CTPRP EXAMS SCRIPT 2026/2027 QUESTIONS AND
SOLUTIONS RATED A+
✔✔community cloud - ✔✔collaborative effort in which infrastructure is shared between
several organizations from a specific community with common concerns
✔✔public cloud - ✔✔owned by a cloud vendor and is accessible to the general public or
a large industry group
✔✔components of a cloud vendor assessment program - ✔✔- review of audit form
attestation reports
- security services documentation
- image snapshot approval and mgmt process
- patching responsibility
✔✔first layer of defense in physical and environmental security - ✔✔assess the
perimeter
✔✔monitoring and controls established for infrastructure - ✔✔- video surveillance
- electronic access control at essential ingress/egress points
- correlation of the video an dcard access data
- retention of video and logs for forensics
✔✔asset management program - ✔✔process for documenting and maintaining an
inventory of hardware, software and information assets (includes a data classification
process)
✔✔asset owner - ✔✔ensures assets are inventoried, properly classified and protected,
defines and reviews access restrictions and classifications, reviews locations of where
assets and data are being used, and ensures proper handling of an asset
✔✔assets - ✔✔- hardware
- software
- data
- facilities
✔✔asset management program - ✔✔should be approved by senior management and
communicated to all appropriate personnel
✔✔potential egress points - ✔✔-email
-USB ports
-internet
-printing
-network
, ✔✔DLP scanning - ✔✔-SSN/National ID
-account numbers
-functionality
-email and attachments
✔✔Commercial DLP software programs - ✔✔-capabilities vs configuration
-monitor vs block
-thresholds for acceptance
-escalation processes
-roles for review
✔✔documented operating procedures - ✔✔ensure the effective mgmt, operation,
integrity and security of information systems and data
✔✔change management/change control policy - ✔✔-change in network
-change in systems
-application updates
-code changes
-back out procedures
-problem mgmt
-environmental control over application development
✔✔Business Impact Analysis (BIA) - ✔✔identifies the third party's critical processes and
associated systems and prioritizes the effect of a business disruption based on the
impact and likelihood
✔✔Recovery Point Objective (RPO) - ✔✔point in time in the past to which you will
recover
✔✔Recovery Time Objective (RTO) - ✔✔point in time in the future at which you will be
up and running again
✔✔disaster recovery - ✔✔process of resuming technical operations at a back-up site
while recovering operations at the primary site
✔✔BC/DR testing - ✔✔uses the actual written plans, processes and procedures in an
exercise or table top review to test validity and accuracy of the documentation to
resume business operations
✔✔pandemic planning - ✔✔focuses on external events that impact infrastructure,
environmental, social factors (crime, political, etc.)
✔✔Incident Mgmt Program - ✔✔-notiifcation to all affected customers of the third party
-provides customers with appropriate data to respond to the issue
-consider the timing needed for customers to respond to the issue
SOLUTIONS RATED A+
✔✔community cloud - ✔✔collaborative effort in which infrastructure is shared between
several organizations from a specific community with common concerns
✔✔public cloud - ✔✔owned by a cloud vendor and is accessible to the general public or
a large industry group
✔✔components of a cloud vendor assessment program - ✔✔- review of audit form
attestation reports
- security services documentation
- image snapshot approval and mgmt process
- patching responsibility
✔✔first layer of defense in physical and environmental security - ✔✔assess the
perimeter
✔✔monitoring and controls established for infrastructure - ✔✔- video surveillance
- electronic access control at essential ingress/egress points
- correlation of the video an dcard access data
- retention of video and logs for forensics
✔✔asset management program - ✔✔process for documenting and maintaining an
inventory of hardware, software and information assets (includes a data classification
process)
✔✔asset owner - ✔✔ensures assets are inventoried, properly classified and protected,
defines and reviews access restrictions and classifications, reviews locations of where
assets and data are being used, and ensures proper handling of an asset
✔✔assets - ✔✔- hardware
- software
- data
- facilities
✔✔asset management program - ✔✔should be approved by senior management and
communicated to all appropriate personnel
✔✔potential egress points - ✔✔-email
-USB ports
-internet
-printing
-network
, ✔✔DLP scanning - ✔✔-SSN/National ID
-account numbers
-functionality
-email and attachments
✔✔Commercial DLP software programs - ✔✔-capabilities vs configuration
-monitor vs block
-thresholds for acceptance
-escalation processes
-roles for review
✔✔documented operating procedures - ✔✔ensure the effective mgmt, operation,
integrity and security of information systems and data
✔✔change management/change control policy - ✔✔-change in network
-change in systems
-application updates
-code changes
-back out procedures
-problem mgmt
-environmental control over application development
✔✔Business Impact Analysis (BIA) - ✔✔identifies the third party's critical processes and
associated systems and prioritizes the effect of a business disruption based on the
impact and likelihood
✔✔Recovery Point Objective (RPO) - ✔✔point in time in the past to which you will
recover
✔✔Recovery Time Objective (RTO) - ✔✔point in time in the future at which you will be
up and running again
✔✔disaster recovery - ✔✔process of resuming technical operations at a back-up site
while recovering operations at the primary site
✔✔BC/DR testing - ✔✔uses the actual written plans, processes and procedures in an
exercise or table top review to test validity and accuracy of the documentation to
resume business operations
✔✔pandemic planning - ✔✔focuses on external events that impact infrastructure,
environmental, social factors (crime, political, etc.)
✔✔Incident Mgmt Program - ✔✔-notiifcation to all affected customers of the third party
-provides customers with appropriate data to respond to the issue
-consider the timing needed for customers to respond to the issue