CTPRP CERTIFICATION EXAM 2025
STUDYGUIDE QUESTIONS AND 100%
ANSWERS
components of a cloud vendor assessment program
Correct Answer - review of audit form attestation reports
- security services documentation
- image snapshot approval and mgmt process
- patching responsibility
first layer of defense in physical and environmental
security Correct Answer assess the perimeter
monitoring and controls established for infrastructure
Correct Answer - video surveillance
- electronic access control at essential ingress/egress
points
- correlation of the video an dcard access data
- retention of video and logs for forensics
asset management program Correct Answer process for
documenting and maintaining an inventory of hardware,
software and information assets (includes a data
classification process)
asset owner Correct Answer ensures assets are
inventoried, properly classified and protected, defines and
reviews access restrictions and classifications, reviews
,locations of where assets and data are being used, and
ensures proper handling of an asset
assets Correct Answer - hardware
- software
- data
- facilities
asset management program Correct Answer should be
approved by senior management and communicated to all
appropriate personnel
potential egress points Correct Answer -email
-USB ports
-internet
-printing
-network
DLP scanning Correct Answer -SSN/National ID
-account numbers
-functionality
-email and attachments
Commercial DLP software programs Correct Answer -
capabilities vs configuration
-monitor vs block
-thresholds for acceptance
-escalation processes
-roles for review
,documented operating procedures Correct Answer ensure
the effective mgmt, operation, integrity and security of
information systems and data
change management/change control policy Correct
Answer -change in network
-change in systems
-application updates
-code changes
-back out procedures
-problem mgmt
-environmental control over application development
Business Impact Analysis (BIA) Correct Answer identifies
the third party's critical processes and associated systems
and prioritizes the effect of a business disruption based on
the impact and likelihood
Recovery Point Objective (RPO) Correct Answer point in
time in the past to which you will recover
Recovery Time Objective (RTO) Correct Answer point in
time in the future at which you will be up and running
again
disaster recovery Correct Answer process of resuming
technical operations at a back-up site while recovering
operations at the primary site
BC/DR testing Correct Answer uses the actual written
plans, processes and procedures in an exercise or table
, top review to test validity and accuracy of the
documentation to resume business operations
pandemic planning Correct Answer focuses on external
events that impact infrastructure, environmental, social
factors (crime, political, etc.)
Incident Mgmt Program Correct Answer -notiifcation to all
affected customers of the third party
-provides customers with appropriate data to respond to
the issue
-consider the timing needed for customers to respond to
the issue
-allow customer to activate own program
-coordinate with law enforcement and appropriate
regulatory agencies as required
incident response Correct Answer -detection, investigation
and forensic evidence integrity
-event containment, post mortem and remediation
-management communication and reporting
incident notification plan Correct Answer -law enforcement
-regulators
-clients
-service providers
-employees
-external stakeholders
-media
STUDYGUIDE QUESTIONS AND 100%
ANSWERS
components of a cloud vendor assessment program
Correct Answer - review of audit form attestation reports
- security services documentation
- image snapshot approval and mgmt process
- patching responsibility
first layer of defense in physical and environmental
security Correct Answer assess the perimeter
monitoring and controls established for infrastructure
Correct Answer - video surveillance
- electronic access control at essential ingress/egress
points
- correlation of the video an dcard access data
- retention of video and logs for forensics
asset management program Correct Answer process for
documenting and maintaining an inventory of hardware,
software and information assets (includes a data
classification process)
asset owner Correct Answer ensures assets are
inventoried, properly classified and protected, defines and
reviews access restrictions and classifications, reviews
,locations of where assets and data are being used, and
ensures proper handling of an asset
assets Correct Answer - hardware
- software
- data
- facilities
asset management program Correct Answer should be
approved by senior management and communicated to all
appropriate personnel
potential egress points Correct Answer -email
-USB ports
-internet
-printing
-network
DLP scanning Correct Answer -SSN/National ID
-account numbers
-functionality
-email and attachments
Commercial DLP software programs Correct Answer -
capabilities vs configuration
-monitor vs block
-thresholds for acceptance
-escalation processes
-roles for review
,documented operating procedures Correct Answer ensure
the effective mgmt, operation, integrity and security of
information systems and data
change management/change control policy Correct
Answer -change in network
-change in systems
-application updates
-code changes
-back out procedures
-problem mgmt
-environmental control over application development
Business Impact Analysis (BIA) Correct Answer identifies
the third party's critical processes and associated systems
and prioritizes the effect of a business disruption based on
the impact and likelihood
Recovery Point Objective (RPO) Correct Answer point in
time in the past to which you will recover
Recovery Time Objective (RTO) Correct Answer point in
time in the future at which you will be up and running
again
disaster recovery Correct Answer process of resuming
technical operations at a back-up site while recovering
operations at the primary site
BC/DR testing Correct Answer uses the actual written
plans, processes and procedures in an exercise or table
, top review to test validity and accuracy of the
documentation to resume business operations
pandemic planning Correct Answer focuses on external
events that impact infrastructure, environmental, social
factors (crime, political, etc.)
Incident Mgmt Program Correct Answer -notiifcation to all
affected customers of the third party
-provides customers with appropriate data to respond to
the issue
-consider the timing needed for customers to respond to
the issue
-allow customer to activate own program
-coordinate with law enforcement and appropriate
regulatory agencies as required
incident response Correct Answer -detection, investigation
and forensic evidence integrity
-event containment, post mortem and remediation
-management communication and reporting
incident notification plan Correct Answer -law enforcement
-regulators
-clients
-service providers
-employees
-external stakeholders
-media