A company must meet the following security requirements when implementing controls in order to be compliant with government policy:
• Access to the system document repository must be MFA enabled.
• Ongoing risk monitoring must be displayed on a system dashboard.
• Staff must receive email notifications about periodic tasks.
Which of the following best meets all of these requirements?
A. Implementing a GRC tool
B. Configuring a privileged access management system
C. Launching a vulnerability management program
D. Creating a risk register
Show Answer
Correct Answer: A
Explanation: A GRC tool can centralize compliance controls, display ongoing risk information on dashboards, and automate email reminders for recurring tasks. It can also integrate with identity and access management to require MFA for the document repository.
Question 162
During a security review for the CI/CD process, a security engineer discovers the following information in a testing repository from the company:
Which of the following options is the best countermeasure to prevent this issue in the future?
A. Performing an application penetration test over the testing environment before moving to production
B. Changing the repository technology to avoid inclusion of confidential information
C. Automating the upload process of code to the repository and improving the software development life cycle
D. Using a secrets management platform to share and manage confidential information
Show Answer
Correct Answer: D
Explanation: A secrets management platform keeps credentials and other confidential information out of the repository while providing a secure way to store, control, and distribute them. The other options do not directly prevent sensitive information from being committed to code.
Question 163
A company plans to deploy a new online application that provides video training for its customers. As part of the design, the application must be:
• Fast for all users
• Available for users worldwide
• Protected against attacks
Which of the following are the best components the company should use to meet these requirements? (Choose two.)
A. WAF
B. IPS
C. CDN
D. SASE
E. VPN
F. CASB
Show Answer
Correct Answer: A, C
Explanation: A WAF protects the public-facing application from common web attacks. A CDN distributes and caches video content at locations near users, improving performance and availability worldwide.
Question 164
An organization is implementing Zero Trust architecture. A systems administrator must increase the effectiveness of the organization's context-aware access system. Which of the following is the best way to improve the effectiveness of the system?
A. Secure zone architecture
B. Always-on VPN
C. RADIUS
D. Microsegmentation
Show Answer
Correct Answer: D
Explanation: Microsegmentation applies fine-grained access policies between workloads and network segments, supporting Zero Trust by restricting access and limiting lateral movement. An always-on VPN, RADIUS, and secure-zone architecture do not directly provide that level of granular enforcement.
Question 165
A company isolates its ОТ systems from other areas of the corporate network. These systems are required to report usage information over the internet to the vendor. Which of the following best prevents compromise or sabotage? (Choose two.)
A. Implementing allow lists
B. Monitoring network behaviors
C. Encrypting data at rest
D. Performing boot integrity checks
E. Executing daily health checks
F. Implementing a site-to-site IPSec VPN
Show Answer
Correct Answer: A, F
Explanation: Allowlisting restricts OT communications to approved applications or destinations, reducing unauthorized access and exposure. A site-to-site IPsec VPN protects and authenticates the required communications with the vendor. Together, these controls limit the connection and secure its traffic.
Question 166
In a recent audit, several critical legacy systems, which are externally exposed so that a specific vendor can manage them remotely, were identified. These systems must remain available to the vendor for the next six months. A security team segmented the network so these systems can only communicate with internal resources. Which of the following actions would be most appropriate to restore the vendor's access to manage these systems?
A. Disable all connections to the systems, and implement a backup solution to capture the needed data to send to the vendor on a weekly basis.
B. Create a VPN connection and set up firewall rules so only specific connections are allowed to those systems.
C. Disable external connections to those systems for the next six months.
D. Isolate the critical systems so they can only be remotely managed from the internet.
Show Answer
Correct Answer: B
Explanation: Establish a VPN for the vendor and use restrictive firewall rules to permit only the necessary management traffic to the legacy systems. This restores remote access without exposing them broadly to the internet.
Question 167
An organization hires a security consultant to establish a SOC that includes a threat-modeling function. During initial activities, the consultant works with system engineers to identify antipatterns within the environment. Which of the following is most critical for the engineers to disclose to the consultant during this phase?
A. Results from the most recent infrastructure access review
B. A listing of unpatchable IoT devices in use in the data center
C. Network and data flow diagrams covering the production environment
D. Results from the most recent software composition analysis
E. A current inventory of cloud resources and SaaS products in use
Show Answer
Correct Answer: C
Explanation: Production network and data flow diagrams give engineers and the consultant a view of system architecture, trust boundaries, and how data moves between components. That information is most critical for identifying architectural antipatterns during threat modeling.
Question 168
An auditor is reviewing the logs from a web application to determine the source of an incident. The web application architecture includes an internet-accessible application load balancer, a number of web servers in a private subnet, application servers, and one database server in a tiered configuration. The application load balancer cannot store the logs. The following are sample log snippets:
Which of the following should the auditor recommend to ensure future incidents can be traced back to the sources?
A. Enable the X-Forwarded-For header at the load balancer.
B. Install a software-based HIDS on the application servers.
C. Install a certificate signed by a trusted CA.
D. Use stored procedures on the database server.
E. Store the value of the $_SERVER['REMOTE_ADDR'] received by the web servers.
Show Answer
Correct Answer: A
Explanation: The load balancer acts as the web servers’ network peer, so their REMOTE_ADDR value would typically identify the load balancer rather than the original client. Forwarding the client IP in the X-Forwarded-For header lets the web servers record it and preserve source attribution for later investigation.
Question 169
A company needs to define a new road map for improving secure coding practices in the software development life cycle and implementing better security standards. Which of the following is the best way for the company to achieve this goal?
A. Performing a Software Assurance Maturity Model assessment and generating a road map as a final result
B. Conducting a threat-modeling exercise for the main applications and developing a road map based on the necessary security implementations
C. Developing a new road map, including secure coding best practices, based on the security area road map and annual goals defined by the Chief Information Security Officer
D. Using the best practices in the OWASP secure coding manual to define a new road map
Show Answer
Correct Answer: A
Explanation: A Software Assurance Maturity Model (SAMM) assessment evaluates the organization’s current software security practices and helps identify prioritized improvements, producing a tailored roadmap for strengthening secure coding and security across the SDLC.
Question 170
A security officer performs due diligence activities before implementing a third-party solution into the enterprise environment. The security officer needs evidence from the third party that a data subject access request handling process is in place. Which of the following is the security officer most likely seeking to maintain compliance?
A. Information security standards
B. E-discovery requirements
C. Privacy regulations
D. Certification requirements
E. Reporting frameworks
Show Answer
Correct Answer: C
Explanation: A data subject access request (DSAR) is a privacy right under regulations such as the GDPR. Evidence that the third party has a process for handling DSARs supports compliance with privacy regulations.
$19
Get all 400 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.