Question 91

Which objective is MOST appropriate to measure the effectiveness of password policy?
  • Question 92

    As Infrastructure as a Service (laaS) cloud service providers often do not allow the cloud service customers to perform on-premise audits, the BEST approach for the auditor should be to:
  • Question 93

    Who is accountable for the use of a cloud service?
  • Question 94

    Which objective is MOST appropriate to measure the effectiveness of password policy?
  • Question 95

    What is an advantage of using dynamic application security testing (DAST) over static application security testing (SAST) methodology?