問題1
What role does the "Cross Market Operational Resilience Group" (CMORG) play in relation to CBEST and the wider UK financial sector testing landscape?
What role does the "Cross Market Operational Resilience Group" (CMORG) play in relation to CBEST and the wider UK financial sector testing landscape?
正確答案: C
說明:(僅 NewDumps 成員可見)
問題2
Which of the following best describes why Rules of Engagement documents commonly include a defined document version history and change log?
Which of the following best describes why Rules of Engagement documents commonly include a defined document version history and change log?
正確答案: C
說明:(僅 NewDumps 成員可見)
問題3
Which of the following best describes why maintaining a clear distinction between "governance of the testing programme" and "governance of day-to-day IT security operations" is important?
Which of the following best describes why maintaining a clear distinction between "governance of the testing programme" and "governance of day-to-day IT security operations" is important?
正確答案: B
說明:(僅 NewDumps 成員可見)
問題4
Which of the following best explains why "consent" obtained from a single business unit within a large, decentralised organisation may not be sufficient legal authorisation to test a shared, group-wide system?
Which of the following best explains why "consent" obtained from a single business unit within a large, decentralised organisation may not be sufficient legal authorisation to test a shared, group-wide system?
正確答案: C
說明:(僅 NewDumps 成員可見)
問題5
Structurally, how does the phased approach of iCAST compare to CBEST?
Structurally, how does the phased approach of iCAST compare to CBEST?
正確答案: C
說明:(僅 NewDumps 成員可見)
問題6
Which of the following best describes the value of scheduling a formal closure/debrief meeting with key stakeholders after the report is delivered, rather than simply emailing the report with no further discussion?
Which of the following best describes the value of scheduling a formal closure/debrief meeting with key stakeholders after the report is delivered, rather than simply emailing the report with no further discussion?
正確答案: D
說明:(僅 NewDumps 成員可見)
問題7
The CBEST Implementation Guide is best described as:
The CBEST Implementation Guide is best described as:
正確答案: A
說明:(僅 NewDumps 成員可見)
問題8
Why is early identification of stakeholders (e.g., business owners of in-scope systems, legal, data protection officer, IT operations leadership) considered essential during scoping?
Why is early identification of stakeholders (e.g., business owners of in-scope systems, legal, data protection officer, IT operations leadership) considered essential during scoping?
正確答案: D
說明:(僅 NewDumps 成員可見)
問題9
Which best summarises how TIBER-EU treats third-party and supply-chain attack paths discovered during threat intelligence gathering?
Which best summarises how TIBER-EU treats third-party and supply-chain attack paths discovered during threat intelligence gathering?
正確答案: A
說明:(僅 NewDumps 成員可見)
問題10
Which of the following best describes the concept of a "three lines of defence" model as it might apply to governance of a red team programme within a large organisation?
Which of the following best describes the concept of a "three lines of defence" model as it might apply to governance of a red team programme within a large organisation?
正確答案: B
說明:(僅 NewDumps 成員可見)
問題11
What document formally defines the scope of a TIBER-EU test, including the Critical or Important Functions to be assessed?
What document formally defines the scope of a TIBER-EU test, including the Critical or Important Functions to be assessed?
正確答案: D
說明:(僅 NewDumps 成員可見)
問題12
Which of the following best describes appropriate RoE treatment of "live" versus "simulated" malicious payloads (e.g., custom malware) used to demonstrate exploitation?
Which of the following best describes appropriate RoE treatment of "live" versus "simulated" malicious payloads (e.g., custom malware) used to demonstrate exploitation?
正確答案: D
說明:(僅 NewDumps 成員可見)
問題13
Which of the following best describes the governance rationale for requiring the Control Group (rather than individual technical staff) to make the final decision on whether to proceed with a particularly high-risk technical scenario identified during planning?
Which of the following best describes the governance rationale for requiring the Control Group (rather than individual technical staff) to make the final decision on whether to proceed with a particularly high-risk technical scenario identified during planning?
正確答案: D
說明:(僅 NewDumps 成員可見)
問題14
Which of the following best describes the governance rationale for the internal Red Team provider organisation applying rigorous internal quality assurance review to a report before it is delivered to the client?
Which of the following best describes the governance rationale for the internal Red Team provider organisation applying rigorous internal quality assurance review to a report before it is delivered to the client?
正確答案: C
說明:(僅 NewDumps 成員可見)
問題15
CBEST accredited service providers for threat intelligence and penetration testing are:
CBEST accredited service providers for threat intelligence and penetration testing are:
正確答案: C
說明:(僅 NewDumps 成員可見)