Question 51

A security analyst needs to provide evidence of regular vulnerability scanning on the company's network for an auditing process. Which of the following is an example of a tool that can produce such evidence?
  • Question 52

    Which of the following is the best metric for an organization to focus on given recent investments in SIEM, SOAR, and a ticketing system?
  • Question 53

    A company has alerted planning the implemented a vulnerability management procedure.
    However, to security maturity level is low, so there are some prerequisites to complete before risk calculation and prioritization. Which of the following should be completed FIRST?
  • Question 54

    A disgruntled open-source developer has decided to sabotage a code repository with a logic bomb that will act as a wiper. Which of the following parts of the Cyber Kill Chain does this act exhibit?
  • Question 55

    A security analyst reviews the following Arachni scan results for a web application that stores PII data:

    Which of the following should be remediated first?