A security architect wants to prevent security impacts from input into data fields, such as the following:
'AND 1=1#
Which of the following would best accomplish this objective?
A. APIs
B. Coding standards
C. Base64 encoding
D. Sandboxing
Show Answer
Correct Answer: B
Explanation: Secure coding standards can require practices such as parameterized queries and appropriate input validation, which prevent user input like `AND 1=1#` from being interpreted as SQL. Base64 encoding and sandboxing do not directly prevent injection, and APIs alone do not ensure safe input handling.
Question 152
An IT department is currently working to implement an enterprise DLP solution. Due diligence and best practices must be followed in regard to mitigating risk. Which of the following ensures that authorized modifications are well planned and executed?
A. Risk management
B. Network management
C. Configuration management
D. Change management
Show Answer
Correct Answer: D
Explanation: Change management ensures authorized modifications are reviewed, approved, planned, tested, and implemented in a controlled manner.
Question 153
Due to budget constraints, an organization created a policy that only permits vulnerabilities rated high and critical according to CVSS to be fixed or mitigated. A security analyst notices that many vulnerabilities that were previously scored as medium are now breaching higher thresholds. Upon further investigation, the analyst notices certain ratings are not aligned with the approved system categorization. Which of the following can the analyst do to get a better picture of the risk while adhering to the organization’s policy?
A. Align the exploitability metrics to the predetermined system categorization.
B. Align the remediation levels to the predetermined system categorization.
C. Align the impact subscore requirements to the predetermined system categorization.
D. Align the attack vectors to the predetermined system categorization.
Show Answer
Correct Answer: C
Explanation: Align the CVSS impact subscore requirements (confidentiality, integrity, and availability) with the approved system categorization. These environmental metrics reflect the system’s business impact, helping prioritize risk more accurately while retaining the organization’s high/critical remediation policy.
Question 154
A company that uses several cloud applications wants to property identify:
• All the devices potentially affected by a given vulnerability
• All the internal servers utilizing the same physical switch
• The number of endpoints using a particular operating system
Which of the following is the best way to meet the requirements?
A. SBoM
B. CASB
C. GRC
D. CMDB
Show Answer
Correct Answer: D
Explanation: A configuration management database (CMDB) tracks IT assets and their relationships, supporting vulnerability impact analysis, network-topology queries such as shared switch usage, and endpoint counts by operating system.
Question 155
A university issues badges through a homegrown identity management system to all staff and students. Each week during the summer, temporary summer school students arrive and need to be issued a badge to access minimal campus resources. The security team received a report from an outside auditor indicating the homegrown system is not consistent with best practices in the security field. Which of the following should the security team recommend first?
A. Investigating a potential threat identified in logs related to the identity management system
B. Updating the identity management system to use discretionary access control
C. Beginning research on two-factor authentication to later introduce into the identity management system
D. Working with procurement and creating a requirements document to select a new IAM system/vendor
Show Answer
Correct Answer: D
Explanation: A homegrown identity management system that fails to meet security best practices should be replaced with a properly evaluated IAM solution. The first step is to work with procurement to define requirements and select a suitable system. The other options address an unrelated log investigation or isolated controls rather than the underlying IAM problem.
Question 156
A new, online file hosting service is being offered. The service has the following security requirements:
• Threats to customer data integrity and availability should be remediated first.
• The environment should be dynamic to match increasing customer demands.
• The solution should not interfere with customers’ ability to access their data at anytime.
• Security analysts should focus on high-risk items.
Which of the following would best satisfy the requirements?
A. Expanding the use of IPS and NGFW devices throughout the environment
B. Increasing the number of analysts to identify risks that need remediation
C. Implementing a SOAR solution to address known threats
D. Integrating enterprise threat feeds in the existing SIEM
Show Answer
Correct Answer: C
Explanation: A SOAR solution can automatically respond to known threats and prioritize remediation, helping protect data integrity and availability as demand changes. Automating routine responses also lets analysts focus on higher-risk issues, without relying on additional inline devices that could disrupt customer access.
Question 157
A cloud security architect has been tasked with finding a solution for hardening VMs. The solution must meet the following requirements:
• Data needs to be stored outside of the VMs.
• No unauthorized modifications to the VMs are allowed.
• If a change needs to be done, a new VM needs to be deployed.
Which of the following is the best solution?
A. Immutable system
B. Data loss prevention
C. Storage area network
D. Baseline template
Show Answer
Correct Answer: A
Explanation: An immutable system keeps VM instances unchanged after deployment. Data is stored externally, and any required changes are made by deploying a new VM rather than modifying the existing one.
Question 158
An incident response analyst finds the following content inside of a log file that was collected from a compromised server:
Which of the following is the best action to prevent future compromise?
A. Blocking the processing of external files by forwarding them to another server for processing
B. Implementing an allow list for all text boxes throughout the web application
C. Filtering inserted characters for all user inputs and allowing only ASCII characters
D. Improving file-parsing capabilities to stop external entities from executing commands
Show Answer
Correct Answer: D
Explanation: The log indicates an XML External Entity (XXE) attack. Securely configuring XML parsers to disable external entity processing prevents malicious XML from accessing external resources or triggering unintended actions.
Question 159
After discovering that an employee is using a personal laptop to access highly confidential data, a systems administrator must secure the company's data. Which of the following capabilities best addresses this situation?
A. OCSP stapling
B. CASB
C. SOAR
D. Conditional access
E. Package monitoring
Show Answer
Correct Answer: D
Explanation: Conditional access can evaluate the user, device compliance, and risk before granting access, allowing the administrator to block an unmanaged personal laptop from highly confidential data.
Question 160
Based on the results of a SAST report on a legacy application, a security engineer is reviewing the following snippet of code flagged as vulnerable:
Which of the following is the vulnerable line of code that must be changed?
A. Line [02]
B. Line [04]
C. Line [07]
D. Line [08]
E. Line [10]
Show Answer
Correct Answer: E
Explanation: Line [10] is vulnerable: copying the input into the 20-byte `transmit` buffer with `strcpy` can overflow it because `strcpy` does not check the destination’s capacity.
$19
Get all 400 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.