<< Prev Question Next Question >>

Question 36/373

What is one way to mitigate the risk of security flaws in custom software?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (373q)
Question 1: With data labeling, which of the following MUST be the key d...
Question 2: Which of the following is a critical factor for implementing...
Question 3: If an identification process using a biometric system detect...
Question 4: Refer to the information below to answer the question. A lar...
Question 5: Which one of these risk factors would be the LEAST important...
Question 6: Refer to the information below to answer the question. An or...
Question 7: Which type of control recognizes that a transaction amount i...
Question 8: If an attacker in a SYN flood attack uses someone else's val...
Question 9: The goal of software assurance in application development is...
Question 10: Which Hyper Text Markup Language 5 (HTML5) option presents a...
Question 11: DRAG DROP Match the objectives to the assessment questions i...
Question 12: Which of the following is critical for establishing an initi...
Question 13: An organization decides to implement a partial Public Key In...
Question 14: What is the BEST method to detect the most common improper i...
Question 15: What is an effective practice when returning electronic stor...
Question 16: Refer to the information below to answer the question. An or...
Question 17: The PRIMARY purpose of a security awareness program is to...
Question 18: What security management control is MOST often broken by col...
Question 19: Which of the following analyses is performed to protect info...
Question 20: Which of the following is the MOST crucial for a successful ...
Question 21: Refer to the information below to answer the question. Durin...
Question 22: By carefully aligning the pins in the lock, which of the fol...
Question 23: Which of the following is an attacker MOST likely to target ...
Question 24: Which of the following is a limitation of the Common Vulnera...
Question 25: Which of the following describes the BEST configuration mana...
Question 26: A Simple Power Analysis (SPA) attack against a device direct...
Question 27: What is the MAIN feature that onion routing networks offer?...
Question 28: Secure Sockets Layer (SSL) encryption protects...
Question 29: Retaining system logs for six months or longer can be valuab...
Question 30: Which of the following PRIMARILY contributes to security inc...
Question 31: Which one of the following is a fundamental objective in han...
Question 32: What does secure authentication with logging provide?...
Question 33: Refer to the information below to answer the question. Deskt...
Question 34: An organization publishes and periodically updates its emplo...
Question 35: Which of the following are required components for implement...
Question 36: What is one way to mitigate the risk of security flaws in cu...
Question 37: Which of the following is the MOST likely cause of a non-mal...
Question 38: Refer to the information below to answer the question. A new...
Question 39: The use of strong authentication, the encryption of Personal...
Question 40: By allowing storage communications to run on top of Transmis...
Question 41: Which of the following is the BEST example of weak managemen...
Question 42: Which of the following is the MAIN goal of a data retention ...
Question 43: The World Trade Organization's (WTO) agreement on Trade-Rela...
Question 44: Which of the following MOST influences the design of the org...
Question 45: Discretionary Access Control (DAC) is based on which of the ...
Question 46: Which one of the following considerations has the LEAST impa...
Question 47: Which of the following is considered best practice for preve...
Question 48: Which one of the following is the MOST important in designin...
Question 49: The Structured Query Language (SQL) implements Discretionary...
Question 50: The goal of a Business Continuity Plan (BCP) training and aw...
Question 51: A security consultant has been asked to research an organiza...
Question 52: How does an organization verify that an information system's...
Question 53: Which of the following is a physical security control that p...
Question 54: Which of the following violates identity and access manageme...
Question 55: HOTSPOT Which Web Services Security (WS-Security) specificat...
Question 56: Which of the following is a security feature of Global Syste...
Question 57: Which of the following would be the FIRST step to take when ...
Question 58: A mobile device application that restricts the storage of us...
Question 59: What technique BEST describes antivirus software that detect...
Question 60: A health care provider is considering Internet access for th...
Question 61: An auditor carrying out a compliance audit requests password...
Question 62: DRAG DROP Drag the following Security Engineering terms on t...
Question 63: What is the GREATEST challenge to identifying data leaks?...
Question 64: What is the MOST important reason to configure unique user I...
Question 65: Which of the following is the MOST effective method of mitig...
Question 66: Which of the following is generally indicative of a replay a...
Question 67: Which of the following provides the minimum set of privilege...
Question 68: Which of the following is ensured when hashing files during ...
Question 69: The Hardware Abstraction Layer (HAL) is implemented in the...
Question 70: What security risk does the role-based access approach mitig...
Question 71: What should be the INITIAL response to Intrusion Detection S...
Question 72: Which of the following MUST be part of a contract to support...
Question 73: Which of the following is the MOST effective attack against ...
Question 74: A security professional has been asked to evaluate the optio...
Question 75: The use of proximity card to gain access to a building is an...
Question 76: Which one of the following operates at the session, transpor...
Question 77: The BEST way to check for good security programming practice...
Question 78: Which of the following secures web transactions at the Trans...
Question 79: What is the MOST efficient way to secure a production progra...
Question 80: In Disaster Recovery (DR) and business continuity training, ...
Question 81: DRAG DROP A software security engineer is developing a black...
Question 82: Which of the following can BEST prevent security flaws occur...
Question 83: HOTSPOT In the network design below, where is the MOST secur...
Question 84: What is the MOST effective method for gaining unauthorized a...
Question 85: What is the GREATEST challenge of an agent-based patch manag...
Question 86: The BEST method of demonstrating a company's security level ...
Question 87: For privacy protected data, which of the following roles has...
Question 88: According to best practice, which of the following is requir...
Question 89: What type of encryption is used to protect sensitive data in...
Question 90: What would be the PRIMARY concern when designing and coordin...
Question 91: Which of the following disaster recovery test plans will be ...
Question 92: Which of the following statements is TRUE regarding state-ba...
Question 93: An organization has decided to contract with a cloud-based s...
Question 94: Which of the following is the PRIMARY concern when using an ...
Question 95: Which of the following is the MOST difficult to enforce when...
Question 96: Who is ultimately responsible to ensure that information ass...
Question 97: A network scan found 50% of the systems with one or more cri...
Question 98: Which of the following prevents improper aggregation of priv...
Question 99: Refer to the information below to answer the question. A new...
Question 100: Alternate encoding such as hexadecimal representations is MO...
Question 101: The process of mutual authentication involves a computer sys...
Question 102: Which of the following is a security limitation of File Tran...
Question 103: What is the BEST first step for determining if the appropria...
Question 104: The application of which of the following standards would BE...
Question 105: Which of the following defines the key exchange for Internet...
Question 106: What is an important characteristic of Role Based Access Con...
Question 107: Data remanence refers to which of the following?...
Question 108: A global organization wants to implement hardware tokens as ...
Question 109: A Business Continuity Plan (BCP) is based on...
Question 110: DRAG DROP During the risk assessment phase of the project th...
Question 111: Refer to the information below to answer the question. A new...
Question 112: HOTSPOT Which Web Services Security (WS-Security) specificat...
Question 113: From a security perspective, which of the following is a bes...
Question 114: When designing a networked Information System (IS) where the...
Question 115: Which of the following provides effective management assuran...
Question 116: Which of the following activities BEST identifies operationa...
Question 117: Which of the following is TRUE about Disaster Recovery Plan ...
Question 118: Which of the following is the BEST method to assess the effe...
Question 119: A system is developed so that its business users can perform...
Question 120: If compromised, which of the following would lead to the exp...
Question 121: What is a common challenge when implementing Security Assert...
Question 122: What physical characteristic does a retinal scan biometric d...
Question 123: Without proper signal protection, embedded systems may be pr...
Question 124: The key benefits of a signed and encrypted e-mail include...
Question 125: Which of the following secure startup mechanisms are PRIMARI...
Question 126: Which of the following methods provides the MOST protection ...
Question 127: The implementation of which features of an identity manageme...
Question 128: In the Open System Interconnection (OSI) model, which layer ...
Question 129: At a MINIMUM, a formal review of any Disaster Recovery Plan ...
Question 130: After acquiring the latest security updates, what must be do...
Question 131: Host-Based Intrusion Protection (HIPS) systems are often dep...
Question 132: Which one of the following security mechanisms provides the ...
Question 133: Which one of the following affects the classification of dat...
Question 134: Which of the following is the BEST approach to take in order...
Question 135: Which security approach will BEST minimize Personally Identi...
Question 136: Which of the following statements is TRUE regarding value bo...
Question 137: A disadvantage of an application filtering firewall is that ...
Question 138: Which of the following is a MAJOR consideration in implement...
Question 139: DRAG DROP Given the various means to protect physical and lo...
Question 140: Which one of the following effectively obscures network addr...
Question 141: The three PRIMARY requirements for a penetration test are...
Question 142: Which of the following BEST avoids data remanence disclosure...
Question 143: What is the PRIMARY reason for ethics awareness and related ...
Question 144: While impersonating an Information Security Officer (ISO), a...
Question 145: Which of the following is the PRIMARY issue when collecting ...
Question 146: An external attacker has compromised an organization's netwo...
Question 147: What type of test assesses a Disaster Recovery (DR) plan usi...
Question 148: As one component of a physical security system, an Electroni...
Question 149: Which of the following protocols would allow an organization...
Question 150: Which of the following is the MOST beneficial to review when...
Question 151: Single Sign-On (SSO) is PRIMARILY designed to address which ...
Question 152: Refer to the information below to answer the question. A lar...
Question 153: During the procurement of a new information system, it was d...
Question 154: Refer to the information below to answer the question. A lar...
Question 155: When is security personnel involvement in the Systems Develo...
Question 156: Software Code signing is used as a method of verifying what ...
Question 157: What is the PRIMARY difference between security policies and...
Question 158: Checking routing information on e-mail to determine it is in...
Question 159: Refer to the information below to answer the question. An or...
Question 160: Which of the following standards/guidelines requires an Info...
Question 161: An internal Service Level Agreement (SLA) covering security ...
Question 162: Which of the following is the BIGGEST weakness when using na...
Question 163: Which of the following is a potential risk when a program ru...
Question 164: What is the MOST important purpose of testing the Disaster R...
Question 165: Which of the following MUST be done when promoting a securit...
Question 166: Contingency plan exercises are intended to do which of the f...
Question 167: Which of the following is a method used to prevent Structure...
Question 168: Refer to the information below to answer the question. An or...
Question 169: Refer to the information below to answer the question. Durin...
Question 170: A business has implemented Payment Card Industry Data Securi...
Question 171: Which of the following is most helpful in applying the princ...
Question 172: An organization is selecting a service provider to assist in...
Question 173: While inventorying storage equipment, it is found that there...
Question 174: Regarding asset security and appropriate retention, which of...
Question 175: Which of the following types of security testing is the MOST...
Question 176: Refer to the information below to answer the question. An or...
Question 177: Which of the following entities is ultimately accountable fo...
Question 178: Refer to the information below to answer the question. A sec...
Question 179: Which of the following assessment metrics is BEST used to un...
Question 180: DRAG DROP Place the following information classification ste...
Question 181: After a thorough analysis, it was discovered that a perpetra...
Question 182: Which one of the following is a common risk with network con...
Question 183: When designing a vulnerability test, which one of the follow...
Question 184: The stringency of an Information Technology (IT) security as...
Question 185: Which item below is a federated identity standard?...
Question 186: An organization allows ping traffic into and out of their ne...
Question 187: Which of the following BEST describes the purpose of perform...
Question 188: The MAIN reason an organization conducts a security authoriz...
Question 189: Refer to the information below to answer the question. A sec...
Question 190: When transmitting information over public networks, the deci...
Question 191: Which of the following is the BEST solution to provide redun...
Question 192: For a service provider, which of the following MOST effectiv...
Question 193: Which of the following is an essential step before performin...
Question 194: When constructing an Information Protection Policy (IPP), it...
Question 195: An advantage of link encryption in a communications network ...
Question 196: Which of the following problems is not addressed by using OA...
Question 197: The 802.1x standard provides a framework for what?...
Question 198: What maintenance activity is responsible for defining, imple...
Question 199: During a fingerprint verification process, which of the foll...
Question 200: A security professional is asked to provide a solution that ...
Question 201: To protect auditable information, which of the following MUS...
Question 202: What is the MOST effective method of testing custom applicat...
Question 203: Which of the following is an appropriate source for test dat...
Question 204: To prevent inadvertent disclosure of restricted information,...
Question 205: Refer to the information below to answer the question. In a ...
Question 206: Refer to the information below to answer the question. Deskt...
Question 207: Which of the following is the BEST way to determine if a par...
Question 208: A risk assessment report recommends upgrading all perimeter ...
Question 209: The PRIMARY characteristic of a Distributed Denial of Servic...
Question 210: Sensitive customer data is going to be added to a database. ...
Question 211: In order for a security policy to be effective within an org...
Question 212: Which of the following is the BEST mitigation from phishing ...
Question 213: For an organization considering two-factor authentication fo...
Question 214: What is the PRIMARY advantage of using automated application...
Question 215: Which of the following is the BEST countermeasure to brute f...
Question 216: Why is a system's criticality classification important in la...
Question 217: Which of the following controls is the FIRST step in protect...
Question 218: Which of the following is an effective method for avoiding m...
Question 219: Internet Protocol (IP) source address spoofing is used to de...
Question 220: Why must all users be positively identified prior to using m...
Question 221: Which of the following Disaster Recovery (DR) sites is the M...
Question 222: Which of the following questions can be answered using user ...
Question 223: In a basic SYN flood attack, what is the attacker attempting...
Question 224: Which of the following is the PRIMARY security concern assoc...
Question 225: Which of the following could elicit a Denial of Service (DoS...
Question 226: Refer to the information below to answer the question. A sec...
Question 227: DRAG DROP Order the below steps to create an effective vulne...
Question 228: Which of the following assures that rules are followed in an...
Question 229: When in the Software Development Life Cycle (SDLC) MUST soft...
Question 230: Which of the following describes the concept of a Single Sig...
Question 231: When building a data center, site location and construction ...
Question 232: Which one of the following is a threat related to the use of...
Question 233: The type of authorized interactions a subject can have with ...
Question 234: The amount of data that will be collected during an audit is...
Question 235: Which of the following statements is TRUE of black box testi...
Question 236: The PRIMARY security concern for handheld devices is the...
Question 237: Which of the following is the MAIN reason that system re-cer...
Question 238: Which of the following has the GREATEST impact on an organiz...
Question 239: Which of the following is the MOST important consideration w...
Question 240: Which of the following methods can be used to achieve confid...
Question 241: Refer to the information below to answer the question. In a ...
Question 242: An engineer in a software company has created a virus creati...
1 commentQuestion 243: Following the completion of a network security assessment, w...
Question 244: What is the term commonly used to refer to a technique of au...
Question 245: How does Encapsulating Security Payload (ESP) in transport m...
Question 246: A large bank deploys hardware tokens to all customers that u...
Question 247: What is the FIRST step in developing a security test and its...
Question 248: What is the process called when impact values are assigned t...
Question 249: Which of the following explains why record destruction requi...
Question 250: Which of the following command line tools can be used in the...
Question 251: Which of the following is a detective access control mechani...
Question 252: Refer to the information below to answer the question. A lar...
Question 253: A practice that permits the owner of a data object to grant ...
Question 254: A software scanner identifies a region within a binary image...
Question 255: What component of a web application that stores the session ...
Question 256: Which of the following BEST represents the principle of open...
Question 257: An organization has hired a security services firm to conduc...
Question 258: DRAG DROP Place in order, from BEST (1) to WORST (4), the fo...
Question 259: The FIRST step in building a firewall is to...
Question 260: A security manager has noticed an inconsistent application o...
Question 261: An organization is designing a large enterprise-wide documen...
Question 262: Which one of the following describes granularity?...
Question 263: Refer to the information below to answer the question. An or...
Question 264: Are companies legally required to report all data breaches?...
Question 265: Which of the following is an authentication protocol in whic...
Question 266: When using third-party software developers, which of the fol...
Question 267: Which of the following BEST describes a Protection Profile (...
Question 268: An Intrusion Detection System (IDS) is generating alarms tha...
Question 269: Which of the following is the best practice for testing a Bu...
Question 270: A thorough review of an organization's audit logs finds that...
Question 271: A system has been scanned for vulnerabilities and has been f...
Question 272: The PRIMARY outcome of a certification process is that it pr...
Question 273: In a financial institution, who has the responsibility for a...
Question 274: Copyright provides protection for which of the following?...
Question 275: Which of the following is the MOST important output from a m...
Question 276: Which of the following BEST mitigates a replay attack agains...
Question 277: Disaster Recovery Plan (DRP) training material should be...
Question 278: Who must approve modifications to an organization's producti...
Question 279: Refer to the information below to answer the question. A lar...
Question 280: In the area of disaster planning and recovery, what strategy...
Question 281: Discretionary Access Control (DAC) restricts access accordin...
Question 282: What is the PRIMARY goal for using Domain Name System Securi...
Question 283: Which of the following is an example of two-factor authentic...
Question 284: Why MUST a Kerberos server be well protected from unauthoriz...
Question 285: Which of the following is a BEST practice when traveling int...
Question 286: Which of the following actions should be performed when impl...
Question 287: Which one of the following transmission media is MOST effect...
Question 288: Which of the following BEST describes a rogue Access Point (...
Question 289: What do Capability Maturity Models (CMM) serve as a benchmar...
Question 290: When planning a penetration test, the tester will be MOST in...
Question 291: According to best practice, which of the following groups is...
Question 292: Multi-threaded applications are more at risk than single-thr...
Question 293: Refer to the information below to answer the question. A lar...
Question 294: Which of the following elements MUST a compliant EU-US Safe ...
Question 295: Which methodology is recommended for penetration testing to ...
Question 296: In Business Continuity Planning (BCP), what is the importanc...
Question 297: What is the MOST critical factor to achieve the goals of a s...
Question 298: What is the ultimate objective of information classification...
Question 299: A large university needs to enable student access to univers...
Question 300: Refer to the information below to answer the question. An or...
Question 301: Which of the following is a recommended alternative to an in...
Question 302: Which of the following is the PRIMARY benefit of implementin...
Question 303: Data leakage of sensitive information is MOST often conceale...
Question 304: An organization is found lacking the ability to properly est...
Question 305: Which of the following is the FIRST step of a penetration te...
Question 306: An organization's data policy MUST include a data retention ...
Question 307: Which of the following actions MUST be taken if a vulnerabil...
Question 308: Which of the following provides the MOST protection against ...
Question 309: While investigating a malicious event, only six days of audi...
Question 310: Which of the following BEST describes Recovery Time Objectiv...
Question 311: Which of the following is the FIRST action that a system adm...
Question 312: A vulnerability test on an Information System (IS) is conduc...
Question 313: Which of the following are Systems Engineering Life Cycle (S...
Question 314: The BEST example of the concept of "something that a user ha...
Question 315: During an audit of system management, auditors find that the...
Question 316: Which of the following is an essential element of a privileg...
Question 317: Which of the following is the MOST important element of chan...
Question 318: Which of the following methods protects Personally Identifia...
Question 319: Two companies wish to share electronic inventory and purchas...
Question 320: During an audit, the auditor finds evidence of potentially i...
Question 321: When dealing with compliance with the Payment Card Industry-...
Question 322: Multi-Factor Authentication (MFA) is necessary in many syste...
Question 323: Which of the following is the PRIMARY benefit of a formalize...
Question 324: HOTSPOT Which Web Services Security (WS-Security) specificat...
Question 325: Including a Trusted Platform Module (TPM) in the design of a...
Question 326: Which of the following is the BEST reason to review audit lo...
Question 327: An online retail company has formulated a record retention s...
Question 328: Which of the following does the Encapsulating Security Paylo...
Question 329: Application of which of the following Institute of Electrica...
Question 330: An organization has developed a major application that has u...
Question 331: Refer to the information below to answer the question. An or...
Question 332: Which of the following is a function of Security Assertion M...
Question 333: Refer to the information below to answer the question. Durin...
Question 334: Which of the following BEST describes the purpose of the sec...
Question 335: Which of the following roles has the obligation to ensure th...
Question 336: During an investigation of database theft from an organizati...
Question 337: Which of the following is a strategy of grouping requirement...
Question 338: How can a forensic specialist exclude from examination a lar...
Question 339: Which of the following does Temporal Key Integrity Protocol ...
Question 340: Refer to the information below to answer the question. A sec...
Question 341: In a data classification scheme, the data is owned by the...
Question 342: Logical access control programs are MOST effective when they...
Question 343: Which of the following MUST system and database administrato...
Question 344: A security professional has just completed their organizatio...
Question 345: Which of the following is a process within a Systems Enginee...
Question 346: The birthday attack is MOST effective against which one of t...
Question 347: Which layer of the Open Systems Interconnections (OSI) model...
Question 348: Which of the following wraps the decryption key of a full di...
Question 349: During the risk assessment phase of the project the CISO dis...
Question 350: Passive Infrared Sensors (PIR) used in a non-climate control...
Question 351: Which of the following statements is TRUE for point-to-point...
Question 352: What is the MOST effective countermeasure to a malicious cod...
Question 353: Which security action should be taken FIRST when computer pe...
Question 354: Which of the following is a network intrusion detection tech...
Question 355: HOTSPOT Identify the component that MOST likely lacks digita...
Question 356: Which of the following is an advantage of on-premise Credent...
Question 357: DRAG DROP In which order, from MOST to LEAST impacted, does ...
Question 358: Refer to the information below to answer the question. A new...
Question 359: Which of the following is required to determine classificati...
Question 360: The overall goal of a penetration test is to determine a sys...
Question 361: Which of the following is the BEST way to verify the integri...
Question 362: What principle requires that changes to the plaintext affect...
Question 363: Which of the following is a reason to use manual patch insta...
Question 364: When implementing controls in a heterogeneous end-point netw...
Question 365: Changes to a Trusted Computing Base (TCB) system that could ...
Question 366: Refer to the information below to answer the question. In a ...
Question 367: Refer to the information below to answer the question. A lar...
Question 368: The BEST method to mitigate the risk of a dictionary attack ...
Question 369: An organization lacks a data retention policy. Of the follow...
Question 370: When implementing a secure wireless network, which of the fo...
Question 371: What should happen when an emergency change to a system must...
Question 372: What does an organization FIRST review to assure compliance ...
Question 373: How can lessons learned from business continuity training an...