WorksheetsASYC DOM2.2 XEBYS
Total questions: 151
Worksheet time: 1hrs 16mins
Raphael discovered during a vulnerability scan that an administrative interface to one of his
storage systems was inadvertently exposed to the Internet. He is reviewing firewall logs and
would like to determine whether any access attempts came from external sources. Which
one of the following IP addresses reflects an external source?
10.15.1.100
12.8.1.100
172.16.1.100
192.168.1.100
Nick is configuring vulnerability scans for his network using a third-party
vulnerability scanning service. He is attempting to scan a web server that he knows exposes a CIFS file
share and contains several significant vulnerabilities. However, the scan results only show
ports 80 and 443 as open. What is the most likely cause of these scan results?
The CIFS file share is running on port 443.
A firewall configuration is preventing the scan from succeeding.
The scanner configuration is preventing the scan from succeeding.
The CIFS file share is running on port 80.
Thomas learned this morning of a critical security flaw that affects a major service used by
his organization and requires immediate patching. This flaw was the subject of news reports
and is being actively exploited. Thomas has a patch and informed stakeholders of the issue
and received permission to apply the patch during business hours. How should he handle
the change management process?
Thomas should apply the patch and then follow up with an emergency change request
after work is complete.
Thomas should initiate a standard change request but apply the patch before waiting
for approval.
Thomas should work through the standard change approval process and wait until it
is complete to apply the patch.
Thomas should file an emergency change request and wait until it is approved to apply
the patch.
After running a vulnerability scan of systems in his organization’s development shop,
Mike discovers the issue shown here on several systems. What is the best solution to this
vulnerability?
Apply the required security patches to this framework.
Remove this framework from the affected systems.
Upgrade the operating system of the affected systems.
No action is necessary.
Tran is preparing to conduct vulnerability scans against a set of workstations in his organization.
He is particularly concerned about system configuration settings. Which one of the
following scan types will give him the best results?
Unauthenticated scan
Credentialed scan
External scan
Internal scan
Brian is configuring a vulnerability scan of all servers in his organization’s datacenter. He
is configuring the scan to detect only the highest-severity
vulnerabilities. He would like to
empower system administrators to correct issues on their servers but also have some insight
into the status of those remediations. Which approach would best serve Brian’s interests?
Give the administrators access to view the scans in the vulnerability scanning system.
Send email alerts to administrators when the scans detect a new vulnerability on their
servers.
Configure the vulnerability scanner to open a trouble ticket when they detect a new
vulnerability on a server.
Configure the scanner to send reports to Brian who can notify administrators and
track them in a spreadsheet.
Xiu Ying is configuring a new vulnerability scanner for use in her organization’s datacenter.
Which one of the following values is considered a best practice for the scanner’s update
frequency?
Daily
Weekly
Monthly
Quarterly
Ben’s manager recently assigned him to begin the remediation work on the most vulnerable
server in his organization. A portion of the scan report appears here. What remediation
action should Ben take first?
Install patches for Adobe Flash.
Install patches for Firefox.
Run Windows Update.
Remove obsolete software.
Zhang Wei completed a vulnerability scan of his organization’s virtualization platform from
an external host and discovered the vulnerability shown here. How should he react?
This is a critical issue that requires immediate adjustment of firewall rules.
This issue has a very low severity and does not require remediation.
This issue should be corrected as time permits.
This is a critical issue, and Zhang Wei should shut down the platform until it is
corrected.
Elliott runs a vulnerability scan of one of the servers belonging to his organization and finds
the results shown here. Which one of these statements is not correct?
This server requires one or more Linux patches.
This server requires one or more Oracle database patches.
This server requires one or more Firefox patches.
This server requires one or more MySQL patches.
Tom runs a vulnerability scan of the file server shown here.
Block RDP access to this server from all hosts.
Review and secure server accounts.
Upgrade encryption on the server.
No action is required.
Dave is running a vulnerability scan of a client’s network for the first time. The client has
never run such a scan and expects to find many results. What security control is likely to
remediate the largest portion of the vulnerabilities discovered in Dave’s scan?
Input validation
Patching
Intrusion prevention systems
Encryption
Kai is planning to patch a production system to correct a vulnerability detected during a
scan. What process should she follow to correct the vulnerability but minimize the risk of a
system failure?
Kai should deploy the patch immediately on the production system.
Kai should wait 60 days to deploy the patch to determine whether bugs are reported.
Kai should deploy the patch in a sandbox environment to test it prior to applying it in
production.
Kai should contact the vendor to determine a safe timeframe for deploying the patch in
production.
Given no other information, which one of the following vulnerabilities would you consider
the greatest threat to information confidentiality?
HTTP TRACE/TRACK methods enabled
SSL Server with SSL v3 enabled vulnerability
phpinfo information disclosure vulnerability
Web application SQL injection vulnerability
Ling recently completed the security analysis of a web browser deployed on systems
in her organization and discovered that it is susceptible to a zero-day
integer overflow
attack. Who is in the best position to remediate this vulnerability in a manner that allows
continued use of the browser?
Ling
The browser developer
The network administrator
The domain administrator
Jeff’s team is preparing to deploy a new database service, and he runs a vulnerability scan
of the test environment. This scan results in the four vulnerability reports shown here. Jeff is
primarily concerned with correcting issues that may lead to a confidentiality breach. Which
vulnerability should Jeff remediate first?
Rational ClearCase Portscan Denial of Service vulnerability
Non-Zero
Padding Bytes Observed in Ethernet Packets
Oracle Database TNS Listener Poison Attack vulnerability
Hidden RPC Services
Eric is a security consultant and is trying to sell his services to a new client. He would like
to run a vulnerability scan of their network prior to their initial meeting to show the client
the need for added security. What is the most significant problem with this approach?
Eric does not know the client’s infrastructure design.
Eric does not have permission to perform the scan.
Eric does not know what operating systems and applications are in use.
Eric does not know the IP range of the client’s systems.
Renee is assessing the exposure of her organization to the denial-of-
service vulnerability in the scan report shown here. She is specifically interested in determining whether an external attacker would be able to exploit the denial-of-service vulnerability. Which one of the following
sources of information would provide her with the best information to complete this assessment?
Server logs
Firewall rules
IDS configuration
DLP configuration
Mary is trying to determine what systems in her organization should be subject to vulnerability
scanning. She would like to base this decision on the criticality of the system to
business operations. Where should Mary turn to best find this information?
The CEO
System names
IP addresses
Asset inventory
Paul ran a vulnerability scan of his vulnerability scanner and received the result shown here.
What is the simplest fix to this issue?
Upgrade Nessus.
Remove guest accounts.
Implement TLS encryption.
Renew the server certificate.
Kamea is designing a vulnerability management system for her organization. Her highest
priority is conserving network bandwidth. She does not have the ability to alter the configuration
or applications installed on target systems. What solution would work best in
Kamea’s environment to provide vulnerability reports?
Agent-based
scanning
Server-based
scanning
Passive network monitoring
Port scanning
Aki is conducting a vulnerability scan when he receives a report that the scan is slowing
down the network for other users. He looks at the performance configuration settings
shown here. Which setting would be most likely to correct the issue?
Enable safe checks.
Stop scanning hosts that become unresponsive during the scan.
Scan IP addresses in random order.
Max simultaneous hosts per scan.
Laura received a vendor security bulletin that describes a zero-day
vulnerability in her organization’s main database server. This server is on a private network but is used by publicly accessible web applications. The vulnerability allows the decryption of administrative
connections to the server. What reasonable action can Laura take to address this issue as
quickly as possible?
Apply a vendor patch that resolves the issue.
Disable all administrative access to the database server.
Require VPN access for remote connections to the database server.
Verify that the web applications use strong encryption.
Emily discovered the vulnerability shown here on a server running in her organization.
What is the most likely underlying cause for this vulnerability?
Failure to perform input validation
Failure to use strong passwords
Failure to encrypt communications
Failure to install antimalware software
Rex recently ran a vulnerability scan of his organization’s network and received the results
shown here. He would like to remediate the server with the highest number of the most
serious vulnerabilities first. Which one of the following servers should be on his highest priority list?
10.0.102.58
10.0.16.58
10.0.46.116
10.0.69.232
Abella is configuring a vulnerability scanning tool. She recently learned about a privilege
escalation vulnerability that requires the user already have local access to the system. She
would like to ensure that her scanners are able to detect this vulnerability as well as future
similar vulnerabilities. What action can she take that would best improve the scanner’s
ability to detect this type of issue?
Enable credentialed scanning.
Run a manual vulnerability feed update.
Increase scanning frequency.
Change the organization’s risk appetite.
Kylie reviewed the vulnerability scan report for a web server and found that it has multiple
SQL injection and cross-site scripting vulnerabilities. What would be the least difficult way
for Kylie to address these issues?
Install a web application firewall.
Recode the web application to include input validation.
Apply security patches to the server operating system.
Apply security patches to the web server service.
Karen ran a vulnerability scan of a web server used on her organization’s internal network.
She received the report shown here. What circumstances would lead Karen to dismiss this
vulnerability as a false positive?
The server is running SSL v2.
The server is running SSL v3.
The server is for internal use only.
The server does not contain sensitive information.
Which one of the following vulnerabilities is the most difficult to confirm with an external
vulnerability scan?
Cross-site
scripting
Cross-site
request forgery
Blind SQL injection
Unpatched web server
Holly ran a scan of a server in her datacenter, and the most serious result was the vulnerability
shown here. What action is most commonly taken to remediate this vulnerability?
Remove the file from the server.
Edit the file to limit information disclosure.
Password protect the file.
Limit file access to a specific IP range.
During a recent vulnerability scan, Mark discovered a flaw in an internal web application
that allows cross-site scripting attacks. He spoke with the manager of the team responsible
for that application and was informed that he discovered a known vulnerability and the
manager worked with other leaders and determined that the risk is acceptable and does not
require remediation. What should Mark do?
Object to the manager’s approach and insist on remediation.
Mark the vulnerability as a false positive.
Schedule the vulnerability for remediation in six months.
Mark the vulnerability as an exception.
Jacquelyn recently read about a new vulnerability in Apache web servers that allows
attackers to execute arbitrary code from a remote location. She verified that her servers
have this vulnerability, but this morning’s OpenVAS vulnerability scan report shows that
the servers are secure. She contacted the vendor and determined that they have released a
signature for this vulnerability and it is working properly at other clients. What action can
Jacquelyn take that will most likely address the problem efficiently?
Add the web servers to the scan.
Reboot the vulnerability scanner.
Update the vulnerability feed.
Wait until tomorrow’s scan.
Sharon is designing a new vulnerability scanning system for her organization. She must scan
a network that contains hundreds of unmanaged hosts. Which of the following techniques
would be most effective at detecting system configuration issues in her environment?
Agent-based
scanning
Credentialed scanning
Server-based
scanning
Passive network monitoring
Arlene ran a vulnerability scan of a VPN server used by contractors and employees to gain access to her organization’s network. An external scan of the server found the vulnerability shown here.
Which one of the following hash algorithms would not trigger this vulnerability?
MD4
MD5
SHA-1
SHA-256
What is the most likely result of failing to correct this vulnerability?
All users will be able to access the site.
All users will be able to access the site, but some may see an error message.
Some users will be unable to access the site.
All users will be unable to access the site.
How can Arlene correct this vulnerability?
Reconfigure the VPN server to only use secure hash functions.
Request a new certificate.
Change the domain name of the server.
Implement an intrusion prevention system.
After reviewing the results of a vulnerability scan, Bruce discovered that many of the servers
in his organization are susceptible to a brute-force
SSH attack. He would like to determine
what external hosts attempted SSH connections to his servers and is reviewing firewall logs.
What TCP port would relevant traffic most likely use?
22
636
1433
1521
Joaquin runs a vulnerability scan of the network devices in his organization and sees the
vulnerability report shown here for one of those devices. What action should he take?
No action is necessary because this is an informational report.
Upgrade the version of the certificate.
Replace the certificate.
Verify that the correct ciphers are being used.
Lori is studying vulnerability scanning as she prepares for the CySA+ exam. Which of the
following is not one of the principles she should observe when preparing for the exam to
avoid causing issues for her organization?
Run only nondangerous scans on production systems to avoid disrupting a production
service.
Run scans in a quiet manner without alerting other IT staff to the scans or their results
to minimize the impact of false information.
Limit the bandwidth consumed by scans to avoid overwhelming an active network
link.
Run scans outside of periods of critical activity to avoid disrupting the business.
Meredith is configuring a vulnerability scan and would like to configure the scanner to perform
credentialed scans. Of the menu options shown here, which will allow her to directly
configure this capability?
Manage Discovery Scans
Configure Scan Settings
Configure Search Lists
Set Up Host Authentication
Norman is working with his manager to implement a vulnerability management program
for his company. His manager tells him that he should focus on remediating critical and
high-severity risks and that the organization does not want to spend time worrying about
risks rated medium or lower. What type of criteria is Norman’s manager using to make this
decision?
Risk appetite
False positive
False negative
Data classification
Sara’s organization has a well-managed
test environment. What is the most likely issue that
Sara will face when attempting to evaluate the impact of a vulnerability remediation by first
deploying it in the test environment?
Test systems are not available for all production systems.
Production systems require a different type of patch than test systems.
Significant configuration differences exist between test and production systems.
Test systems are running different operating systems than production systems.
How many vulnerabilities listed in the report shown here are significant enough to warrant
immediate remediation in a typical operating environment?
22
14
5
0
Which one of the following types of data is subject to regulations in the United States that
specify the minimum frequency of vulnerability scanning?
Driver’s license numbers
Insurance records
Credit card data
Medical records
Chang is responsible for managing his organization’s vulnerability scanning program. He
is experiencing issues with scans aborting because the previous day’s scans are still running
when the scanner attempts to start the current day’s scans. Which one of the following solutions
is least likely to resolve Chang’s issue?
Add a new scanner.
Reduce the scope of the scans.
Reduce the sensitivity of the scans.
Reduce the frequency of the scans.
Bhanu is scheduling vulnerability scans for her organization’s datacenter. Which one of the
following is a best practice that Bhanu should follow when scheduling scans?
Schedule scans so that they are spread evenly throughout the day.
Schedule scans so that they run during periods of low activity.
Schedule scans so that they all begin at the same time.
Schedule scans so that they run during periods of peak activity to simulate
performance under load.
Alan recently reviewed a vulnerability report and determined that an insecure direct object
reference vulnerability existed on the system. He implemented a remediation to correct the
vulnerability. After doing so, he verifies that his actions correctly mitigated the vulnerability.
What term best describes the initial vulnerability report?
True positive
True negative
False positive
False negative
Gwen is reviewing a vulnerability report and discovers that an internal system contains a
serious flaw. After reviewing the issue with her manager, they decide that the system is sufficiently
isolated and they will take no further action. What risk management strategy are
they adopting?
Risk avoidance
Risk mitigation
Risk transference
Risk acceptance
Mike is in charge of the software testing process for his company. They perform a complete
set of tests for each product throughout its life span. Use your knowledge of software
assessment methods to answer the following questions.
A new web application has been written by the development team in Mike’s company. They
used an Agile process and built a tool that fits all of the user stories that the participants
from the division that asked for the application outlined. If they want to ensure that the
functionality is appropriate for all users in the division, what type of testing should Mike
perform?
Stress testing
Regression testing
Static testing
User acceptance testing
Mike is in charge of the software testing process for his company. They perform a complete
set of tests for each product throughout its life span. Use your knowledge of software
assessment methods to answer the following questions.
Mike’s development team wants to expand the use of the software to the whole company,
but they are concerned about its performance. What type of testing should they conduct to
ensure that the software will not fail under load?
Stress testing
Regression testing
Static testing
User acceptance testing
Mike is in charge of the software testing process for his company. They perform a complete
set of tests for each product throughout its life span. Use your knowledge of software
assessment methods to answer the following questions.
Two years after deployment, Mike’s team is ready to roll out a major upgrade to their web
application. They have pulled code from the repository that it was checked into but are
worried that old bugs may have been reintroduced because they restored additional functionality
based on older code that had been removed in a release a year ago. What type of
testing does Mike’s team need to perform?
Stress testing
Regression testing
Static testing
User acceptance testing
Padma is evaluating the security of an application developed within her organization. She
would like to assess the application’s security by supplying it with invalid inputs. What
technique is Padma planning to use?
Fault injection
Stress testing
Mutation testing
Fuzz testing
Which software development life cycle model is illustrated in the image?
Waterfall
Spiral
Agile
RAD
The Open Worldwide Application Security Project (OWASP) maintains an application
called Orizon. This application reviews Java classes and identifies potential security flaws.
What type of tool is Orizon?
Fuzzer
Static code analyzer
Web application assessor
Fault injector
Barney’s organization mandates fuzz testing for all applications before deploying them
into production. Which one of the following issues is this testing methodology most likely
to detect?
Incorrect firewall rules
Unvalidated input
Missing operating system patches
Unencrypted data transmission
Mia would like to ensure that her organization’s cybersecurity team reviews the architecture
of a new ERP application that is under development. During which SDLC phase should
Mia expect the security architecture to be completed?
Analysis and Requirements Definition
Design
Development
Testing and Integration
Which one of the following security activities is not normally a component of the Operations
and Maintenance phase of the SDLC?
Vulnerability scans
Disposition
Patching
Regression testing
Olivia has been put in charge of performing code reviews for her organization and needs
to determine which code analysis models make the most sense based on specific needs her
organization has. Use your knowledge of code analysis techniques to answer the following
questions.
Olivia’s security team has identified potential malicious code that has been uploaded to
a webserver. If she wants to review the code without running it, what technique should
she use?
Dynamic analysis
Fagan analysis
Regression analysis
Static analysis
Olivia’s next task is to test the code for a new mobile application. She needs to test it by
executing the code and intends to provide the application with input based on testing scenarios
created by the development team as part of their design work. What type of testing
will Olivia conduct?
Dynamic analysis
Fagan analysis
Regression analysis
Static analysis
After completing the first round of tests for her organization’s mobile application, Olivia
has discovered indications that the application may not handle unexpected data well. What
type of testing should she conduct if she wants to test it using an automated tool that will
check for this issue?
Fault injection
Fagan testing
Fuzzing
Failure injection
Which one of the following characters would not signal a potential security issue during the
validation of user input to a web application?
<
'
>
$
The Open Worldwide Application Security Project (OWASP) maintains a listing of the most
important web application security controls. Which one of these items is least likely to
appear on that list?
Implement identity and authentication controls.
Implement appropriate access controls.
Obscure web interface locations.
Leverage security frameworks and libraries.
Kyle is developing a web application that uses a database back end. He is concerned about
the possibility of an SQL injection attack against his application and is consulting the
OWASP proactive security controls list to identify appropriate controls. Which one of the
following OWASP controls is least likely to prevent a SQL injection attack?
Parameterize queries.
Validate all input.
Encode data.
Implement logging and intrusion detection.
Jill’s organization has adopted an asset management tool. If she wants to identify systems
on the network based on a unique identifier per machine that will not normally change over
time, which of the following options can she use for network-based
discovery?
IP address
Hostname
MAC address
None of the above
Which software development methodology is illustrated in the diagram?
Spiral
RAD
Agile
Waterfall
Claire knows that a web application that her organization needs to have in production has
vulnerabilities due to a recent scan using a web application security scanner. What is her
best protection option if she knows that the vulnerability is a known SQL injection flaw?
A firewall
An IDS
A WAF
DLP
Donna has been assigned as the security lead for a DevSecOps team building a new web
application. As part of the effort, she has to oversee the security practices that the team will
use to protect the application. Use your knowledge of secure coding practices to help Donna
guide her team through this process.
A member of Donna’s team recommends building a blocklist to avoid dangerous characters
like ' and <script> tags. How could attackers bypass a blocklist that individually identified
those characters?
They can use a binary attack.
They can use alternate encodings.
They can use different characters with the same meaning.
The characters could be used together to avoid the blocklist.
Donna has been assigned as the security lead for a DevSecOps team building a new web
application. As part of the effort, she has to oversee the security practices that the team will
use to protect the application. Use your knowledge of secure coding practices to help Donna
guide her team through this process.
The design of the application calls for client-side
validation of input. What type of tool
could an attacker use to bypass this?
An XSS injector
A web proxy
A JSON interpreter
A SQL injector
Donna has been assigned as the security lead for a DevSecOps team building a new web
application. As part of the effort, she has to oversee the security practices that the team will
use to protect the application. Use your knowledge of secure coding practices to help Donna
guide her team through this process.
A member of Donna’s security team suggests that output encoding should also be considered.
What type of attack is the team member most likely attempting to prevent?
Cross-site
scripting
SQL injection
Cross-site
request forgery
All of the above
Nathan downloads a BIOS/UEFI update from Dell’s website, and when he attempts to
install it on the PC, he receives an error that the hash of the download does not match the
hash stored on Dell’s servers. What type of protection is this?
Full-disk
encryption
Firmware protection
Operating system protection
None of the above
What practice is typical in a DevSecOps organization as part of a CI/CD pipeline?
Automating some security gates
Programmatic implementation of zero-day
vulnerabilities
Using security practitioners to control the flow of the CI/CD pipeline
Removing security features from the IDE
Valerie wants to prevent potential cross-site
scripting attacks from being executed when
previously entered information is displayed in user’s browsers. What technique should she
use to prevent this?
A firewall
A HIDS
Output encoding
String randomization
While developing a web application, Chris sets his session ID length to 128 bits based on
OWASP’s recommended session management standards. What reason would he have for
needing such a long session ID?
To avoid duplication
To allow for a large group of users
To prevent brute-forcing
All of the above
Robert is reviewing a web application, and the developers have offered four different
responses to incorrect logins. Which of the following four responses is the most
secure option?
Login failed for user; invalid password
Login failed; invalid user ID or password
Login failed; invalid user ID
Login failed; account does not exist
Nathan is reviewing PHP code for his organization and finds the following code in the
application he is assessing. What technique is the developer using?
Dynamic binding
Parameterized queries
Variable limitation
None of the above
Christina wants to check the firmware she has been provided to ensure that it is the same
firmware that the manufacturer provides. What process should she follow to validate that
the firmware is trusted firmware?
Download the same file from the manufacturer and compare file size.
Compare a hash of the file to a hash provided by the manufacturer.
Run strings against the firmware to find any evidence of tempering.
Submit the firmware to a malware scanning site to verify that it does not contain
malware.
What type of attack is the use of query parameterization intended to prevent?
Buffer overflows
Cross-site
scripting
SQL injection
Denial-of-
service
attacks
What type of attack is output encoding typically used against?
DoS
XSS
XML
DDoS
Scott has been asked to select a software development model for his organization and knows
that there are a number of models that may make sense for what he has been asked to
accomplish. Use your knowledge of SDLC models to identify an appropriate model for each
of the following requirements.
Scott’s organization needs basic functionality of the effort to become available as soon as
possible and wants to involve the teams that will use it heavily to ensure that their needs are
met. What model should Scott recommend?
Waterfall
Spiral
Agile
Rapid Application Development
Scott has been asked to select a software development model for his organization and knows
that there are a number of models that may make sense for what he has been asked to
accomplish. Use your knowledge of SDLC models to identify an appropriate model for each
of the following requirements.
A parallel coding effort needs to occur; however, this effort involves a very complex system
and errors could endanger human lives. The system involves medical records and drug
dosages, and the organization values stability and accuracy over speed. Scott knows the
organization often adds design constraints throughout the process and that the model he
selects must also deal with that need. What model should he choose?
Waterfall
Spiral
Agile
Rapid Application Development
Scott has been asked to select a software development model for his organization and knows
that there are a number of models that may make sense for what he has been asked to
accomplish. Use your knowledge of SDLC models to identify an appropriate model for each
of the following requirements.
At the end of his development cycle, what SDLC phase will Scott enter as the new application
is installed and replaces the old code?
User acceptance testing
Testing and integration
Disposition
Redesign
The OWASP Session Management Cheatsheet advises that session IDs are meaningless and
recommends that they should be used only as an identifier on the client side. Why should
a session ID not have additional information encoded in it like the IP address of the client,
their username, or other information?
Processing complex session IDs will slow down the service.
Session IDs cannot contain this information for legal reasons.
Session IDs are sent to multiple different users, which would result in a data breach.
Session IDs could be decoded, resulting in data leakage.
Bounds checking, removing special characters, and forcing strings to match a limited set of
options are all examples of what web application security technique?
SQL injection prevention
Input validation
XSS prevention
Fuzzing
Abigail is performing input validation against an input field and uses the following regular
expression:
What is she checking with the regular expression?
She is removing all typical special characters found in SQL injection.
She is checking for all U.S. state names.
She is removing all typical special characters for cross-site
scripting attacks.
She is checking for all U.S. state name abbreviations.
Jennifer uses an application to send randomized data to her application to determine how it
responds to unexpected input. What type of tool is she using?
A UAT tool
A stress testing tool
A fuzzer
A regression testing tool
Greg wants to prevent SQL injection in a web application he is responsible for. Which of
the following is not a common defense against SQL injection?
Prepared statements with parameterized queries
Output validation
Stored procedures
Escaping all user-supplied
input
While reviewing code that generates a SQL query, Aarav notices that the “address” field is
appended to the query without input validation or other techniques applied. What type of
attack is most likely to be successful against code like this?
DoS
XSS
SQL injection
Teardrop
Amanda has been assigned to lead the development of a new web application for her
organization. She is following a standard SDLC model as shown here. Use the model and
your knowledge of the software development life cycle to answer the following questions.
Amanda’s first task is to determine if there are alternative solutions that are more cost effective
than in-house development. What phase is she in?
Design
Operations and maintenance
Feasibility
Analysis and requirements definition
Amanda has been assigned to lead the development of a new web application for her
organization. She is following a standard SDLC model as shown here. Use the model and
your knowledge of the software development life cycle to answer the following questions.
What phase of the SDLC typically includes the first code analysis and unit testing in the
process?
Analysis and requirements definition
Design
Coding
Testing and integration
Amanda has been assigned to lead the development of a new web application for her
organization. She is following a standard SDLC model as shown here. Use the model and
your knowledge of the software development life cycle to answer the following questions.
After making it through most of the SDLC process, Amanda has reached point E on the
diagram. What occurs at point E?
Disposition
Training and transition
Unit testing
Testing and integration
Angela wants to prevent buffer overflow attacks on a Windows system. What two built-in
technologies should she consider?
The memory firewall and the stack guard
ASLR and DEP
ASLR and DLP
The memory firewall and the buffer guard
Amanda has been assigned to reduce the attack surface area for her organization, and she
knows that the current network design relies on allowing systems throughout her organization
to access the Internet directly via public IP addresses they are assigned. What should
her first step be to reduce her organization’s attack surface quickly and without large
amounts of time invested?
Install host firewalls on the systems.
Move to a NAT environment.
Install an IPS.
None of the above.
Matt believes that developers in his organization deployed code that did not implement
cookies in a secure way. What type of attack would be aided by this security issue?
SQL injection
A denial-of-
service
attack
Session hijacking
XSS
Chris operates the point-of-sale
(POS) network for a company that accepts credit cards and
is thus required to be compliant with PCI DSS. During his regular assessment of the POS
terminals, he discovers that a recent Windows operating system vulnerability exists on all
of them. Since they are all embedded systems that require a manufacturer update, he knows
that he cannot install the available patch. What is Chris’s best option to stay compliant with
PCI DSS and protect his vulnerable systems?
Replace the Windows embedded point-of-
sale
terminals with standard Windows
systems.
Build a custom operating system image that includes the patch.
Identify, implement, and document compensating controls.
Remove the POS terminals from the network until the vendor releases a patc
Tracy is validating the web application security controls used by her organization. She
wants to ensure that the organization is prepared to conduct forensic investigations of
future security incidents. Which one of the following OWASP control categories is most
likely to contribute to this effort?
Implement logging.
Validate all inputs.
Parameterize queries.
Error and exception handling.
While reviewing his Apache logs, Oscar discovers the following entry. What has occurred?
A successful database query
A PHP overflow attack
A SQL injection attack
An unsuccessful database query
Joan is working as a security consultant to a company that runs a critical web application.
She discovered that the application has a serious SQL injection vulnerability, but the
company cannot take the system offline during the two weeks required to revise the code.
Which one of the following technologies would serve as the best compensating control?
IPS
WAF
Vulnerability scanning
Encryption
After conducting an nmap scan of his network from outside of his network, James notes
that a large number of devices are showing three TCP ports open on public IP addresses:
9100, 515, and 631. What type of devices has he found, and how could he reduce his
organization’s attack surface?
Wireless access points, disable remote administration
Desktop workstations, enable the host firewall
Printers, move the printers to an internal-only
IP address range
Network switches, enable encrypted administration mode
Alex is working to understand his organization’s attack surface. Services, input fields in a
web application, and communication protocols are all examples of what component of an
attack surface evaluation?
Threats
Attack vectors
Risks
Surface tension
Michelle wants to implement a static application security testing (SAST) tool into her
continuous integration pipeline. What challenge could she run into if her organization
uses multiple programming languages for components of their application stack that will
be tested?
They will have to ensure the scanner works with all of the languages chosen
They will have to compile all of the code to the same binary output language.
They will have to run the applications in a sandbox.
They will have to run the applications under the same execution environment.
Ken learns that an APT group is targeting his organization. What term best describes this
situation?
Risk
Threat
Countermeasure
Vulnerability
Which one of the following activities is least likely to occur during the risk identification
process?
Network segmentation
Threat intelligence
Vulnerability scanning
System assessments
What two factors are weighted most heavily when determining the severity of a risk?
Probability and magnitude
Likelihood and probability
Magnitude and impact
Impact and control
Preemployment background screening is an example of what type of security control?
Detective
Preventive
Corrective
Compensating
Roland received a security assessment report from a third-party
assessor, and it indicated
that one of the organization’s web applications is susceptible to an OAuth redirect attack.
What type of attack would this vulnerability allow an attacker to wage?
Privilege escalation
Cross-site
scripting
SQL injection
Impersonation
Gary recently conducted a comprehensive security review of his organization. He identified
the 25 top risks to the organization and is pursuing different risk management strategies for
each of these risks. In some cases, he is using multiple strategies to address a single risk. His
goal is to reduce the overall level of risk so that it lies within his organization’s risk tolerance.
Gary decides that the organization should integrate a threat intelligence feed with the firewall.
What type of risk management strategy is this?
Risk mitigation
Risk acceptance
Risk transference
Risk avoidance
Gary recently conducted a comprehensive security review of his organization. He identified
the 25 top risks to the organization and is pursuing different risk management strategies for
each of these risks. In some cases, he is using multiple strategies to address a single risk. His
goal is to reduce the overall level of risk so that it lies within his organization’s risk tolerance.
Gary discovers that his organization is storing some old files in a cloud service that are
exposed to the world. He deletes those files. What type of risk management strategy is this?
Risk mitigation
Risk acceptance
Risk transference
Risk avoidance
Gary recently conducted a comprehensive security review of his organization. He identified
the 25 top risks to the organization and is pursuing different risk management strategies for
each of these risks. In some cases, he is using multiple strategies to address a single risk. His
goal is to reduce the overall level of risk so that it lies within his organization’s risk tolerance.
Gary is working with his financial team to purchase a cyber-liability
insurance policy to cover the financial impact of a data breach. What type of risk management strategy is
he using?
Risk mitigation
Risk acceptance
Risk transference
Risk avoidance
Which one of the following risk management strategies is most likely to limit the probability
of a risk occurring?
Risk acceptance
Risk avoidance
Risk transference
Risk mitigation
Saanvi would like to reduce the probability of a data breach that affects sensitive personal
information. Which one of the following compensating controls is most likely to achieve
that objective?
Minimizing the amount of data retained and the number of places where it is stored
Limiting the purposes for which data may be used
Purchasing cyber-risk
insura
Installing a new firewall
Kwame recently completed a risk assessment and is concerned that the level of residual risk
exceeds his organization’s risk tolerance. What should he do next?
Have a discussion with his manager.
Implement new security controls.
Modify business processes to lower risk.
Purge data from systems.
Alan is a risk manager for Acme University, a higher education institution located in the
western United States. He is concerned about the threat that an earthquake will damage his
organization’s primary datacenter. He recently undertook a replacement cost analysis and
determined that the datacenter is valued at $10 million.
After consulting with seismologists, Alan determined that an earthquake is expected in the
area of the datacenter once every 200 years. Datacenter specialists and architects helped
him determine that an earthquake would likely cause $5 million in damage to the facility.
Based on the information in this scenario, what is the exposure factor (EF) for the effect of
an earthquake on Acme University’s datacenter?
10 percent
25 percent
50 percent
75 percent
Alan is a risk manager for Acme University, a higher education institution located in the
western United States. He is concerned about the threat that an earthquake will damage his
organization’s primary datacenter. He recently undertook a replacement cost analysis and
determined that the datacenter is valued at $10 million.
After consulting with seismologists, Alan determined that an earthquake is expected in the
area of the datacenter once every 200 years. Datacenter specialists and architects helped
him determine that an earthquake would likely cause $5 million in damage to the facility.
Based on the information in this scenario, what is the annualized rate of occurrence (ARO)
for an earthquake at the datacenter?
.0025
.005
.01
.015
Alan is a risk manager for Acme University, a higher education institution located in the
western United States. He is concerned about the threat that an earthquake will damage his
organization’s primary datacenter. He recently undertook a replacement cost analysis and
determined that the datacenter is valued at $10 million.
After consulting with seismologists, Alan determined that an earthquake is expected in the
area of the datacenter once every 200 years. Datacenter specialists and architects helped
him determine that an earthquake would likely cause $5 million in damage to the facility.
Based on the information in this scenario, what is the annualized loss expectancy (ALE) for
an earthquake at the datacenter?
$25,000
$50,000
$250,000
$500,000
Alan is a risk manager for Acme University, a higher education institution located in the
western United States. He is concerned about the threat that an earthquake will damage his
organization’s primary datacenter. He recently undertook a replacement cost analysis and
determined that the datacenter is valued at $10 million.
After consulting with seismologists, Alan determined that an earthquake is expected in the
area of the datacenter once every 200 years. Datacenter specialists and architects helped
him determine that an earthquake would likely cause $5 million in damage to the facility.
Referring to the previous scenario, if Alan’s organization decides to move the datacenter to
a location where earthquakes are not a risk, what risk management strategy are they using?
Risk mitigation
Risk avoidance
Risk acceptance
Risk transference
Alan is a risk manager for Acme University, a higher education institution located in the
western United States. He is concerned about the threat that an earthquake will damage his
organization’s primary datacenter. He recently undertook a replacement cost analysis and
determined that the datacenter is valued at $10 million.
After consulting with seismologists, Alan determined that an earthquake is expected in the
area of the datacenter once every 200 years. Datacenter specialists and architects helped
him determine that an earthquake would likely cause $5 million in damage to the facility.
Referring to the previous scenario, if the organization decides not to relocate the datacenter
but instead purchases an insurance policy to cover the replacement cost of the datacenter,
what risk management strategy are they using?
Risk mitigation
Risk avoidance
Risk acceptance
Risk transference
Alan is a risk manager for Acme University, a higher education institution located in the
western United States. He is concerned about the threat that an earthquake will damage his
organization’s primary datacenter. He recently undertook a replacement cost analysis and
determined that the datacenter is valued at $10 million.
After consulting with seismologists, Alan determined that an earthquake is expected in the
area of the datacenter once every 200 years. Datacenter specialists and architects helped
him determine that an earthquake would likely cause $5 million in damage to the facility.
Referring to the previous scenario, assume that the organization decides that relocation is
too difficult and the insurance is too expensive. They instead decide that they will carry on
despite the risk of earthquake and handle the impact if it occurs. What risk management
strategy are they using?
Risk mitigation
Risk avoidance
Risk acceptance
Risk transference
Colin would like to implement a detective security control in his accounting department,
which is specifically designed to identify cases of fraud that are able to occur despite the
presence of other security controls. Which one of the following controls is best suited to
meet Colin’s need?
Separation of duties
Least privilege
Dual control
Mandatory vacations
Rob is an auditor reviewing the managerial controls used in an organization. He is examining
the payment process used by the company to issue checks to vendors. He notices
that Helen, a staff accountant, is the person responsible for creating new vendors. Norm,
another accountant, is responsible for issuing payments to vendors. Helen and Norm are
cross-trained to provide backup for each other. What security issue, if any, exists in this
situation?
Least privilege violation
Separation of duties violation
Dual control violation
No issue
Mei recently completed a risk management review and identified that the organization is susceptible to an on-path (also known as man-in-the-middle) attack. After review with her manager, they jointly decided that accepting the risk is the most appropriate strategy. What should Mei do next?
Implement additional security controls.
Design a remediation plan.
Repeat the business impact assessment.
Document the decision.
Robin is planning to conduct a risk assessment in her organization. She is concerned that
it will be difficult to perform the assessment because she needs to include information
about both tangible and intangible assets. What would be the most effective risk assessment
strategy for her to use?
Quantitative risk assessment
Qualitative risk assessment
Combination of quantitative and qualitative risk assessment
Neither quantitative nor qualitative risk assessment
Barry’s organization is running a security exercise and Barry was assigned to conduct offensive
operations. What term best describes Barry’s role in the process?
Red team
Purple team
Blue team
White team
Vlad’s organization recently underwent a security audit that resulted in a finding that the
organization fails to promptly remove the accounts associated with users who have left
the organization. This resulted in at least one security incident where a terminated user
logged into a corporate system and took sensitive information. What identity and access
management control would best protect against this risk?
Automated deprovisioning
Quarterly user account reviews
Separation of duties
Two-person
control
Jay is the CISO for his organization and is responsible for conducting periodic reviews of
the organization’s information security policy. The policy was written three years ago and
has undergone several minor revisions after audits and assessments. Which one of the following
would be the most reasonable frequency to conduct formal reviews of the policy?
Monthly
Quarterly
Annually
Every five years
Terri is undertaking a risk assessment for her organization. Which one of the following
activities would normally occur first?
Risk identification
Risk calculation
Risk mitigation
Risk management
Kai is attempting to determine whether he can destroy a cache of old records that he discovered.
What type of policy would most directly answer his question?
Data ownership
Data classification
Data minimization
Data retention
Fences are a widely used security control that can be described by several different control
types. Which one of the following control types would least describe a fence?
Deterrent
Corrective
Preventive
Physical
Ian is designing an authorization scheme for his organization’s deployment of a new
accounting system. He is considering putting a control in place that would require that two
accountants approve any payment request over $100,000. What security principle is Ian
seeking to enforce?
Security through obscurity
Least privilege
Separation of duties
Dual control
Carmen is working with a new vendor on the design of a penetration test. She would like
to ensure that the vendor does not conduct any physical intrusions as part of their testing.
Where should Carmen document this requirement?
Rules of engagement
Service level objectives
Nondisclosure agreement
Counterparty agreement
Gavin is drafting a document that provides a detailed step-by-
step process that users may
follow to connect to the VPN from remote locations. Alternatively, users may ask IT to help
them configure the connection. What term best describes this document?
Policy
Procedure
Standard
Guideline
Which one of the following security controls is designed to help provide continuity for security
responsibilities?
Succession planning
Separation of duties
Mandatory vacation
Dual control
After conducting a security review, Oskar determined that his organization is not conducting
regular backups of critical data. What term best describes the type of control gap that
exists in Oskar’s organization?
Preventive
Corrective
Detective
Deterrent
Carla is reviewing the cybersecurity policies used by her organization. What policy might
she put in place as a failsafe to cover employee behavior situations where no other policy
directly applies?
Data monitoring policy
Account management policy
Code of conduct
Data ownership policy
Which one of the following items is not normally included in a request for an exception to
security policy?
Description of a compensating control
Description of the risks associated with the exception
Proposed revision to the security policy
Business justification for the exception
What policy should contain provisions for removing user access upon termination?
Data ownership policy
Data classification policy
Data retention policy
Account management policy
Karen is the CISO of a major manufacturer of industrial parts. She is currently performing an
assessment of the firm’s financial controls, with an emphasis on implementing security practices
that will reduce the likelihood of theft from the firm.
Karen would like to ensure that the same individual is not able to both create a new vendor
in the system and authorize a payment to that vendor. She is concerned that an individual
who could perform both of these actions would be able to send payments to false vendors.
What type of control should Karen implement?
Mandatory vacations
Separation of duties
Job rotation
Two-person
control
Karen is the CISO of a major manufacturer of industrial parts. She is currently performing an
assessment of the firm’s financial controls, with an emphasis on implementing security practices
that will reduce the likelihood of theft from the firm.
The accounting department has a policy that requires the signatures of two individuals on
checks valued over $5,000. What type of control do they have in place?
Mandatory vacations
Separation of duties
Job rotation
Two-person
control
Karen is the CISO of a major manufacturer of industrial parts. She is currently performing an
assessment of the firm’s financial controls, with an emphasis on implementing security practices
that will reduce the likelihood of theft from the firm.
Karen would also like to implement controls that would help detect potential malfeasance
by existing employees. Which one of the following controls is least likely to detect
malfeasance?
Mandatory vacations
Separation of duties
Job rotation
Two-person
control
Kevin is conducting a security exercise for his organization that uses both offensive and
defensive operations. His role is to serve as the moderator of the exercise and to arbitrate
disputes. What role is Kevin playing?
White team
Red team
Swiss team
Blue team
Bohai is concerned about access to the main account for a cloud service that his company
uses to manage payment transactions. He decides to implement a new process for multifactor
authentication to that account where an individual on the IT team has the password
to the account, while an individual in the accounting group has the token. What security
principle is Bohai using?
Dual control
Separation of duties
Least privilege
Security through obscurity
Tina is preparing for a penetration test and is working with a new vendor. She wants to
make sure that the vendor understands exactly what technical activities are permitted
within the scope of the test. Where should she document these requirements?
MOA
Contract
RoE
SLA
Azra is reviewing a draft of the Domer Doodads information security policy and finds that
it contains the following statements. Which one of these statements would be more appropriately
placed in a different document?
Domer Doodads designates the chief information security officer as the individual with
primary responsibility for information security.
The chief information security officer is granted the authority to create specific
requirements that implement this policy.
All access to financial systems must use multifactor authentication for remote
connections.
Domer Doodads considers cybersecurity and compliance to be of critical importance
to the business.
Which one of the following security policy framework documents never includes mandatory
employee compliance?
Policy
Guideline
Procedure
Standard
Kaitlyn is on the red team during a security exercise, and she has a question about whether
an activity is acceptable under the exercise’s rules of engagement. Who would be the most
appropriate person to answer her question?
Red team leader.
White team leader.
Blue team leader.
Kaitlyn should act without external advice.
Seamus is conducting a business impact assessment for his organization. He is attempting
to determine the risk associated with a denial-of-service attack against his organization’s datacenter.
Seamus consulted with various subject-matter experts (SMEs) and determined that the attack
would not cause any permanent damage to equipment, applications, or data. The primary
damage would come in the form of lost revenue. Seamus believes that the organization would lose $75,000 in revenue during a successful attack.
Seamus also consulted with his threat management vendor, who considered the probability of
a successful attack against his organization and determined that there is a 10 percent chance
of a successful attack in the next 12 months.
What is the ARO for this assessment?
8 percent
10 percent
12 percent
100 percent
Seamus is conducting a business impact assessment for his organization. He is attempting
to determine the risk associated with a denial-of-service attack against his organization’s datacenter.
Seamus consulted with various subject-matter experts (SMEs) and determined that the attack
would not cause any permanent damage to equipment, applications, or data. The primary
damage would come in the form of lost revenue. Seamus believes that the organization would lose $75,000 in revenue during a successful attack.
Seamus also consulted with his threat management vendor, who considered the probability of
a successful attack against his organization and determined that there is a 10 percent chance
of a successful attack in the next 12 months.
What is the SLE for this scenario?
$625
$6,250
$7,500
$75,000
Seamus is conducting a business impact assessment for his organization. He is attempting
to determine the risk associated with a denial-of-service attack against his organization’s datacenter.
Seamus consulted with various subject-matter experts (SMEs) and determined that the attack
would not cause any permanent damage to equipment, applications, or data. The primary
damage would come in the form of lost revenue. Seamus believes that the organization would lose $75,000 in revenue during a successful attack.
Seamus also consulted with his threat management vendor, who considered the probability of
a successful attack against his organization and determined that there is a 10 percent chance
of a successful attack in the next 12 months.
What is the ALE for this scenario?
$625
$6,250
$7,500
$75,000
Seamus is conducting a business impact assessment for his organization. He is attempting
to determine the risk associated with a denial-of-service attack against his organization’s datacenter.
Seamus consulted with various subject-matter experts (SMEs) and determined that the attack
would not cause any permanent damage to equipment, applications, or data. The primary
damage would come in the form of lost revenue. Seamus believes that the organization would lose $75,000 in revenue during a successful attack.
Seamus also consulted with his threat management vendor, who considered the probability of
a successful attack against his organization and determined that there is a 10 percent chance
of a successful attack in the next 12 months.
Seamus is considering purchasing a DDoS protection system that would reduce the
likelihood of a successful attack. What type of control is he considering?
Detective
Corrective
Preventive
Deterrent
Seamus is conducting a business impact assessment for his organization. He is attempting
to determine the risk associated with a denial-of-service attack against his organization’s datacenter.
Seamus consulted with various subject-matter experts (SMEs) and determined that the attack
would not cause any permanent damage to equipment, applications, or data. The primary
damage would come in the form of lost revenue. Seamus believes that the organization would lose $75,000 in revenue during a successful attack.
Seamus also consulted with his threat management vendor, who considered the probability of
a successful attack against his organization and determined that there is a 10 percent chance
of a successful attack in the next 12 months.
Seamus wants to make sure that he can accurately describe the category of the DDoS protection
service to auditors. Which term best describes the category of this control?
Compensating
Physical
Operational
Technical
Piper’s organization handles credit card information and is, therefore, subject to the Payment
Card Industry Data Security Standard (PCI DSS). She is working to implement the PCI DSS
requirements.
As Piper attempts to implement PCI DSS requirements, she discovers that she is unable to
meet one of the requirements because of a technical limitation in her point-of-
sale system.
She decides to work with regulators to implement a second layer of logical isolation to protect
this system from the Internet to allow its continued operation despite not meeting one
of the requirements. What term best describes the type of control Piper has implemented?
Physical control
Operational control
Compensating control
Deterrent control
Piper’s organization handles credit card information and is, therefore, subject to the Payment
Card Industry Data Security Standard (PCI DSS). She is working to implement the PCI DSS
requirements.
When Piper implements this new isolation technology, what type of risk management action
is she taking?
Risk acceptance
Risk avoidance
Risk transference
Risk mitigation
