Question 236

You are the chief cybersecurity officer at CloudSecure Inc., and your team is responsible for securing a cloud based application that handles sensitive customer data. To ensure that the data is protected from breaches, you have decided to implement encryption for both data-at-rest and data-in-transit. The development team suggests using SSL/TLS for securing data in transit.
However, you want to also implement a mechanism to detect if the data was tampered with during transmission. Which of the following should you propose?
  • Question 237

    Cyber experts conducting covert missions exclusively for national interests are best classified as:
  • Question 238

    The network in ABC company is using the network address 192.168.1.64 with mask 255.255.255.192. In the network the servers are in the addresses 192.168.1.122, 192.168.1.123 and 192.168.1.124. An attacker is trying to find those servers but he cannot see them in his scanning. The command he is using is: nmap
    192.168.1.64/28.
    Why he cannot see the servers?
  • Question 239

    A regional investment firm in Denver, Colorado, recently migrated to a fully switched Ethernet infrastructure.
    During an authorized security evaluation, a consultant connected a test device to an access-layer switch and initiated a scripted network interaction.
    Within minutes, administrators observed irregular switching behavior. Frames that were normally delivered directly between specific workstations began appearing across multiple switch ports. Users reported brief connectivity instability, but no configuration changes were made to the switch. After the activity subsided, forwarding operations gradually stabilized.
    Based on the observed behavior, which sniffing technique was most likely performed?
  • Question 240

    An organization has automated the operation of critical infrastructure from a remote location. For this purpose, all the industrial control systems are connected to the Internet. To empower the manufacturing process, ensure the reliability of industrial networks, and reduce downtime and service disruption, the organization decided to install an OT security tool that further protects against security incidents such as cyber espionage, zero-day attacks, and malware. Which of the following tools must the organization employ to protect its critical infrastructure?