Question 191

A security engineer needs to ensure production containers are automatically scanned for vulnerabilities before they are accepted into the production environment. Which of the following should the engineer use to automatically incorporate vulnerability scanning on every commit?
  • Question 192

    A security analyst is performing a vulnerability assessment on behalf of a client. The analyst must define what constitutes a risk to the organization.
    Which of the following should be the analyst's FIRST action?
  • Question 193

    A company hired a third party to develop software as part of its strategy to be quicker to market. The company's policy outlines the following requirements:
    The credentials used to publish production software to the container registry should be stored in a secure location.
    Access should be restricted to the pipeline service account, without the ability for the third-party developer to read the credentials directly.
    Which of the following would be the BEST recommendation for storing and monitoring access to these shared credentials?
  • Question 194

    A cybersecurity engineer analyst a system for vulnerabilities. The tool created an OVAL. Results document as output. Which of the following would enable the engineer to interpret the results in a human readable form? (Select TWO.)
  • Question 195

    An auditor Is reviewing the logs from a web application to determine the source of an Incident. The web application architecture Includes an Internet-accessible application load balancer, a number of web servers In a private subnet, application servers, and one database server In a tiered configuration. The application load balancer cannot store the logs. The following are sample log snippets:

    Which of the following should the auditor recommend to ensure future incidents can be traced back to the sources?