A Chief Information Security Officer wants to monitor the company ' s servers for SQLi attacks and allow for comprehensive investigations if an attack occurs. The company uses SSL decryption to allow traffic monitoring. Which of the following strategies would best accomplish this goal?
A company prevented direct access from the database administrators’ workstations to the network segment that contains database servers. Which of the following should a database administrator use to access the database servers?
Which of the following is the best way to sanitize an SSD to prevent the exposure of sensitive data while allowing the drive to be reused?
Which of the following activities uses OSINT?
While updating the security awareness training, a security analyst wants to address issues created if vendors ' email accounts are compromised. Which of the following recommendations should the security analyst include in the training?
Which of the following is the best method to reduce the attack surface of an enterprise network?
In which of the following scenarios is tokenization the best privacy technique 10 use?
After a recent vulnerability scan, a security engineer needs to harden the routers within the corporate network. Which of the following is the most appropriate to disable?
A software development manager wants to ensure the authenticity of the code created by the company. Which of the following options is the most appropriate?
Which of the following would be most useful in determining whether the long-term cost to transfer a risk is less than the impact of the risk?
A spoofed identity was detected for a digital certificate. Which of the following are the type of unidentified key and the certificate mat could be in use on the company domain?
A company performs a risk assessment on the information security program each year. Which of the following best describes this risk assessment?
Which of the following metrics are used to calculate the risk rating in a matrix format? Select two.
Which of the following would most likely prevent exploitation of an end-of-life, business-critical system?
Which of the following describes the procedures a penetration tester must follow while conducting a test?
An important patch for a critical application has just been released, and a systems administrator is identifying all of the systems requiring the patch. Which of the following must be maintained in order to ensure that all systems requiring the patch are updated?
A security audit of an organization revealed that most of the IT staff members have domain administrator credentials and do not change the passwords regularly. Which of the following solutions should the security learn propose to resolve the findings in the most complete way?
An employee in the accounting department receives an email containing a demand for payment tot services performed by a vendor However, the vendor is not in the vendor management database. Which of the following in this scenario an example of?
A security operations center determines that the malicious activity detected on a server is normal. Which of the following activities describes the act of ignoring detected activity in the future?
Which of the following is a security benefit of an effective IT asset tracking system?