Question 96

An auditor Is reviewing the logs from a web application to determine the source of an Incident. The web application architecture Includes an Internet-accessible application load balancer, a number of web servers In a private subnet, application servers, and one database server In a tiered configuration. The application load balancer cannot store the logs. The following are sample log snippets:

Which of the following should the auditor recommend to ensure future incidents can be traced back to the sources?
  • Question 97

    A company is deploying multiple VPNs to support supplier connections into its extranet applications. The network security standard requires:
    * All remote devices to have up-to-date antivirus
    * An up-to-date and patched OS
    Which of the following technologies should the company deploy to meet its security objectives? (Select TWO)_
  • Question 98

    A security analyst notices a number of SIEM events that show the following activity:

    Which of the following response actions should the analyst take FIRST?
  • Question 99

    A bank hired a security architect to improve its security measures against the latest threats The solution must meet the following requirements
    * Recognize and block fake websites
    * Decrypt and scan encrypted traffic on standard and non-standard ports
    * Use multiple engines for detection and prevention
    * Have central reporting
    Which of the following is the BEST solution the security architect can propose?
  • Question 100

    An organization is planning for disaster recovery and continuity of operations.
    INSTRUCTIONS
    Review the following scenarios and instructions. Match each relevant finding to the affected host.
    After associating scenario 3 with the appropriate host(s), click the host to select the appropriate corrective action for that finding.
    Each finding may be used more than once.
    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.