Question 11

Clients are reporting slowness when attempting to access a series of load-balanced APIs that do not require authentication. The servers that host the APIs are showing heavy CPU utilization. No alerts are found on the WAFs sitting in front of the APIs.
Which of the following should a security engineer recommend to BEST remedy the performance issues in a timely manner?
  • Question 12

    An organization's finance system was recently attacked. A forensic analyst is reviewing the contents Of the compromised files for credit card dat a.
    Which of the following commands should the analyst run to BEST determine whether financial data was lost?
  • Question 13

    An organization is assessing the security posture of a new SaaS CRM system that handles sensitive Pll and identity information, such as passport numbers. The SaaS CRM system does not meet the organization's current security standards. The assessment identifies the following:
    1- There will be a $20,000 per day revenue loss for each day the system is delayed going into production.
    2- The inherent risk is high.
    3- The residual risk is low.
    4- There will be a staged deployment to the solution rollout to the contact center.
    Which of the following risk-handling techniques will BEST meet the organization's requirements?
  • Question 14

    Given the following log snippet from a web server:

    Which of the following BEST describes this type of attack?
  • Question 15

    A municipal department receives telemetry data from a third-party provider The server collecting telemetry sits in the municipal departments screened network and accepts connections from the third party over HTTPS. The daemon has a code execution vulnerability from a lack of input sanitization of out-of-bound messages, and therefore,
    the cybersecurity engineers would like to Implement nsk mitigations. Which of the following actions, if combined, would BEST prevent exploitation of this vulnerability? (Select TWO).