Question 1

A pharmaceutical company's marketing team wants to send out notifications about new products to alert users of recalls and newly discovered adverse drug reactions. The team plans to use the names and mailing addresses that users have provided.
Which of the following data privacy standards does this violate?
  • Question 2

    Management wants to scan servers for vulnerabilities on a periodic basis. Management has decided that the scan frequency should be determined only by vendor patch schedules and the organization's application deployment schedule. Which of the following would force the organization to conduct an out-of- cycle vulnerability scan?
  • Question 3

    A server contains baseline images that are deployed to sensitive workstations on a regular basis.
    The images are evaluated once per month for patching and other fixes, but do not change otherwise. Which of the following controls should be put in place to secure the file server and ensure the images are not changed?
  • Question 4

    An analyst is examining a system that is suspected of being involved in an intrusion.
    The analyst uses the command `cat/etc/passwd' and receives the following partial output:

    Based on the above output, which of the following should the analyst investigate further?
  • Question 5

    A security technician configured a NIDS to monitor network traffic. Which of the following is a condition in which harmless traffic is classified as a potential network attack?