Question 36

What is the key difference between a disaster recovery plan and a business continuity plan?
  • Question 37

    Anderson, a security engineer, was Instructed to monitor all incoming and outgoing traffic on the organization's network to identify any suspicious traffic. For this purpose, he employed an analysis technique using which he analyzed packet header fields such as IP options, IP protocols, IP fragmentation flags, offset, and identification to check whether any fields are altered in transit.
    Identify the type of attack signature analysis performed by Anderson in the above scenario.
  • Question 38

    Stella purchased a smartwatch online using her debit card. After making payment for the product through the payment gateway, she received a transaction text message with a deducted and available balance from her bank.
    Identify the information security element that ensures that Stella's transaction status is immediately reflected in her bank account in this scenario.
  • Question 39

    You have been assigned to perform a vulnerability assessment of a web server located at IP address 20.20.10.26. Identify the vulnerability with a severity score of &A. You can use the OpenVAS vulnerability scanner, available with the Parrot Security machine, with credentials admin/password for this challenge. (Practical Question)
  • Question 40

    A software company is developing a new software product by following the best practices for secure application development. Dawson, a software analyst, is checking the performance of the application on the client's network to determine whether end users are facing any issues in accessing the application.
    Which of the following tiers of a secure application development lifecycle involves checking the performance of the application?