A recent security audit is reporting several unsuccessful login attempts being repeated at specific times during the day on an Internet facing authentication server. No alerts have been generated by the security information and event management (SIEM) system. What PRIMARY action should be taken to improve SIEM performance?
employee training, risk management, and data handling procedures and policies could be characterized as which type of security measure?
What is the FIRST step in developing a security test and its evaluation?
In the area of disaster planning and recovery, what strategy entails the presentation of information about the plan?
Which of the following could cause a Denial of Service (DoS) against an authentication system?
An organization recently conducted a review of the security of its network applications. One of the
vulnerabilities found was that the session key used in encrypting sensitive information to a third party server had been hard-coded in the client and server applications. Which of the following would be MOST effective in mitigating this vulnerability?
In an organization where Network Access Control (NAC) has been deployed, a device trying to connect to the network is being placed into an isolated domain. What could be done on this device in order to obtain proper
connectivity?
Which of the following operates at the Network Layer of the Open System Interconnection (OSI) model?
Which one of the following documentation should be included in a Disaster Recovery (DR) package?
Which of the fallowing statements is MOST accurate regarding information assets?
Which of the following processes has the PRIMARY purpose of identifying outdated software versions, missing patches, and lapsed system updates?
Which of the following needs to be taken into account when assessing vulnerability?
Which of the following objects should be removed FIRST prior to uploading code to public code repositories?
A cloud hosting provider would like to provide a Service Organization Control (SOC) report relevant to its security program. This report should an abbreviated report that can be freely distributed. Which type of report BEST meets this requirement?
In the last 15 years a company has experienced three electrical failures. The cost associated with each failure is listed below.
Which of the following would be a reasonable annual loss expectation?
