Which part of an operating system (OS) is responsible for providing security interfaces among the hardware, OS, and other parts of the computing system?
AReference monitor
BTrusted Computing Base (TCB)
CTime separation
DSecurity kernel
The security architect is designing and implementing an internal certification authority to generate digital certificates for all employees. Which of the following is the
BEST solution to securely store the private keys?
APhysically secured storage device
BTrusted Platform Module (TPM)
CEncrypted flash drive
DPublic key infrastructure (PKI)
Which of the following is the BEST way to protect an organization's data assets?
AEncrypt data in transit and at rest using up-to-date cryptographic algorithms.
BMonitor and enforce adherence to security policies.
CRequire Multi-Factor Authentication (MFA) and Separation of Duties (SoD).
DCreate the Demilitarized Zone (DMZ) with proxies, firewalls and hardened bastion hosts.
In a quarterly system access review, an active privileged account was discovered that did not exist in the prior review on the production system. The account was created one hour after the previous access review. Which of the following is the BEST option to reduce overall risk in addition to quarterly access reviews?
AImplement bi-annual reviews.
BCreate policies for system access.
CImplement and review risk-based alerts.
DIncrease logging levels.
Question 6
Security and Risk Management
0
Question 7
Security and Risk Management
Question 8
Software Development Security
Question 9
Security Architecture and Engineering
Question 10
Security Architecture and Engineering
Question 11
Security Assessment and Testing
Question 12
Identity and Access Management (IAM)
Question 13
Security Assessment and Testing
Question 14
Security Operations
Question 15
Communication and Network Security
Question 16
Asset Security
Question 17
Security Operations
Question 18
Communication and Network Security
Question 19
Communication and Network Security
Question 20
Identity and Access Management (IAM)
Question 21
Security Assessment and Testing
Question 22
Security Architecture and Engineering
Question 23
Security Assessment and Testing
Question 24
Asset Security
Question 25
Security and Risk Management
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ad
Want a break from the ads?
Become a Supporter and enjoy a completely ad-free experience, plus unlock Learn Mode, Exam Mode, AstroTutor AI, and more.
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
When reviewing vendor certifications for handling and processing of company data, which of the following is the BEST Service Organization Controls (SOC) certification for the vendor to possess?
ASOC 1 Type 1
BSOC 2 Type 1
CSOC 2 Type 2
DSOC 3
What process facilitates the balance of operational and economic costs of protective measures with gains in mission capability?
APerformance testing
BRisk assessment
CSecurity audit
DRisk management
When auditing the Software Development Life Cycle (SDLC) which of the following is one of the high-level audit phases?
APlanning
BRisk assessment
CDue diligence
DRequirements
Which of the following does the security design process ensure within the System Development Life Cycle (SDLC)?
AProper security controls, security objectives, and security goals are properly initiated.
BSecurity objectives, security goals, and system test are properly conducted.
CProper security controls, security goals, and fault mitigation are properly conducted.
DSecurity goals, proper security controls, and validation are properly initiated.
A subscription service which provides power, climate control, raised flooring, and telephone wiring but NOT the computer and peripheral equipment is BEST described as a:
Acold site.
Bwarm site.
Chot site.
Dreciprocal site.
What is the BEST approach to anonymizing personally identifiable information (PII) in a test environment?
ASwapping data
BRandomizing data
CEncoding data
DEncrypting data
An organization has implemented a protection strategy to secure the network from unauthorized external access. The new Chief Information Security Officer
(CISO) wants to increase security by better protecting the network from unauthorized internal access. Which Network Access Control (NAC) capability BEST meets this objective?
APort security
BTwo-factor authentication (2FA)
CStrong passwords
DApplication firewall
Which of the following threats would be MOST likely mitigated by monitoring assets containing open source libraries for vulnerabilities?
ADistributed denial-of-service (DDoS) attack
BAdvanced persistent threat (APT) attempt
CZero-day attack
DPhishing attempt
Which of the following ensures old log data is not overwritten?
ALog retention
BImplement Syslog
CIncrease log file size
DLog preservation
Which of the following virtual network configuration options is BEST to protect virtual machines (VM)?
AData segmentation
BData encryption
CTraffic filtering
DTraffic throttling
An organization has been collecting a large amount of redundant and unusable data and filling up the storage area network (SAN). Management has requested the identification of a solution that will address ongoing storage problems. Which is the BEST technical solution?
ACompression
BCaching
CReplication
DDeduplication
Which of the following is included in change management?
ATechnical review by business owner
BUser Acceptance Testing (UAT) before implementation
CCost-benefit analysis (CBA) after implementation
DBusiness continuity testing
When designing a new Voice over Internet Protocol (VoIP) network, an organization's top concern is preventing unauthorized users accessing the VoIP network.
Which of the following will BEST help secure the VoIP network?
A802.11g
BWeb application firewall (WAF)
CTransport Layer Security (TLS)
D802.1x
Which of the following is the PRIMARY type of cryptography required to support non-repudiation of a digitally signed document?
AHashing
BMessage digest (MD)
CSymmetric
DAsymmetric
An organization would like to ensure that all new users have a predefined departmental access template applied upon creation. The organization would also like additional access for users to be granted on a per-project basis. What type of user access administration is BEST suited to meet the organization's needs?
ADecentralized
BHybrid
CCentralized
DFederated
What is the PRIMARY consideration when testing industrial control systems (ICS) for security weaknesses?
AICS often run on UNIX operating systems.
BICS often do not have availability requirements.
CICS are often sensitive to unexpected traffic.
DICS are often isolated and difficult to access.
A Simple Power Analysis (SPA) attack against a device directly observes which of the following?
AMagnetism
BGeneration
CConsumption
DStatic discharge
Which security audit standard provides the BEST way for an organization to understand a vendor's Information Systems (IS) in relation to confidentiality, integrity, and availability?
AService Organization Control (SOC) 2
BStatement on Standards for Attestation Engagements (SSAE) 18
CStatement on Auditing Standards (SAS) 70
DService Organization Control (SOC) 1
An organization is looking to include mobile devices in its asset management system for better tracking. In which system tier of the reference architecture would mobile devices be tracked?
A0
B1
C2
D3
A criminal organization is planning an attack on a government network. Which of the following scenarios presents the HIGHEST risk to the organization?
AOrganization loses control of their network devices.
BNetwork is flooded with communication traffic by the attacker.
CNetwork management communications is disrupted.
DAttacker accesses sensitive information regarding the network topology.