Question 481
A critical system audit shows that the payroll system is not meeting security policy due to missing OS security patches. Upon further review, it appears that the system is not being patched at all. The vendor states that the system is only supported on the current OS patch level. Which of the following compensating controls should be used to mitigate the vulnerability of missing OS patches on this system?
Question 482
Which of the following provides the BEST risk calculation methodology?
Question 483
A security engineer is embedded with a development team to ensure security is built into products being
developed. The security engineer wants to ensure developers are not blocked by a large number of
security requirements applied at specific schedule points.
Which of the following solutions BEST meets the engineer's goal?
developed. The security engineer wants to ensure developers are not blocked by a large number of
security requirements applied at specific schedule points.
Which of the following solutions BEST meets the engineer's goal?
Question 484
A development team is testing an in-house-developed application for bugs. During the test, the application crashes several times due to null pointer exceptions. Which of the following tools, if integrated into an IDE during coding, would identify these bugs routinely?
Question 485
An organization is currently performing a market scan for managed security services and EDR capability. Which of the following business documents should be released to the prospective vendors in the first step of the process? (Select TWO).