Question 216

A potentially life-threatening vulnerability is found in vendor software that is used to manage critical systems.
Which of the following is generally considered the BEST method to disclose the vulnerability from an ethical hacking perspective?
  • Question 217

    An organization has determined that it needs to retain customer records for at least thirty years to discover generational trends in customer behavior. However, relevant local regulation requires that all Personally Identifiable Information (PII) is deleted after expiration of the customer's engagement with the organization, which is usually no longer than one year. How should the data be handled at the expiration of customer engagement at one year?
  • Question 218

    Which of the following actions best supports a company's strategic focus on delivery speed to improve competitive advantage?
  • Question 219

    Following the setting of an organization's risk appetite by senior management, a risk manager needs to prioritize all identified risks for treatment. Each risk has been scored based on its Annualized Loss Expectancy (ALE). Management has asked for an immediate risk mitigation plan focusing on top risks.
    Which is the MOST effective approach for the risk manager to quickly present a proposal to management?
  • Question 220

    An organization needs a firewall that maps packets to connections and uses Transmission Control Protocol
    /Internet Protocol (TCP/IP) header fields to keep track of connections. Which type of firewall will be recommended?