Valid CISSP Dumps shared by EduDump.com for Helping Passing CISSP Exam! EduDump.com now offer the newest CISSP exam dumps, the EduDump.com CISSP exam questions have been updated and answers have been corrected get the newest EduDump.com CISSP dumps with Test Engine here:
An organization discovers that its Secure File Transfer Protocol (SFTP) server has been accessed by an unauthorized person to download an unreleased game. A recent security audit found weaknesses in some of the organization's general Information Technology (IT) controls, superficially pertaining t software change control and security patch management, but rot in other control areas. Which of the following is the MOST probable attack vector used in the security breach?
Correct Answer: D
SFTP Server Access via Credentials - SFTP (SSH File Transfer Protocol) typically requires authentication (username/password or SSH keys). Weak IT Controls Mentioned - The audit found issues in: Software change control (could imply poor credential management). Security patch management (but no evidence of unpatched exploits being used). Unauthorized Access Suggests Credential Compromise - If passwords were weak or reused, brute-forcing or credential stuffing could have allowed access.