Which of the following should a security analyst consider when prioritizing remediation efforts against known vulnerabilities?
A company with a high-availability website is looking to harden its controls at any cost. The company wants to ensure that the site is secure by finding any possible issues. Which of the following would most likely achieve this goal?
The Chief Information Security Officer gives the security community the opportunity to report vulnerabilities on the organization’s public-facing assets. Which of the following does this scenario best describe?
Which of the following most accurately describes the order in which a security engineer should implement secure baselines?
A security analyst must identify abnormal behavior on the server. Which of the following does the analyst most likely need to do?
A penetration tester begins an engagement by performing port and service scans against the client environment according to the rules of engagement. Which of the following reconnaissance types is the tester performing?
A security engineer is working to address the growing risks that shadow IT services are introducing to the organization. The organization has taken a cloud-first approach end does not have an on-premises IT infrastructure. Which of the following would best secure the organization?
Which of the following can assist in recovering data if the decryption key is lost?
A company processes a large volume of business-to-business transactions and prioritizes data confidentiality over transaction availability. The company ' s firewall administrator must configure a new hardware-based firewall to replace the current one. Which of the following should the administrator do to best align with the company requirements in case a security event occurs?
A systems administrator is working on a solution with the following requirements:
• Provide a secure zone.
• Enforce a company-wide access control policy.
• Reduce the scope of threats.
Which of the following is the systems administrator setting up?
An administrator investigating an incident is concerned about the downtime of a critical server due to a failed drive. Which of the following would the administrator use to estimate the time needed to fix the issue?
A company is considering an expansion of access controls for an application that contractors and internal employees use to reduce costs. Which of the following risk elements should the implementation team understand before granting access to the application?
Which of the following explains how a supply chain service provider could introduce a security vulnerability into an organization?
Which of the following best describe the benefits of a microservices architecture when compared to a monolithic architecture? (Select two).
An administrator discovers a cross-site scripting vulnerability on a company website. Which of the following will most likely remediate the issue?
An organization experiences a cybersecurity incident involving a command-and-control server. Which of the following logs should be analyzed to identify the impacted host? (Select two).
A manufacturing organization receives the results from a penetration test. According to the results, legacy devices that are critical to continued business function display vulnerabilities. The devices have minimal vendor support and should be segmented and monitored closely. Which of the following devices were most likely identified?
Which of the following would a security administrator use to comply with a secure baseline during a patch update?
Which of the following describes how a risk event might affect operations and limit the overall risk score?
A company must ensure sensitive data at rest is rendered unreadable. Which of the following will the company most likely use?