A Chief Information Security Officer (CISO) has developed information security policies that relate to the software development methodology. Which of the following would the CISO most likely include in the organization’s documentation?
A. Peer review requirements
B. Multifactor authentication
C. Branch protection tests
D. Secrets management configurations
Show Answer
Correct Answer: A
Explanation: Information security policies tied to the software development methodology focus on governance and process requirements within the SDLC. Peer review requirements are a policy-level control that enforces secure coding practices and quality assurance across development. The other options are technical or implementation-specific controls rather than methodology documentation.
Question 94
Which of the following is the stage in an investigating when forensic images are obtained?
A. Acquisition
B. Preservation
C. Reporting
D. E-discovery
Show Answer
Correct Answer: A
Explanation: In a forensic investigation, forensic images are created during the acquisition stage, where a bit-by-bit copy of digital evidence is collected for analysis while preserving the integrity of the original data. Preservation focuses on safeguarding evidence, reporting documents findings, and e-discovery relates to legal collection of ESI rather than imaging.
Question 95
A company is considering an expansion of access controls for an application that contractors and internal employees use to reduce costs. Which of the following risk elements should the implementation team understand before granting access to the application?
A. Threshold
B. Appetite
C. Avoidance
D. Register
Show Answer
Correct Answer: B
Explanation: Before expanding access to an application for contractors and employees, the implementation team must understand the organization’s risk appetite—the amount and type of risk the organization is willing to accept to achieve its objectives. Access expansion introduces security and compliance risks, and decisions should align with this tolerance. Thresholds are derived from appetite, avoidance is a response strategy rather than a guiding element, and a risk register is a documentation tool, not the governing risk parameter.
Question 96
Which of the following activities uses OSINT?
A. Social engineering testing
B. Data analysis of logs
C. Collecting evidence of malicious activity
D. Producing IOC for malicious artifacts
Show Answer
Correct Answer: A
Explanation: OSINT focuses on gathering information from publicly available sources. Social engineering testing explicitly relies on OSINT (e.g., social media, company websites, public records) to profile targets and craft realistic scenarios. The other activities primarily depend on internal telemetry, forensic analysis, or technical malware analysis rather than open sources.
Question 97
A security engineer at a large company needs to enhance IAM in order to ensure that employees can only access corporate systems during their shifts. Which of the following access controls should the security engineer implement?
A. Role-based
B. Time-of-day restrictions
C. Least privilege
D. Biometric authentication
Show Answer
Correct Answer: B
Explanation: The requirement is to allow access only during employees’ scheduled shifts, which is a time-based condition. Time-of-day restrictions explicitly limit system access to defined hours. Role-based access, least privilege, and biometric authentication control *who* or *what level* of access is granted, not *when* it is allowed.
Question 98
Which of the following is a reason environmental variables are a concern when reviewing potential system vulnerabilities?
A. The contents of environmental variables could affect the scope and impact of an exploited vulnerability.
B. In-memory environmental variable values can be overwritten and used by attackers to insert malicious code.
C. Environmental variables define cryptographic standards for the system and could create vulnerabilities if deprecated algorithms are used.
D. Environmental variables will determine when updates are run and could mitigate the likelihood of vulnerability exploitation.
Show Answer
Correct Answer: A
Explanation: Environmental variables often store configuration and sensitive data (e.g., credentials, paths, runtime options). If a vulnerability is exploited, access to or manipulation of these variables can significantly expand the scope and impact of the attack, such as enabling privilege escalation or access to additional systems.
Question 99
While conducting a business continuity tabletop exercise, the security team becomes concerned by potential impact if a generator was to develop a fault during failover. Which of the following is the team most likely to consider in regard to risk management activities?
A. RPO
B. ARO
C. BIA
D. MTTR
Show Answer
Correct Answer: C
Explanation: The scenario focuses on concern about the potential impact to the business if a generator fails during failover in a business continuity exercise. Assessing the consequences of such a disruption on critical operations is the purpose of a Business Impact Analysis (BIA). BIA evaluates how outages affect the organization and informs risk management priorities. RPO addresses data loss tolerance, ARO addresses frequency of occurrence, and MTTR addresses recovery time, none of which primarily assess business impact.
Question 100
An administrator is creating a secure method for a contractor to access a test environment. Which of the following would provide the contractor with the best access to the test environment?
A. Application server
B. Jump server
C. RDP server
D. Proxy server
Show Answer
Correct Answer: B
Explanation: A jump server (bastion host) provides a secure, controlled entry point into a restricted environment. Contractors connect to the jump server first, and from there are granted limited, monitored access to the test environment. This reduces direct exposure, enforces access controls, and supports auditing, making it the best option compared with an application server, generic RDP server, or proxy server.
Question 101
Which of the following is a type of vulnerability that refers to the unauthorized installation of applications on a device through means other than the official application store?
A. Cross-site scripting
B. Buffer overflow
C. Jailbreaking
D. Side loading
Show Answer
Correct Answer: D
Explanation: The vulnerability described involves installing applications from sources other than an official app store. This is known as side loading, which bypasses standard store security checks and can introduce unauthorized or malicious apps. Cross-site scripting and buffer overflow are unrelated software vulnerabilities, and jailbreaking refers to modifying the operating system itself rather than the act of installing apps from unofficial sources.
Question 102
Which of the following should be used to aggregate log data in order to create alerts and detect anomalous activity?
A. SIEM
B. WAF
C. Network taps
D. IDS
Show Answer
Correct Answer: A
Explanation: SIEM platforms are specifically designed to collect, aggregate, correlate, and analyze log data from multiple sources, enabling alerting and detection of anomalous or malicious activity. WAFs, network taps, and IDS tools have narrower roles and do not provide centralized log aggregation and correlation at the same level.
$19
Get all 609 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.