules
C. Office furniture locations
D. Marketing campaign colors
Answer: A
Rationale: Critical services and dependencies help determine what must be protected and recovered
first.
4.
A company has strong firewalls but cannot restore operations after ransomware. What important
capability is missing?
, Page 4 of 150
A. Recovery capability
B. Physical security
C. Password complexity
D. Network segmentation
Answer: A
Rationale: Cyber resilience requires the ability to recover and maintain essential operations after an
incident.
5.
Senior leaders are deciding how much money should be invested in cyber resilience. What should guide
this decision most directly?
A. Business risk and organizational priorities
B. Employee opinions only
C. Number of computers alone
D. Age of the company website
Answer: A