Security and Risk ManagementAsset SecuritySecurity Architecture and EngineeringCommunication and Network SecurityIdentity and Access Management (IAM)Security Assessment and TestingSecurity OperationsSoftware Development Security
When auditing the Software Development Life Cycle (SDLC), which of the following is a high-level audit phase?
APlanning
BRisk assessment
CDue diligence
DRequirements
An organization deploys Network Access Control (NAC) with Institute of Electrical and Electronics Engineers (IEEE) 802.1X and finds that its printers do not support the IEEE 802.1X standard. Which of the following is the BEST resolution?
AImplement port security on the switch ports for the printers.
BDo nothing; IEEE 802.1x is irrelevant to printers.
CInstall an IEEE 802.1x bridge for the printers.
DImplement a virtual local area network (VLAN) for the printers.
At which Open Systems Interconnection (OSI) model layer does a circuit-level firewall function?
ASession layer
BNetwork layer
CApplication layer
DTransport layer
Which dynamic routing protocol is BEST suited to a dispersed campus network that uses Internet Protocol version 6 (IPv6) addresses?
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
An Information System Security Officer (ISSO) working for a large corporation, while also freelancing in a comparable role for a competitor, violates which canon of the (ISC)2 Code of Professional Ethics?
AAdvance and protect the profession
BProvide diligent and competent service to principals
CAct honorably, honestly, justly, responsibly, and legally
DProtect society, the commonwealth, and the infrastructure
A web developer is finalizing a security checklist for a new web application before deploying the application to production. Disabling unneeded services is included on the checklist. Which web application threat does this action mitigate?
ASession hijacking
BSecurity misconfiguration
CBroken access control
DSensitive data exposure
A security engineer must incorporate security into a software project carried out by small groups that rapidly, continuously, and independently develop, test, and deploy code to the cloud. With which software development process will the engineer MOST likely integrate?
ADevops Integrated Product Team (IPT)
BStructured Waterfall Programming Development
CService-oriented architecture (SOA)
DSpiral Methodology
What benefit does an operating system (OS) feature provide when it is designed to stop an application from running code from a non-executable memory region?
AIdentifies which security patches still need to be installed on the system
BReduces the risk of polymorphic viruses from encrypting their payload
CStops memory resident viruses from propagating their payload
DHelps prevent certain exploits that store code in buffers
When is an organization required to review its information security strategic plan?
AWhenever there are major changes to the business
BQuarterly, when the organization's strategic plan is updated
CEvery three years, when the organization's strategic plan is updated
DWhenever there are significant changes to a major application
What is the MOST common security risk for a mobile device?
AData spoofing
BMalware infection
CInsecure communications link
DData leakage
Which of the following is the primary cryptographic type required to support non-repudiation for a digitally signed document?
AHashing
BMessage digest (MD)
CSymmetric
DAsymmetric
Which of the following is a type of covert channel?
APipe
BMemory
CStorage
DMonitoring
When implementing single sign-on (SSO) on a network, which authentication approach BEST enables users to use their credentials across multiple applications?
APublic key infrastructure (PKI)
BSecurity Assertion Markup Language (SAML)
CDelegated Identity Management
DFederated Identity Management
A security professional has reviewed a recent site assessment and noted that a server room on the second floor of a building has Heating, Ventilation, and Air Conditioning (HVAC) intakes at ground level with ultraviolet light filters installed, Aero-K fire suppression in the server room, and pre-action fire suppression on floors above the server room. Which of the following changes can the security professional recommend to reduce the risk associated with these conditions?
ARemove the ultraviolet light filters on the HVAC intake and replace the fire suppression system on the upper floors with a dry system
BElevate the HVAC intake by constructing a plenum or external shaft over it and convert the server room fire suppression to a pre-action system
CAdd additional ultraviolet light fi lters to the HVAC intake supply and return ducts and change server room fire suppression to FM-200
DApply additional physical security around the HVAC intakes and update upper floor fire suppression to FM-200
A bank did not meet customer service-level agreements (SLAs) after a database failure in its transaction processing system (TPS) caused financial deposits to be delayed. A regulatory agency that oversees the bank wants to determine whether the delay's cause was a material weakness. Which of the following documents is MOST relevant for the regulatory agency to review?
ABusiness continuity plan (BCP)
BBusiness impact analysis (BIA)
CContinuity of Operations Plan (COOP)
DEnterprise resource planning (ERP)
Which of the following is the BEST method for protecting an organization's data assets?
AEncrypt data in transit and at rest using up-to-date cryptographic algorithms.
BMonitor and enforce adherence to security policies.
CRequire Multi-Factor Authentication (MFA) and Separation of Duties (SoD).
DCreate the Demilitarized Zone (DMZ) with proxies, firewalls and hardened bastion hosts.
When designing a Cyber-Physical System (CPS), what should be a security practitioner’s initial consideration?
ADetection of sophisticated attackers
BTopology of the network used for the system
CRisk assessment of the system
DResiliency of the system
When assessing vendor certifications for the handling and processing of company data, which of the following is the BEST Service Organization Controls (SOC) certification for the vendor to hold?
ASOC 1 Type 1
BSOC 2 Type 1
CSOC 2 Type 2
DSOC 3
What is the PRIMARY objective of logical access controls?
ARestrict access to an information asset.
BEnsure availability of an information asset.
CRestrict physical access to an information asset.
DEnsure integrity of an information asset.
What is a commonly used term for log reviews, synthetic transactions, and code reviews?
AApplication development
BSpiral development functional testing
CSecurity control testing
DDevOps Integrated Product Team (IPT) development
For a security-breach victim to prevail on a negligence claim, what MUST the victim prove?
AConcern
BBreach of contract
CProximate cause
DHardship
What is static analysis designed to do when it examines an executable file?
ASearch the documents and files associated with the executable file.
BAnalyze the position of the file in the file system and the executable file's libraries.
CCollect evidence of the executable file's usage, including dates of creation and last use.
DDisassemble the file to gather information about the executable file's function.
A criminal organization is preparing an attack against a government network. Which of the following scenarios poses the HIGHEST risk to the organization?
AOrganization loses control of their network devices.
BNetwork is flooded with communication traffic by the attacker.
CNetwork management communications is disrupted.
DAttacker accesses sensitive information regarding the network topology.
An organization is deploying data encryption with symmetric ciphers, and the Chief Information Officer (CIO) is worried about the risk of relying on a single key to protect all sensitive data. A security practitioner must recommend a solution that addresses the CIO's concern. Which of the following is the BEST way to meet this objective while encrypting all sensitive data?
Community Discussion