A hospital has three data classification levels: shareable without restrictions, shareable with restrictions, and internal use only. Which of the following BEST demonstrates adhering to principles of good enterprise data classification?
-
A
A printout of the employee code of conduct marked "shareable with restrictions" is posted in the hallway where patients have access.
-
B
A printout of the employee code of conduct marked "internal use only" is posted in the waiting room.
-
C
A memo regarding a newly discovered data breach marked as "internal use only" is posted on the wall in the employee lunchroom.
-
D
An electronic health record (EHR) with personally identifiable information (PII) marked as "sharable with restrictions" is found in the employee lunchroom.
Reveal answer details
Close answer details
Using Address Space Layout Randomization (ASLR) reduces the potential for which of the following attacks?
-
A
-
B
-
C
Cross-Site Scripting (XSS)
-
D
Reveal answer details
Close answer details
A security practitioner has just been assigned to address an ongoing Denial of Service (DoS) attack against the company's network, which includes an e-commerce web site. The strategy has to include defenses for any size of attack without rendering the company network unusable. Which of the following should be a PRIMARY concern when addressing this issue?
-
A
Deal with end user education and training.
-
B
Pay more for a dedicated path to the Internet.
-
C
Allow legitimate connections while blocking malicious connections.
-
D
Ensure the web sites are properly backed up on a daily basis.
Reveal answer details
Close answer details
Which of the following types of datacenter architectures will MOST likely be used in a large SDN and can be extended beyond the datacenter?
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Refer to the information below to answer the question. A security practitioner detects client-based attacks on the organization's network. A plan will be necessary to address these concerns. In the plan, what is the BEST approach to mitigate future internal client-based attacks?
-
A
Block all client side web exploits at the perimeter.
-
B
Remove all non-essential client-side web services from the network.
-
C
Screen for harmful exploits of client-side services before implementation.
-
D
Harden the client image before deployment.
Reveal answer details
Close answer details
Refer to the information below to answer the question. An organization experiencing a negative financial impact is forced to reduce budgets and the number of Information Technology (IT) operations staff performing basic logical access security administration functions. Security processes have been tightly integrated into normal IT operations and are not separate and distinct roles. Which of the following will be the PRIMARY security concern as staff is released from the organization?
-
A
-
B
Loss of data and separation of duties
-
C
Undocumented security controls
-
D
Additional responsibilities for remaining staff
Reveal answer details
Close answer details
Which of the following types of devices can provide content filtering and threat protection, and manage multiple IPSec site-to-site connections?
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Company A is evaluating new software to replace an in-house developed application. During the acquisition process. Company A specified the security retirement, as well as the functional requirements. Company B responded to the acquisition request with their flagship product that runs on an Operating System (OS) that Company A has never used nor evaluated. The flagship product meets all security -and functional requirements as defined by Company A. Based upon Company B's response, what step should Company A take?
-
A
Move ahead with the acpjisition process, and purchase the flagship software
-
B
Conduct a security review of the OS
-
C
Perform functionality testing
-
D
Enter into contract negotiations ensuring Service Level Agreements (SLA) are established to include security patching
Reveal answer details
Close answer details
In general, servers that are facing the Internet should be placed in a demilitarized zone (DMZ). What is MAIN purpose of the DMZ?
-
A
Reduced risk to internal systems.
-
B
Prepare the server for potential attacks.
-
C
Mitigate the risk associated with the exposed server.
-
D
Bypass the need for a firewall.
Reveal answer details
Close answer details
Question 10
Single choice
An organization wants a service provider to authenticate users via the users' organization domain credentials. Which markup language should the organization's security personnel use to support the integration?
-
A
Security Assertion Markup Language (SAML)
-
B
YAML Ain't Markup Language (YAML)
-
C
Hypertext Markup Language (HTML)
-
D
Extensible Markup Language (XML)
Reveal answer details
Close answer details
Question 11
Single choice
Which of the following are common components of a Security Assertion Markup Language (SAML) based federation system?
-
A
Client, Service Provider, identity provider (IdP), Token
-
B
Client, Service Provider, Resource Server, Grant
-
C
Client, Authorization Server, identity provider (IdP), Claim
-
D
Client, Authorization Server, Resource Server, Assertion
Reveal answer details
Close answer details
Question 12
Single choice
Changes to a Trusted Computing Base (TCB) system that could impact the security posture of that system and trigger a recertification activity are documented in the
-
A
security impact analysis.
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 13
Single choice
According to best practice, which of the following groups is the MOST effective in performing an information security compliance audit?
-
A
In-house security administrators
-
B
-
C
Disaster Recovery (DR) Team
-
D
Reveal answer details
Close answer details
Question 14
Single choice
As a best practice, the Security Assessment Report (SAR) should include which of the following sections?
-
A
Data classification policy
-
B
Software and hardware inventory
-
C
Remediation recommendations
-
D
Reveal answer details
Close answer details
Question 15
Single choice
Which one of the following describes granularity?
-
A
Maximum number of entries available in an Access Control List (ACL)
-
B
Fineness to which a trusted system can authenticate users
-
C
Number of violations divided by the number of total accesses
-
D
Fineness to which an access control system can be adjusted
Reveal answer details
Close answer details
Question 16
Single choice
Which of the following is the PRIMARY security concern associated with the implementation of smart cards?
-
A
The cards have limited memory
-
B
Vendor application compatibility
-
C
The cards can be misplaced
-
D
Mobile code can be embedded in the card
Reveal answer details
Close answer details
Question 17
Single choice
What is the BEST approach to addressing security issues in legacy web applications?
-
A
Debug the security issues
-
B
Migrate to newer, supported applications where possible
-
C
Conduct a security assessment
-
D
Protect the legacy application with a web application firewall
Reveal answer details
Close answer details
Question 18
Single choice
In order to assure authenticity, which of the following are required?
-
A
Confidentiality and authentication
-
B
Confidentiality and integrity
-
C
Authentication and non-repudiation
-
D
Integrity and non-repudiation
Reveal answer details
Close answer details
Question 19
Single choice
Which of the following regulations dictates how data breaches are handled?
-
A
-
B
National Institute of Standards and Technology (NIST)
-
C
Payment Card Industry Data Security Standard (PCI-DSS)
-
D
General Data Protection Regulation (GDPR)
Reveal answer details
Close answer details
Question 20
Single choice
The use of private and public encryption keys is fundamental in the implementation of which of the following?
-
A
-
B
Secure Sockets Layer (SSL)
-
C
Advanced Encryption Standard (AES)
-
D
Reveal answer details
Close answer details
Question 21
Single choice
An organization with divisions in the United States (US) and the United Kingdom (UK) processes data comprised of personal information belonging to subjects living in the European Union (EU) and in the US. Which data MUST be handled according to the privacy protections of General Data Protection Regulation (GDPR)?
-
A
Only the EU citizens' data
-
B
Only the EU residents' data
-
C
Only the UK citizens' data
-
D
Only data processed in the UK
Reveal answer details
Close answer details
Question 22
Single choice
Which of the following is the MOST important output from a mobile application threat modeling exercise according to Open Web Application Security Project (OWASP)?
-
A
Application interface entry and endpoints
-
B
The likelihood and impact of a vulnerability
-
C
Countermeasures and mitigations for vulnerabilities
-
D
A data flow diagram for the application and attack surface analysis
Reveal answer details
Close answer details
Question 23
Single choice
Which of the following will help prevent improper session handling?
-
A
Ensure that all UlWebView calls do not execute without proper input validation.
-
B
Ensure that tokens are sufficiently long, complex, and pseudo-random.
-
C
Ensure JavaScript and plugin support is disabled.
-
D
Ensure that certificates are valid and fail closed.
Reveal answer details
Close answer details
Question 24
Single choice
A Simple Power Analysis (SPA) attack against a device directly observes which of the following?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 25
Single choice
Checking routing information on e-mail to determine it is in a valid format and contains valid information is an example of which of the following anti-spam approaches?
-
A
Simple Mail Transfer Protocol (SMTP) blacklist
-
B
Reverse Domain Name System (DNS) lookup
-
C
-
D
Reveal answer details
Close answer details
Question 26
Single choice
Which of the following is the FIRST step in the incident response process?
-
A
Determine the cause of the incident
-
B
Disconnect the system involved from the network
-
C
Isolate and contain the system involved
-
D
Investigate all symptoms to confirm the incident
Reveal answer details
Close answer details
Question 27
Single choice
While classifying credit card data related to Payment Card Industry Data Security Standards (PCI-DSS), which of the following is a PRIMARY security requirement?
-
A
Processor agreements with card holders
-
B
Three-year retention of data
-
C
-
D
Specific card disposal methodology
Reveal answer details
Close answer details
Question 28
Single choice
Which of the following practices provides the development of security and identification of threats in designing software?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 29
Single choice
How long should the records on a project be retained?
-
A
For the duration of the project, or at the discretion of the record owner
-
B
Until they are no longer useful or required by policy
-
C
Until five years after the project ends, then move to archives
-
D
For the duration of the organization fiscal year
Reveal answer details
Close answer details
Question 30
Single choice
What is considered the BEST explanation when determining whether to provide remote network access to a third-party security service?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 31
Single choice
Which of the following PRIMARILY contributes to security incidents in web-based applications?
-
A
Systems administration and operating systems
-
B
System incompatibility and patch management
-
C
Third-party applications and change controls
-
D
Improper stress testing and application interfaces
Reveal answer details
Close answer details
Question 32
Single choice
What is a common mistake in records retention?
-
A
Having the organization legal department create a retention policy
-
B
Adopting a retention policy based on applicable organization requirements
-
C
Having the Human Resource (HR) department create a retention policy
-
D
Adopting a retention policy with the longest requirement period
Reveal answer details
Close answer details
Question 33
Single choice
Which one of the following is a fundamental objective in handling an incident?
-
A
To restore control of the affected systems
-
B
To confiscate the suspect's computers
-
C
To prosecute the attacker
-
D
To perform full backups of the system
Reveal answer details
Close answer details
Question 34
Single choice
A security professional recommends that a company integrate threat modeling into its Agile development processes. Which of the following BEST describes the benefits of this approach?
-
A
Reduce application development costs.
-
B
Potential threats are addressed later in the Software Development Life Cycle (SDLC).
-
C
Improve user acceptance of implemented security controls.
-
D
Potential threats are addressed earlier in the Software Development Life Cycle (SDLC).
Reveal answer details
Close answer details
Question 35
Single choice
Which of the following protocols will allow the encrypted transfer of content on the Internet?
-
A
Server Message Block (SMB)
-
B
-
C
Hypertext Transfer Protocol (HTTP)
-
D
Reveal answer details
Close answer details
Question 36
Single choice
After a thorough analysis, it was discovered that a perpetrator compromised a network by gaining access to the network through a Secure Socket Layer (SSL) Virtual Private Network (VPN) gateway. The perpetrator guessed a username and brute forced the password to gain access. Which of the following BEST mitigates this issue?
-
A
Implement strong passwords authentication for VPN
-
B
Integrate the VPN with centralized credential stores
-
C
Implement an Internet Protocol Security (IPSec) client
-
D
Use two-factor authentication mechanisms
Reveal answer details
Close answer details
Question 37
Single choice
Refer to the information below to answer the question. In a Multilevel Security (MLS) system, the following sensitivity labels are used in increasing levels of sensitivity: restricted, confidential, secret, top secret. Table A lists the clearance levels for four users, while Table B lists the security classes of four different files.  In a Bell-LaPadula system, which user cannot write to File 3?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 38
Single choice
What is the MOST appropriate hierarchy of documents when implementing a security program?
-
A
Organization principle, policy, standard, guideline
-
B
Policy, organization principle, standard, guideline
-
C
Standard, policy, organization principle, guideline
-
D
Organization principle, guideline, policy, standard
Reveal answer details
Close answer details
Question 39
Single choice
How is protection for hypervisor host and software administration functions BEST achieved?
-
A
Enforce network controls using a host-based firewall.
-
B
Deploy the management interface in a dedicated virtual network segment.
-
C
The management traffic pathway should have separate physical network interface cards (NIC) and network.
-
D
Deny permissions to specific virtual machines (VM) groups and objects.
Reveal answer details
Close answer details
Question 40
Single choice
An application developer is deciding on the amount of idle session time that the application allows before a timeout. Which of the following is the BEST reason for determining the session timeout requirement?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationDetermining the session timeout requirement for an application based on its specific requirements is the best approach because it ensures that the timeout setting will be appropriate for the application's particular security and usability needs.
Question 41
Single choice
What type of risk is related to the sequences of value-adding and managerial activities undertaken in an organization?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 42
Single choice
When are security requirements the LEAST expensive to implement?
-
A
When identified by external consultants
-
B
During the application rollout phase
-
C
During each phase of the project cycle
-
D
When built into application design
Reveal answer details
Close answer details
Question 43
Single choice
In order to support the least privilege security principle when a resource is transferring within the organization from a production support system administration role to a developer role, what changes should be made to that resource's access to the production Operating System (OS) directory structure?
-
A
From Read Only privileges to No Access privileges
-
B
From Author privileges to Administrative privileges
-
C
From Administrative privileges to No Access privileges
-
D
From No Access privileges to Author privileges
Reveal answer details
Close answer details
Question 44
Single choice
What is an important characteristic of Role Based Access Control (RBAC)?
-
A
Supports Mandatory Access Control (MAC)
-
B
Simplifies the management of access rights
-
C
Relies on rotation of duties
-
D
Requires two factor authentication
Reveal answer details
Close answer details
Question 45
Single choice
An organization is looking to include mobile devices in its asset management system for better tracking. In which system tier of the reference architecture would mobile devices be tracked?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 46
Single choice
Which of the following is a process within a Systems Engineering Life Cycle (SELC) stage?
-
A
-
B
Development and Deployment
-
C
-
D
Reveal answer details
Close answer details
Question 47
Single choice
Which of the following addresses requirements of security assessment during software acquisition?
-
A
Software assurance policy
-
B
-
C
Software configuration management (SCM)
-
D
Data loss prevention (DLP) policy
Reveal answer details
Close answer details
Question 48
Single choice
Refer to the information below to answer the question. A large, multinational organization has decided to outsource a portion of their Information Technology (IT) organization to a third-party provider's facility. This provider will be responsible for the design, development, testing, and support of several critical, customer-based applications used by the organization. What additional considerations are there if the third party is located in a different country?
-
A
The organizational structure of the third party and how it may impact timelines within the organization
-
B
The ability of the third party to respond to the organization in a timely manner and with accurate information
-
C
The effects of transborder data flows and customer expectations regarding the storage or processing of their data
-
D
The quantity of data that must be provided to the third party and how it is to be used
Reveal answer details
Close answer details
Question 49
Single choice
When implementing controls in a heterogeneous end-point network for an organization, it is critical that
-
A
hosts are able to establish network communications.
-
B
users can make modifications to their security software configurations.
-
C
common software security components be implemented across all hosts.
-
D
firewalls running on each host are fully customizable by the user.
Reveal answer details
Close answer details
Question 50
Single choice
Which of the following phases involves researching a target's configuration from public sources when performing a penetration test?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 51
Single choice
Which of the following countermeasures is the MOST effective in defending against a social engineering attack?
-
A
Mandating security policy acceptance
-
B
Changing individual behavior
-
C
Evaluating security awareness training
-
D
Filtering malicious e-mail content
Reveal answer details
Close answer details
Question 52
Single choice
What is the BEST approach for maintaining ethics when a security professional is unfamiliar with the culture of a country and is asked to perform a questionable task?
-
A
Exercise due diligence when deciding to circumvent host government requests
-
B
Become familiar with the means in which the code of ethics is applied and considered
-
C
Complete the assignment based on the customer's wishes
-
D
Execute according to the professional's comfort level with the code of ethics
Reveal answer details
Close answer details
Question 53
Single choice
Which of the following are core categories of malicious attack against Internet of Things (IOT) devices?
-
A
Packet capture and false data injection
-
B
Packet capture and brute force attack
-
C
Node capture 3nd Structured Query Langue (SQL) injection
-
D
Node capture and false data injection
Reveal answer details
Close answer details
DRAG DROP Match the types of e-authentication tokens to their description. Drag each e-authentication token on the left to its corresponding description on the right. 
Reveal answer details
Close answer details
Question 55
Single choice
What is the PRIMARY benefit of incident reporting and computer crime investigations?
-
A
Providing evidence to law enforcement
-
B
Repairing the damage and preventing future occurrences
-
C
Appointing a computer emergency response team
-
D
Complying with security policy
Reveal answer details
Close answer details
Question 56
Single choice
Recovery strategies of a Disaster Recovery planning (DRIP) MUST be aligned with which of the following?
-
A
Hardware and software compatibility issues
-
B
Applications' critically and downtime tolerance
-
C
Budget constraints and requirements
-
D
Cost/benefit analysis and business objectives
Reveal answer details
Close answer details
Question 57
Single choice
What type of wireless network attack BEST describes an Electromagnetic Pulse (EMP) attack?
-
A
Radio Frequency (RF) attack
-
B
Denial of Service (DoS) attack
-
C
-
D
Reveal answer details
Close answer details
Question 58
Single choice
An Internet media company produces and broadcasts highly popular television shows. The company is suffering a huge revenue loss due to piracy. What technique should be used to track the distribution of content?
-
A
Install the latest data loss prevention (DLP) software at every server used to distribute content.
-
B
Log user access to servers. Every day those log records are going to be audited by a team of specialized investigators.
-
C
Hire several investigators to identify sources of pirated content and report people sharing the content.
-
D
Use watermarking to hide a signature into the digital media such that it can be used to find who is using the company's content.
Reveal answer details
Close answer details
Question 59
Single choice
Refer to the information below to answer the question. A new employee is given a laptop computer with full administrator access. This employee does not have a personal computer at home and has a child that uses the computer to send and receive e-mail, search the web, and use instant messaging. The organization's Information Technology (IT) department discovers that a peer-to-peer program has been installed on the computer using the employee's access. Which of the following methods is the MOST effective way of removing the Peer-to-Peer (P2P) program from the computer?
-
A
-
B
-
C
Find and remove all installation files
-
D
Delete all cookies stored in the web browser cache
Reveal answer details
Close answer details
Question 60
Single choice
Creation and maintenance of intrusion detection systems and processes for the following is one of them identify it:
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 61
Single choice
The MAIN use of Layer 2 Tunneling Protocol (L2TP) is to tunnel data
-
A
through a firewall at the Session layer
-
B
through a firewall at the Transport layer
-
C
in the Point-to-Point Protocol (PPP)
-
D
in the Payload Compression Protocol (PCP)
Reveal answer details
Close answer details
Question 62
Single choice
Which of the following is the top barrier for companies to adopt cloud technology?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 63
Single choice
A Distributed Denial of Service (DDoS) attack was carried out using malware called Mirai to create a large-scale command and control system to launch a botnet. Which of the following devices were the PRIMARY sources used to generate the attack traffic?
-
A
Internet of Things (IoT) devices
-
B
-
C
Web servers running open source operating systems (OS)
-
D
Mobile devices running Android
Reveal answer details
Close answer details
Question 64
Single choice
Transport Layer Security (TLS) provides which of the following capabilities for a remote access server?
-
A
Transport layer handshake compression
-
B
Application layer negotiation
-
C
Peer identity authentication
-
D
Digital certificate revocation
Reveal answer details
Close answer details
Question 65
Single choice
Which of the following MOST accurately describes the Security Target (ST) in the Common Criteria framework?
-
A
The set of rules that define how resources or assets are managed and protected
-
B
A product independent set of security criteria for a class of products
-
C
The product and documentation to be evaluated
-
D
A document that includes a product specific set of security criteria
Reveal answer details
Close answer details
Correct answerD
ExplanationReferences: https://www.cisa.gov/uscert/bsi/articles/best-practices/requirements-engineering/the-common-criteria
Question 66
Single choice
Which of the following media is LEAST problematic with data remanence?
-
A
Dynamic Random Access Memory (DRAM)
-
B
Electrically Erasable Programming Read-Only Memory (BPRCM)
-
C
-
D
Reveal answer details
Close answer details
Question 67
Single choice
Copyright provides protection for which of the following?
-
A
Ideas expressed in literary works
-
B
A particular expression of an idea
-
C
New and non-obvious inventions
-
D
Discoveries of natural phenomena
Reveal answer details
Close answer details
Question 68
Single choice
Even though a particular digital watermark is difficult to detect, which of the following represents a way it might still be inadvertently removed?
-
A
Truncating parts of the data
-
B
Applying Access Control Lists (ACL) to the data
-
C
Appending non-watermarked data to watermarked data
-
D
Storing the data in a database
Reveal answer details
Close answer details
Question 69
Single choice
Which of the following is the PRIMARY objective of performing scans with an active discovery tool?
-
A
Discovering virus and malware activity
-
B
Discovering changes for security configuration management (CM)
-
C
Asset identification (ID) and inventory management
-
D
Vulnerability management and remediation
Reveal answer details
Close answer details
Correct answerC
ExplanationReferences: https://www.camcode.com/blog/what-is-asset-identification/
Question 70
Single choice
What MUST each information owner do when a system contains data from multiple information owners?
-
A
Provide input to the Information System (IS) owner regarding the security requirements of the data
-
B
Review the Security Assessment report (SAR) for the Information System (IS) and authorize the IS to operate.
-
C
Develop and maintain the System Security Plan (SSP) for the Information System (IS) containing the data
-
D
Move the data to an Information System (IS) that does not contain data owned by other information owners
Reveal answer details
Close answer details
Question 71
Single choice
Which of the following is MOST important when determining appropriate countermeasures for an identified risk?
-
A
Interaction with existing controls
-
B
-
C
Organizational risk tolerance
-
D
Reveal answer details
Close answer details
Question 72
Single choice
A security professional should consider the protection of which of the following elements FIRST when developing a defense-in-depth strategy for a mobile workforce?
-
A
-
B
Demilitarized Zones (DMZ)
-
C
Databases and back-end servers
-
D
Reveal answer details
Close answer details
Question 73
Single choice
Which of the following controls is the FIRST step in protecting privacy in an information system?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 74
Single choice
A security practitioner has been tasked with establishing organizational asset handling procedures. What should be considered that would have the GRFATEST impact to the development of these procedures?
-
A
Media handling procedures
-
B
User roles and responsibilities
-
C
Acceptable Use Policy (ALP)
-
D
Information classification scheme
Reveal answer details
Close answer details
Question 75
Single choice
Which of the following authorization standards is built to handle Application Programming Interface (API) access for Federated Identity Management (FIM)?
-
A
Security Assertion Markup Language (SAML)
-
B
Open Authentication (OAUTH)
-
C
Remote Authentication Dial-in User service (RADIUS)
-
D
Terminal Access Control Access Control System Plus (TACACS+)
Reveal answer details
Close answer details
Question 76
Single choice
Which one of the following is the MOST important in designing a biometric access system if it is essential that no one other than authorized individuals are admitted?
-
A
False Acceptance Rate (FAR)
-
B
False Rejection Rate (FRR)
-
C
Crossover Error Rate (CER)
-
D
Reveal answer details
Close answer details
Question 77
Single choice
What does a Synchronous (SYN) flood attack do?
-
A
Forces Transmission Control Protocol /Internet Protocol (TCP/IP) connections into a reset state
-
B
Establishes many new Transmission Control Protocol / Internet Protocol (TCP/IP) connections
-
C
Empties the queue of pending Transmission Control Protocol /Internet Protocol (TCP/IP) requests
-
D
Exceeds the limits for new Transmission Control Protocol /Internet Protocol (TCP/IP) connections
Reveal answer details
Close answer details
Question 78
Single choice
Which of the following protocols would allow an organization to maintain a centralized list of users that can read a protected webpage?
-
A
Lightweight Directory Access Control (LDAP)
-
B
Security Assertion Markup Language (SAML)
-
C
Hypertext Transfer Protocol (HTTP)
-
D
Reveal answer details
Close answer details
Question 79
Single choice
An organization is establishing a privacy program to ensure that personally identifiable information (PII) is properly protected. What is the FIRST action the organization should take to establish the program?
-
A
Appoint a senior official to oversee the privacy program.
-
B
Allocate sufficient resources to implement the privacy program.
-
C
Develop a strategic organizational privacy plan.
-
D
Monitor privacy laws and policy changes.
Reveal answer details
Close answer details
Correct answerA
ExplanationReferences: https://cloudian.com/guides/data-protection/data-protection-and-privacy-7-ways-to-protect-user-data/
Question 80
Single choice
What is the MOST important reason to configure unique user IDs?
-
A
Supporting accountability
-
B
Reducing authentication errors
-
C
Preventing password compromise
-
D
Supporting Single Sign On (SSO)
Reveal answer details
Close answer details
Question 81
Single choice
What security principle addresses the issue of "Security by Obscurity"?
-
A
-
B
Segregation of duties (SoD)
-
C
Role Based Access Control (RBAC)
-
D
Reveal answer details
Close answer details
Question 82
Single choice
Which of the following will an organization's network vulnerability testing process BEST enhance?
-
A
Firewall log review processes
-
B
Asset management procedures
-
C
Server hardening processes
-
D
Reveal answer details
Close answer details
Question 83
Single choice
By allowing storage communications to run on top of Transmission Control Protocol/Internet Protocol (TCP/IP) with a Storage Area Network (SAN), the
-
A
confidentiality of the traffic is protected.
-
B
opportunity to sniff network traffic exists.
-
C
opportunity for device identity spoofing is eliminated.
-
D
storage devices are protected against availability attacks.
Reveal answer details
Close answer details
Question 84
Single choice
Why should Open Wab Application Secuirty Project (OWASP) Application Security Verification standards (ASVS) Level 1 be considered a MINIMUM level of protection for any wab application?
-
A
ASVS Level 1 ensures that applications are invulnerable to OWASP top 10 threats.
-
B
Opportunistic attackers will look for any easily exploitable vulnerable applications.
-
C
Most regulatory bodies consider ASVS Level 1 as a baseline set of controls for applications.
-
D
Securing applications at ASVS Level 1 provides adequate protection for sensitive data.
Reveal answer details
Close answer details
Question 85
Single choice
During an audit, the auditor finds evidence of potentially illegal activity. Which of the following is the MOST appropriate action to take?
-
A
Immediately call the police
-
B
Work with the client to resolve the issue internally
-
C
Advise the person performing the illegal activity to cease and desist
-
D
Work with the client to report the activity to the appropriate authority
Reveal answer details
Close answer details
Question 86
Single choice
A malicious user gains access to unprotected directories on a web server. Which of the following is MOST likely the cause for this information disclosure?
-
A
Security misconfiguration
-
B
Cross-site request forgery (CSRF)
-
C
Structured Query Language injection (SQLi)
-
D
Broken authentication management
Reveal answer details
Close answer details
Question 87
Single choice
What high Availability (HA) option of database allows multiple clients to access multiple database servers simultaneously?
-
A
Non-Structured Query Language (NoSQL) database
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 88
Single choice
Which of the following is the MOST appropriate control for asset data labeling procedures?
-
A
Logging data media to provide a physical inventory control
-
B
Reviewing audit trails of logging records
-
C
Categorizing the types of media being used
-
D
Reviewing off-site storage access controls
Reveal answer details
Close answer details
Question 89
Single choice
Which access control method is based on users issuing access requests on system resources, features assigned to those resources, the operational or situational context, and a set of policies specified in terms of those features and context?
-
A
Mandatory Access Control (MAC)
-
B
Role Based Access Control (RBAC)
-
C
Discretionary Access Control (DAC)
-
D
Attribute Based Access Control (ABAC)
Reveal answer details
Close answer details
Question 90
Single choice
Which of the following is the GREATEST benefit of implementing a Role Based Access Control (RBAC) system?
-
A
Integration using Lightweight Directory Access Protocol (LDAP)
-
B
Form-based user registration process
-
C
Integration with the organizations Human Resources (HR) system
-
D
A considerably simpler provisioning process
Reveal answer details
Close answer details
Question 91
Single choice
Single Sign-On (SSO) is PRIMARILY designed to address which of the following?
-
A
Confidentiality and Integrity
-
B
Availability and Accountability
-
C
Integrity and Availability
-
D
Accountability and Assurance
Reveal answer details
Close answer details
Question 92
Single choice
Which of the following is the PRIMARY reason a sniffer operating on a network is collecting packets only from its own host?
-
A
An Intrusion Detection System (IDS) has dropped the packets.
-
B
The network is connected using switches.
-
C
The network is connected using hubs.
-
D
The network's firewall does not allow sniffing.
Reveal answer details
Close answer details
Question 93
Single choice
Which of the following is used to detect steganography?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 94
Single choice
Which of the following would qualify as an exception to the "right to be forgotten" of the General Data Protection Regulation's (GDPR)?
-
A
For the establishment, exercise, or defense of legal claims
-
B
The personal data has been lawfully processed and collected
-
C
The personal data remains necessary to the purpose for which it was collected
-
D
For the reasons of private interest
Reveal answer details
Close answer details
Question 95
Single choice
Which of the following is a strategy of grouping requirements in developing a security test and Evaluation (ST&E)?
-
A
Management, operational, and technical
-
B
Standards, policies, and procedures
-
C
Documentation, observation, and manual
-
D
Tactical, strategic, and financial
Reveal answer details
Close answer details
Question 96
Single choice
"Stateful" differs from "Static" packet filtering firewalls by being aware of which of the following?
-
A
Difference between a new and an established connection
-
B
Originating network location
-
C
Difference between a malicious and a benign packet payload
-
D
Originating application session
Reveal answer details
Close answer details
Question 97
Single choice
Which of the following provides the BEST method to verify that security baseline configurations are maintained?
-
A
Perform regular system security testing
-
B
Design security early in the development cycle
-
C
Analyze logs to determine user activities
-
D
Perform quarterly risk assessments
Reveal answer details
Close answer details
Question 98
Single choice
Which of the following defines the key exchange for Internet Protocol Security (IPSec)?
-
A
Secure Sockets Layer (SSL) key exchange
-
B
Internet Key Exchange (IKE)
-
C
Security Key Exchange (SKE)
-
D
Internet Control Message Protocol (ICMP)
Reveal answer details
Close answer details
Question 99
Single choice
Alternate encoding such as hexadecimal representations is MOST often observed in which of the following forms of attack?
-
A
-
B
-
C
-
D
Cross site scripting (XSS)
Reveal answer details
Close answer details
Question 100
Single choice
Discretionary Access Control (DAC) is based on which of the following?
-
A
Information source and destination
-
B
Identification of subjects and objects
-
C
Security labels and privileges
-
D
Reveal answer details
Close answer details
|