Which of the following is MOST likely caused by improper input handling?
A. Untrusted certificate warning
B. Breach of firewall ACLs
C. Power off reboot loop
D. Loss of database tables
正解:D
質問 2:
A security administrator has been tasked with implementing controls that meet management goals. Drag and drop the appropriate control used to accomplish the account management goal. Options may be used once or not at all.

正解:

質問 3:
When a malicious user is able to retrieve sensitive information from RAM, the programmer has failed a implement:
A. ephemeral keys.
B. encryption of data in use.
C. encryption of data at rest
D. session keys.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Which of the following is a type of attack in which a hacker leverages previously obtained packets to gam access to a wireless network?
A. Replay attack
B. Bluesnarfing
C. ARP poisoning
D. IP spoofing
正解:A
質問 5:
A developer has just finished coding a custom web application and would like to test it for bugs by automatically injecting malformed data into it. Which of the following is the developer looking to perform?
A. Fuzzing
B. Normalization
C. Sandboxing
D. Stress testing
正解:A
質問 6:
An organization recently acquired an ISO 27001 certification. Which of the following would MOST likely be considered a benefit of this certification?
A. It certifies the organization can work with foreign entities that require a security clearance.
B. It assures customers that the organization meets security standards.
C. It allows for the sharing of digital forensics data across organizations.
D. It provides insurance in case of a data breach.
E. It provides complimentary training and certification resources to IT security staff.
正解:B
質問 7:
An IT manager is estimating the mobile device budget for the upcoming year. Over the last five years, the number of devices that were replaced due to loss, damage, or theft steadily increased by 10%. Which of the following would BEST describe the estimated number of devices to be replaced next year?
A. ARO
B. SLE
C. ALE
D. RPO
正解:B
質問 8:
A user wants to send a confidential message to a customer to ensure unauthorized users cannot access the information. Which of the following can be used to ensure the security of the document while in transit and at rest?
A. BCRYPT
B. FTPS
C. S/MIME
D. PGP
正解:D
質問 9:
An attacker is attempting to harvest user credentials on a client's website. A security analyst notices multiple attempts of random usernames and passwords. When the analyst types in a random username and password, the logon screen displays the following message:
The username you entered does not exist.
Which of the following should the analyst recommend be enabled?
A. Username lockout
B. Error handling
C. Input validation
D. Obfuscation
正解:A
クリック」


0 お客様のコメント