Question 136

An enterprise is deploying APIs that utilize a private key and a public key to ensure the connection string is protected. To connect to the API, customers must use the private key.
Which of the following would BEST secure the REST API connection to the database while preventing the use of a hard-coded string in the request string?
  • Question 137

    A security administrator wants to enable a feature that would prevent a compromised encryption key from being used to decrypt all the VPN traffic. Which of the following should the security administrator use?
  • Question 138

    Which of the following BEST sets expectation between the security team and business units within an organization?
  • Question 139

    A security engineer is reviewing Apache web server logs and has identified the following pattern in the log:
    GET https://example.com/image5/../../etc/passwd HTTP/1.1 200 OK
    The engineer has also reviewed IDS and firewall logs and established a correlation to an external IP address.
    Which of the following can be determined regarding the vulnerability and response?
  • Question 140

    A company is implementing SSL inspection. During the next six months, multiple web applications that will be separated out with subdomains will be deployed.
    Which of the following will allow the inspection of the data without multiple certificate deployments?