CTPRP CORE EXAM SET 2026/2027 QUESTIONS AND
SOLUTIONS RATED A+
✔✔data connections and transfer types: - ✔✔- ftp
- sftp
- secure connect
✔✔connectivity types: - ✔✔- point to point connection
- multipoint connection
- wireless
- remote terminal tech (RDP, Citrix, etc)
✔✔risks to be evaluated in "server security" - ✔✔- system types (windows, unix, mid-
range, mainframe, virtual)
- system operations
- system hardening
- security operations
✔✔patch management - ✔✔- tweeting of patches, service packs, hot fixes prior to
installation
- evaluation and prioritize vulnerabilities
- logging
- back out procedures
- priority patching of high risk systems first
- use of vendor alert services to keep updated with latest vulnerabilities
- operating systems and software
✔✔cloud computing consists of: - ✔✔- IaaS
- PaaS
- SaaS
✔✔IaaS - ✔✔company outsources equipment used to support operations (storage,
hardware,, servers, networking). service provider owns equipment and responsible for
housing, running and maintaining it
✔✔PaaS - ✔✔offers hardware/software for development of applications
✔✔SaaS - ✔✔business application delivered over the internet which users interact with
app through a website
✔✔private cloud - ✔✔infrastructure is managed and operated only for one company to
keep consistent level of security, privacy, and governance control.
- can be on or off premise
- be managed by company or third party
, ✔✔hybrid cloud - ✔✔combo of public and private cloud computing environments shared
between them
- used when computing demands fluctuate and private cloud needs more resources
✔✔community cloud - ✔✔infrastructure shared between multiple companies that have
same concerns (security, compliance, jurisdiction, etc)
✔✔public cloud - ✔✔resources are dynamically provisioned on a self-service basis over
the internet from office vendor provider who shares resources on a utility computing
basis
- resources owned by cloud vendor and accessible to general public or large company
✔✔components for cloud computing vendor assessment program: - ✔✔- review audit
form attestation reports
- security services documentation
- image snapshot approval and management process
- patching responsibility
✔✔Third party assessment process flow: - ✔✔1. align and plan
2. due diligence and third party selection
3. ongoing oversight and accountabilities
✔✔'align and plan' - ✔✔- properly assess and understand the risks involved by
outsourcing the product/service
✔✔'due diligence and third party selection' - ✔✔- the risk of product/service being
outsourced
- controls in place at the third party
✔✔'ongoing oversight and accountabilities' - ✔✔- monitors the performance of
assessment process
- comprehensive reporting (assessments, assessment process)
✔✔phase 1: pre-assessment - ✔✔- define risk scope
- define test procedures
- define data in use
- define risk tiers
- read agreements (sow, contract, end user license, purchase order)
✔✔phase 2: assessment - ✔✔- perform kickoff
- obtain business unit and vendor docs
- document tcontrol test results
SOLUTIONS RATED A+
✔✔data connections and transfer types: - ✔✔- ftp
- sftp
- secure connect
✔✔connectivity types: - ✔✔- point to point connection
- multipoint connection
- wireless
- remote terminal tech (RDP, Citrix, etc)
✔✔risks to be evaluated in "server security" - ✔✔- system types (windows, unix, mid-
range, mainframe, virtual)
- system operations
- system hardening
- security operations
✔✔patch management - ✔✔- tweeting of patches, service packs, hot fixes prior to
installation
- evaluation and prioritize vulnerabilities
- logging
- back out procedures
- priority patching of high risk systems first
- use of vendor alert services to keep updated with latest vulnerabilities
- operating systems and software
✔✔cloud computing consists of: - ✔✔- IaaS
- PaaS
- SaaS
✔✔IaaS - ✔✔company outsources equipment used to support operations (storage,
hardware,, servers, networking). service provider owns equipment and responsible for
housing, running and maintaining it
✔✔PaaS - ✔✔offers hardware/software for development of applications
✔✔SaaS - ✔✔business application delivered over the internet which users interact with
app through a website
✔✔private cloud - ✔✔infrastructure is managed and operated only for one company to
keep consistent level of security, privacy, and governance control.
- can be on or off premise
- be managed by company or third party
, ✔✔hybrid cloud - ✔✔combo of public and private cloud computing environments shared
between them
- used when computing demands fluctuate and private cloud needs more resources
✔✔community cloud - ✔✔infrastructure shared between multiple companies that have
same concerns (security, compliance, jurisdiction, etc)
✔✔public cloud - ✔✔resources are dynamically provisioned on a self-service basis over
the internet from office vendor provider who shares resources on a utility computing
basis
- resources owned by cloud vendor and accessible to general public or large company
✔✔components for cloud computing vendor assessment program: - ✔✔- review audit
form attestation reports
- security services documentation
- image snapshot approval and management process
- patching responsibility
✔✔Third party assessment process flow: - ✔✔1. align and plan
2. due diligence and third party selection
3. ongoing oversight and accountabilities
✔✔'align and plan' - ✔✔- properly assess and understand the risks involved by
outsourcing the product/service
✔✔'due diligence and third party selection' - ✔✔- the risk of product/service being
outsourced
- controls in place at the third party
✔✔'ongoing oversight and accountabilities' - ✔✔- monitors the performance of
assessment process
- comprehensive reporting (assessments, assessment process)
✔✔phase 1: pre-assessment - ✔✔- define risk scope
- define test procedures
- define data in use
- define risk tiers
- read agreements (sow, contract, end user license, purchase order)
✔✔phase 2: assessment - ✔✔- perform kickoff
- obtain business unit and vendor docs
- document tcontrol test results