Question 216

A compliance officer of a large organization has reviewed the firm's vendor management program but has discovered there are no controls defined to evaluate third-party risk or hardware source authenticity. The compliance officer wants to gain some level of assurance on a recurring basis regarding the implementation of controls by third parties.
Which of the following would BEST satisfy the objectives defined by the compliance officer?
(Choose two.)
  • Question 217

    An audit has revealed an organization is utilizing a large number of servers that are running unsupported operating systems.
    As part of the management response phase of the audit, which of the following would BEST demonstrate senior management is appropriately aware of and addressing the issue?
  • Question 218

    A company's domain has been spooled in numerous phishing campaigns. An analyst needs to determine the company is a victim of domain spoofing, despite having a DMARC record that should tell mailbox providers to ignore any email that fails DMARC upon review of the record, the analyst finds the following:

    Which of the following BEST explains the reason why the company's requirements are not being processed correctly by mailbox providers?
  • Question 219

    You are a penetration tester who is reviewing the system hardening guidelines for a company. Hardening guidelines indicate the following.
    There must be one primary server or service per device.
    Only default port should be used
    Non- secure protocols should be disabled.
    The corporate internet presence should be placed in a protected subnet
    Instructions :
    Using the available tools, discover devices on the corporate network and the services running on these devices.
    You must determine
    ip address of each device
    The primary server or service each device
    The protocols that should be disabled based on the hardening guidelines

    Question 220

    A security manager has asked an analyst to provide feedback on the results of a penetration test. After reviewing the results, the manager requests information regarding the possible exploitation of vulnerabilities. Which of the following information data points would be MOST useful for the analyst to provide to the security manager, who would then communicate the risk factors to the senior management team? (Select TWO).