問題1
A user tried to access a web page at http://10.1.1.1. Previously the web page did not require authentication, and now the browser is prompting for credentials. Which of the following actions would best prevent the issue from reoccurring and reduce the likelihood of credential exposure?
A user tried to access a web page at http://10.1.1.1. Previously the web page did not require authentication, and now the browser is prompting for credentials. Which of the following actions would best prevent the issue from reoccurring and reduce the likelihood of credential exposure?
正確答案: D
說明:(僅 NewDumps 成員可見)
問題2
A security engineer needs 10 secure the OT environment based on me following requirements:
- Isolate the OT network segment
- Restrict Internet access.
- Apply security updates two workstations
- Provide remote access to third-party vendors
Which of the following design strategies should the engineer implement to best meet these requirements?
A security engineer needs 10 secure the OT environment based on me following requirements:
- Isolate the OT network segment
- Restrict Internet access.
- Apply security updates two workstations
- Provide remote access to third-party vendors
Which of the following design strategies should the engineer implement to best meet these requirements?
正確答案: D
說明:(僅 NewDumps 成員可見)
問題3
After an incident response exercise, a security administrator reviews the following table:

Which of the following should the administrator do to best support rapid incident response in the future?
After an incident response exercise, a security administrator reviews the following table:

Which of the following should the administrator do to best support rapid incident response in the future?
正確答案: D
說明:(僅 NewDumps 成員可見)
問題4
A hospital provides tablets to its medical staff to enable them to more quickly access and edit patients' charts. The hospital wants to ensure that if a tablet is identified as lost or stolen and a remote command is issued, the risk of data loss can be mitigated within seconds. The tablets are configured as follows to meet hospital policy:
- Full disk encryption is enabled.
- "Always On" corporate VPN is enabled.
- eFuse-backed keystore is enabled/ready.
- Wi-Fi 6 is configured with SAE.
- Location services is disabled.
- Application allow list is unconfigured.
Assuming the hospital policy cannot be changed, which of the following is the best way to meet the hospital's objective?
A hospital provides tablets to its medical staff to enable them to more quickly access and edit patients' charts. The hospital wants to ensure that if a tablet is identified as lost or stolen and a remote command is issued, the risk of data loss can be mitigated within seconds. The tablets are configured as follows to meet hospital policy:
- Full disk encryption is enabled.
- "Always On" corporate VPN is enabled.
- eFuse-backed keystore is enabled/ready.
- Wi-Fi 6 is configured with SAE.
- Location services is disabled.
- Application allow list is unconfigured.
Assuming the hospital policy cannot be changed, which of the following is the best way to meet the hospital's objective?
正確答案: D
說明:(僅 NewDumps 成員可見)
問題5
Which of the following security risks should be considered as an organization reduces cost and increases availability of services by adopting serverless computing?
Which of the following security risks should be considered as an organization reduces cost and increases availability of services by adopting serverless computing?
正確答案: A
問題6
A malware researcher has discovered a credential stealer is looking at a specific memory register to harvest passwords that will be used later for lateral movement in corporate networks. The malware is using TCP 4444 to communicate with other workstations. The lateral movement would be best mitigated by:
A malware researcher has discovered a credential stealer is looking at a specific memory register to harvest passwords that will be used later for lateral movement in corporate networks. The malware is using TCP 4444 to communicate with other workstations. The lateral movement would be best mitigated by:
正確答案: A
問題7
A security team is creating tickets to track the progress of remediation. Which of the following is used to specify the due dates for high and critical-priority findings?
A security team is creating tickets to track the progress of remediation. Which of the following is used to specify the due dates for high and critical-priority findings?
正確答案: B
說明:(僅 NewDumps 成員可見)
問題8
A company is decommissioning old servers and hard drives that contain sensitive data. Which of the following best protects against data leakage?
A company is decommissioning old servers and hard drives that contain sensitive data. Which of the following best protects against data leakage?
正確答案: A
說明:(僅 NewDumps 成員可見)
問題9
An engineering team determines the cost to mitigate certain risks is higher than the asset values.
The team must ensure the risks are prioritized appropriately. Which of the following is the best way to address the issue?
An engineering team determines the cost to mitigate certain risks is higher than the asset values.
The team must ensure the risks are prioritized appropriately. Which of the following is the best way to address the issue?
正確答案: C
說明:(僅 NewDumps 成員可見)
問題10
A pharmaceutical company acquired a growing startup. The pharmaceutical company has a comprehensive OT stack, while the startup allows employees to install IoT devices without oversight. Both companies will continue to operate independently with some systems shared and others separated. Which of the following considerations are the most important when designing the new combined systems? (Choose two.)
A pharmaceutical company acquired a growing startup. The pharmaceutical company has a comprehensive OT stack, while the startup allows employees to install IoT devices without oversight. Both companies will continue to operate independently with some systems shared and others separated. Which of the following considerations are the most important when designing the new combined systems? (Choose two.)
正確答案: D,E
問題11
A global manufacturing company has an internal application that is critical to making products.
This application cannot be updated and must be available in the production area. A security architect is implementing security for the application. Which of the following best describes the action the architect should take?
A global manufacturing company has an internal application that is critical to making products.
This application cannot be updated and must be available in the production area. A security architect is implementing security for the application. Which of the following best describes the action the architect should take?
正確答案: A
說明:(僅 NewDumps 成員可見)
問題12
Several unlabeled documents in a cloud document repository contain cardholder information.
Which of the following configuration changes should be made to the DLP system to correctly label these documents in the future?
Several unlabeled documents in a cloud document repository contain cardholder information.
Which of the following configuration changes should be made to the DLP system to correctly label these documents in the future?
正確答案: B
說明:(僅 NewDumps 成員可見)
問題13
A security officer is requiring all personnel working on a special project to obtain a security clearance requisite with the level of all information being accessed. Data on this network must be protected at the same level of each clearance holder. The need to know must be verified by the data owner. Which of the following should the security officer do to meet these requirements?
A security officer is requiring all personnel working on a special project to obtain a security clearance requisite with the level of all information being accessed. Data on this network must be protected at the same level of each clearance holder. The need to know must be verified by the data owner. Which of the following should the security officer do to meet these requirements?
正確答案: A
說明:(僅 NewDumps 成員可見)