A security administrator protects passwords by using hashing. Which of the following best describes what the administrator is doing?
A company receives an alert that a widely used network device vendor has been banned by the government. What will general counsel most likely be concerned with during hardware refresh?
The Chief Information Security Officer wants to put security measures in place to protect PlI. The organization needs to use its existing labeling and classification system to accomplish this goal. Which of the following would most likely be configured to meet the requirements?
Which of the following should a systems administrator use to ensure an easy deployment of resources within the cloud provider?
A network engineer is increasing the overall security of network devices and needs to harden the devices. Which of the following will best accomplish this task?
A security analyst learns that an attack vector, used as part of a recent incident, was a well-known IoT device exploit. The analyst needs to review logs to identify the time of the initial exploit. Which of the following logs should the analyst review first?
An organization is evaluating the cost of licensing a new solution to prevent ransomware. Which of the following is the most helpful in making this decision?
Which of the following describes the reason root cause analysis should be conducted as part of incident response?
A security administrator needs to protect the integrity of a compromised laptop. The administrator turns off the laptop for a forensic investigation. Which of the following tasks should the administrator do first before analyzing the hard drive?
A forensic engineer determines that the root cause of a compromise is a SQL injection attack. Which of the following should the engineer review to identify the command used by the threat actor?
Which of the following technologies assists in passively verifying the expired status of a digital certificate?
A software developer released a new application and is distributing application files via the developer’s website. Which of the following should the developer post on the website to allow users to verify the integrity of the downloaded files?
Which of the following would most likely be deployed to obtain and analyze attacker activity and techniques?
Which of the following would best provide insights on the potential impact of a vendor ' s processes on the security of a buyer ' s network?
Which of the following is most likely to be used as a just-in-time reference document within a security operations center?
The internal audit team determines a software application is no longer in scope for external reporting requirements. Which of the following will confirm management’s perspective that the application is no longer applicable?
A company wants to reduce the time and expense associated with code deployment. Which of the following technologies should the company utilize?
A company that has a large IT operation is looking to better control, standardize, and lower the time required to build new servers. Which of the following architectures will best achieve the company’s objectives?
Which of the following is most important to maintain when it comes to evidence during a digital forensic investigation?
Which of the following security concepts is accomplished when granting access after an individual has logged into a computer network?