Question 1
A DevOps analyst must include code scanning in the current CI/CD pipeline. The company decided not to invest in a different system, so the analyst has found a lightweight scanning module in the CI/CD tool to utilize. Which of the following best describes the analyst's approach?
Question 2
A recent security audit found that RCE was possible for a specific application server that requires public access for HTTP and HTTPS traffic. Which of the following controls should a security analyst recommend?
Question 3
A security analyst is scanning an ICS host (192.168.1.5) in an industrial plant for insecure ports while minimizing the impact to uptime or performance. Which of following commands should the analyst use to perform the task?
Question 4
Due to some incidents involving non-authorized devices, a company wants to implement a solution that only allows access to its LAN and Wi-Fi if certain policies are matched. Which of the following is the best solution to implement?
Question 5
Law enforcement subpoenas a company in order to obtain all records related to the activities a threat actor performed using the IP address 154.21.154.21. Which of the following should an analyst perform first?
