As part of a security audit in the software development life cycle, a product manager must demonstrate and provide evidence of a complete representation of the code and modules used within the production-deployed application prior to the build. Which of the following best provides the required evidence?
A. Software composition analysis
B. Runtime application inspection
C. Static application security testing
D. Interactive application security testing
Show Answer
Correct Answer: A
Explanation: Software composition analysis inventories an application’s components and dependencies before the build, providing the basis for a software bill of materials. Runtime inspection occurs after deployment; SAST and IAST test for vulnerabilities rather than provide a component inventory.
Question 62
A Chief Information Security Officer receives the following findings from a third-party risk assessment report:
Finding #1: Absence of a risk management process
Finding #2: Absence of a formal information security management system
Finding #3: Absence of formal procedures to review access
Finding #4: Absence of management engagement on monitoring security objectives
Which of the following is best for the security team to use when remediating the findings?
A. Incorporate PCI DSS compliance.
B. Implement ISO/IEC 27001 standard recommendation.
C. Use OWASP to implement consistent security testing.
D. Research appropriate CIS benchmarks and apply them.
Show Answer
Correct Answer: B
Explanation: ISO/IEC 27001 provides a framework for an information security management system (ISMS), including risk management, access control reviews, and management oversight of security objectives. PCI DSS, OWASP, and CIS Benchmarks address narrower needs and would not remediate all four findings.
Question 63
A penetration tester is drafting a report of findings and recommendations. Multiple EOL biomedical devices were compromised using a combination of known-exploit payloads for CVEs and VLAN hopping. The tester acknowledges that the systems cannot be changed or replaced in the hospital due to regulatory, safety, and cost reasons. Which of the following are the most effective controls for this scenario? (Choose two.)
A. Deploying an IDS with active response for threat activities from a network tap
B. Implementing QoS that limits the throughput of the link speeds from some VLANs
C. Limiting trunking protocols to specific uplink ports of access switches
D. Adding a proxy and requiring medical staff to authenticate every connection
E. Inserting an in-line IPS between network segments of the affected hosts
F. Performing security awareness training for these devices users
Show Answer
Correct Answer: C, E
Explanation: Restricting trunking to designated uplink ports helps prevent VLAN hopping. An in-line IPS can block known-exploit traffic between network segments, providing a compensating control for devices that cannot be patched or replaced.
Sources:
https://deepstrike.io/blog/iomt-vulnerabilities-statistics-2025
Question 64
A company finds logs with modified time stamps when compared to other systems. The security team decides to improve logging and auditing for incident response. Which of the following should the team do to best accomplish this goal?
A. Integrate a file-monitoring tool with the SIEM.
B. Change the log solution and integrate it with the existing SIEM.
C. Implement a central logging server, allowing only log ingestion.
D. Rotate and back up logs every 24 hours, encrypting the backups.
Show Answer
Correct Answer: C
Explanation: A centralized logging server that only accepts log ingestion limits the ability to alter or delete collected logs, improving their integrity and making them more reliable for auditing and incident response.
Question 65
The ISAC for the retail industry recently released a report regarding social engineering tactics in which small groups create distractions for employees while other malicious individuals install advanced card skimmers on the payment systems. The Chief Information Security Officer (CISO) thinks that security awareness training, technical control implementations, and governance already in place is adequate to protect from this threat. The board would like to test these controls. Which of the following should the CISO recommend?
A. Dark web monitoring
B. Adversary emulation engagement
C. Supply chain risk consultation
D. Tabletop exercises
Show Answer
Correct Answer: B
Explanation: An adversary emulation engagement recreates realistic attacker tactics—such as distracting employees while attempting to install a skimmer—to test whether existing awareness, technical, and governance controls work in practice. A tabletop exercise would primarily test discussion-based response processes, not directly validate defenses against the attack.
Question 66
An administrator brings the company's fleet of mobile devices into its PKI in order to align device WLAN NAC configurations with existing workstations and laptops. Thousands of devices need to be reconfigured in a cost-effective, time-efficient, and secure manner. Which of the following actions best achieve this goal? (Choose two.)
A. Using the existing MDM solution to integrate with directory services for authentication and enrollment
B. Deploying netAuth extended key usage certificate templates
C. Deploying serverAuth extended key usage certificate templates
D. Deploying clientAuth extended key usage certificate templates
E. Configuring SCEP on the CA with an OTP for bulk device enrollment
F. Submitting a CSR to the CAto obtain a single certificate that can be used across all devices
Show Answer
Correct Answer: A, E
Explanation: Integrating the existing MDM with directory services supports centralized, automated enrollment and management. SCEP with one-time passwords provides a scalable and secure way to enroll certificates on thousands of devices. The issued WLAN client certificates should use the appropriate client-authentication profile.
Question 67
An organization that performs real-time financial processing is implementing a new backup solution. Given the following business requirements:
• The backup solution must reduce the risk for potential backup compromise
• The backup solution must be resilient to a ransomware attack
• The time to restore from backups is less important than the backup data integrity
• Multiple copies of production data must be maintained.
Which of the following backup strategies best meets these requirements?
A. Creating a secondary, immutable database and adding live data on a continuous basis
B. Utilizing two connected storage arrays and ensuring the arrays constantly sync
C. Enabling remote journaling on the databases to ensure real-time transactions are mirrored
D. Setting up anti-tampering on the databases to ensure data cannot be changed unintentionally
Show Answer
Correct Answer: A
Explanation: A secondary immutable database maintains another copy of production data while preventing backup data from being altered or encrypted by ransomware. Because integrity is more important than restore speed, this protected copy best fits the requirements. Constantly synchronized arrays or journals may replicate malicious changes, while anti-tampering alone does not provide multiple backup copies.
Question 68
A company recently experienced a ransomware attack. Although the company performs systems and data backup on a schedule that aligns with its RPO requirements, the backup administrator could not recover critical systems and data from its offline backups to meet the RPO. Eventually, the systems and data were restored with information that was six months outside of RPO requirements. Which of the following actions should the company take to reduce the risk of a similar attack?
A. Encrypt and label the backup tapes with the appropriate retention schedule before they are sent to the off-site location.
B. Implement a business continuity process that includes reverting manual business processes.
C. Perform regular disaster recovery testing of IT and non-IT systems and process.
D. Carry out a tabletop exercise to update and verify the RACI matrix with IT and critical business functions.
Show Answer
Correct Answer: C
Explanation: Regular disaster recovery testing verifies that backups can actually be restored and that systems and data can be recovered within the required RPO. The other options address tape handling, manual continuity procedures, or role clarity, but do not test restoration capability.
Question 69
A user tried to access a web page at http://10.1.11. Previously the web page did not require authentication, and now the browser is prompting for credentials. Which of the following actions would best prevent the issue from reoccurring and reduce the likelihood of credential exposure?
A. Implementing 802.1x EAP-TTLS on access points to reduce the risk of evil twins
B. Transitioning internal services to use DNS security
C. Modifying web server configuration and utilizing X509 certificates for authentication
D. Installing new rules for the IDS to detect impersonation attacks
Show Answer
Correct Answer: A
Explanation: An unexpected credential prompt for a previously unauthenticated page can indicate an evil-twin access point impersonating the legitimate network or service. 802.1X EAP-TTLS with proper server-certificate validation helps prevent users from connecting to rogue access points and reduces the chance of credentials being exposed.
Question 70
An organization determined its preparedness for a ransomware attack is inadequate. A security administrator is working on ways to improve and monitor the organization's response to ransomware attacks. Which of the following is the best action for the administrator to take?
A. Conduct backup testing.
B. Define the recovery point objective.
C. Perform a business impact analysis.
D. Verify the encryption key length.
Show Answer
Correct Answer: A
Explanation: Testing backups verifies that the organization can successfully restore data after a ransomware attack, directly improving and monitoring its recovery readiness. Defining an RPO and conducting a business impact analysis support broader continuity planning, while encryption key length does not assess ransomware response capability.
$19
Get all 400 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.