Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 12 pages
Exam (elaborations)

CTPRP STUDY GUIDE EXAM 2026.pdf 1. Document information

Document preview thumbnail
Preview 2 out of 12 pages

CTPRP STUDY GUIDE EXAM 1. Document information

Content preview

CTPRP STUDY GUIDE EXAM 2026/2027 QUESTIONS
AND SOLUTIONS RATED A+
✔✔physical and environmental security policy should include: - ✔✔- governance
structure to allow ongoing auditing and measurement from established baseline
- appropriate ownership and sign off from executive level
- standards/processes/procedures reflecting hierarchal governance structure
- program integrity of ownership regardless of personnel changes
- physical access (like logical access) should be assigned 'as needed' basis

✔✔management approved operating procedures: - ✔✔- change management/control
policy
- change in network/systems
- application updates
- code changes
- back out procedures
- problem management
- environmental control over app dev

✔✔segregation of duties: - ✔✔- keep roles separate (network, systems, databases,
application)
- IT change management roles
- business unit roles

✔✔examine logical (tech-based) access to controls to systems via: - ✔✔- password
requirements
- identity management
- controls placed around development

✔✔controls around development include: - ✔✔- access to information processing
systems and facilities
- remote access
- encryption
- secure data transmission

✔✔internet protocol security (IPSec) - ✔✔authenticating and encryption each IP packet
of a communication session. It includes protocols for establishing mutual authentication
between agents at the beginning of session and negation of cryptographic keys to be
used during session

✔✔types of credential management - ✔✔- SSO
- federated authentication
- password policies

✔✔remote access must be managed/controlled: - ✔✔- internet protocol security (IPSec)

, - transport layer security (TLS)
- secure sockets layer (SSL)
- cryptography
- credential management

✔✔multi-factor authentication - ✔✔- used for regular systems/app access

✔✔out of wallet authentication - ✔✔- information about a user not readily available in
financial databased (credit bureau, etc)
- negatively impacted by growth in social media

✔✔SDLC examines: - ✔✔- patch management
- data storage
- data transmission
- security
- application development
- programming

✔✔SDLC lifecyle - ✔✔1. inventory
2. risk prioritization
3. define controls and testing
4. defect vulnerability management
5. define an evergreen process

✔✔types of risks: - ✔✔- inherent application risk
- inherent financial risk
- inherent reputation risk
- residual risk

✔✔security incidents include: - ✔✔- unauthorized access to systems or applications
- unauthorized access to sensitive data
- active network or system attack
- degradation of loss of service availability
- detection and response for data breach event

✔✔incident management program should include: - ✔✔- notification to all affected
customers of vendor
- providing customers with approbate data to respond to the issue
- consider timing needed for customers to respond to issue
- allow customer to activate its own incident management program
- coordinate with law enforcement and appropriate regulatory agencies as required

✔✔business impact analysis (BIA) - ✔✔identifies the third party's critical processes and
associated systems and priorities the affect of a business disruption based on the
impact and likelihood

Document information

Uploaded on
July 20, 2026
Number of pages
12
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$16.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
BOARDWALK
3.5
(41)
Sold
287
Followers
11
Items
36005
Last sold
4 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions