Question 41

When implementing serverless computing an organization must still account for:
  • Question 42

    A company suspects a web server may have been infiltrated by a rival corporation. The security engineer reviews the web server logs and finds the following:

    The security engineer looks at the code with a developer, and they determine the log entry is created when the following line is run:

    Which of the following is an appropriate security control the company should implement?
  • Question 43

    A Chief Security Officer (CSO) is concerned about the number of successful ransomware attacks that have hit the company. The data Indicates most of the attacks came through a fake email. The company has added training, and the CSO now wants to evaluate whether the training has been successful. Which of the following should the CSO implement?
  • Question 44

    A mobile device hardware manufacturer receives the following requirements from a company that wants to produce and sell a new mobile platform:
    * The platform should store biometric data.
    * The platform should prevent unapproved firmware from being loaded.
    * A tamper-resistant, hardware-based counter should track if unapproved firmware was loaded.
    Which of the following should the hardware manufacturer implement? (Select three).
  • Question 45

    A company created an external, PHP-based web application for its customers. A security researcher reports that the application has the Heartbleed vulnerability.
    Which of the following would BEST resolve and mitigate the issue? (Choose two.)