CTPRP STUDY GUIDE EXAM 2026/2027 QUESTIONS
AND SOLUTIONS RATED A+
✔✔physical and environmental security policy should include: - ✔✔- governance
structure to allow ongoing auditing and measurement from established baseline
- appropriate ownership and sign off from executive level
- standards/processes/procedures reflecting hierarchal governance structure
- program integrity of ownership regardless of personnel changes
- physical access (like logical access) should be assigned 'as needed' basis
✔✔management approved operating procedures: - ✔✔- change management/control
policy
- change in network/systems
- application updates
- code changes
- back out procedures
- problem management
- environmental control over app dev
✔✔segregation of duties: - ✔✔- keep roles separate (network, systems, databases,
application)
- IT change management roles
- business unit roles
✔✔examine logical (tech-based) access to controls to systems via: - ✔✔- password
requirements
- identity management
- controls placed around development
✔✔controls around development include: - ✔✔- access to information processing
systems and facilities
- remote access
- encryption
- secure data transmission
✔✔internet protocol security (IPSec) - ✔✔authenticating and encryption each IP packet
of a communication session. It includes protocols for establishing mutual authentication
between agents at the beginning of session and negation of cryptographic keys to be
used during session
✔✔types of credential management - ✔✔- SSO
- federated authentication
- password policies
✔✔remote access must be managed/controlled: - ✔✔- internet protocol security (IPSec)
, - transport layer security (TLS)
- secure sockets layer (SSL)
- cryptography
- credential management
✔✔multi-factor authentication - ✔✔- used for regular systems/app access
✔✔out of wallet authentication - ✔✔- information about a user not readily available in
financial databased (credit bureau, etc)
- negatively impacted by growth in social media
✔✔SDLC examines: - ✔✔- patch management
- data storage
- data transmission
- security
- application development
- programming
✔✔SDLC lifecyle - ✔✔1. inventory
2. risk prioritization
3. define controls and testing
4. defect vulnerability management
5. define an evergreen process
✔✔types of risks: - ✔✔- inherent application risk
- inherent financial risk
- inherent reputation risk
- residual risk
✔✔security incidents include: - ✔✔- unauthorized access to systems or applications
- unauthorized access to sensitive data
- active network or system attack
- degradation of loss of service availability
- detection and response for data breach event
✔✔incident management program should include: - ✔✔- notification to all affected
customers of vendor
- providing customers with approbate data to respond to the issue
- consider timing needed for customers to respond to issue
- allow customer to activate its own incident management program
- coordinate with law enforcement and appropriate regulatory agencies as required
✔✔business impact analysis (BIA) - ✔✔identifies the third party's critical processes and
associated systems and priorities the affect of a business disruption based on the
impact and likelihood
AND SOLUTIONS RATED A+
✔✔physical and environmental security policy should include: - ✔✔- governance
structure to allow ongoing auditing and measurement from established baseline
- appropriate ownership and sign off from executive level
- standards/processes/procedures reflecting hierarchal governance structure
- program integrity of ownership regardless of personnel changes
- physical access (like logical access) should be assigned 'as needed' basis
✔✔management approved operating procedures: - ✔✔- change management/control
policy
- change in network/systems
- application updates
- code changes
- back out procedures
- problem management
- environmental control over app dev
✔✔segregation of duties: - ✔✔- keep roles separate (network, systems, databases,
application)
- IT change management roles
- business unit roles
✔✔examine logical (tech-based) access to controls to systems via: - ✔✔- password
requirements
- identity management
- controls placed around development
✔✔controls around development include: - ✔✔- access to information processing
systems and facilities
- remote access
- encryption
- secure data transmission
✔✔internet protocol security (IPSec) - ✔✔authenticating and encryption each IP packet
of a communication session. It includes protocols for establishing mutual authentication
between agents at the beginning of session and negation of cryptographic keys to be
used during session
✔✔types of credential management - ✔✔- SSO
- federated authentication
- password policies
✔✔remote access must be managed/controlled: - ✔✔- internet protocol security (IPSec)
, - transport layer security (TLS)
- secure sockets layer (SSL)
- cryptography
- credential management
✔✔multi-factor authentication - ✔✔- used for regular systems/app access
✔✔out of wallet authentication - ✔✔- information about a user not readily available in
financial databased (credit bureau, etc)
- negatively impacted by growth in social media
✔✔SDLC examines: - ✔✔- patch management
- data storage
- data transmission
- security
- application development
- programming
✔✔SDLC lifecyle - ✔✔1. inventory
2. risk prioritization
3. define controls and testing
4. defect vulnerability management
5. define an evergreen process
✔✔types of risks: - ✔✔- inherent application risk
- inherent financial risk
- inherent reputation risk
- residual risk
✔✔security incidents include: - ✔✔- unauthorized access to systems or applications
- unauthorized access to sensitive data
- active network or system attack
- degradation of loss of service availability
- detection and response for data breach event
✔✔incident management program should include: - ✔✔- notification to all affected
customers of vendor
- providing customers with approbate data to respond to the issue
- consider timing needed for customers to respond to issue
- allow customer to activate its own incident management program
- coordinate with law enforcement and appropriate regulatory agencies as required
✔✔business impact analysis (BIA) - ✔✔identifies the third party's critical processes and
associated systems and priorities the affect of a business disruption based on the
impact and likelihood