CS0-003 試験問題 456

Which of the following risk management principles is accomplished by purchasing cyber insurance?
  • CS0-003 試験問題 457

    An MSSP received several alerts from customer 1, which caused a missed incident response deadline for customer 2. Which of the following best describes the document that was violated?
  • CS0-003 試験問題 458

    A security analyst is reviewing the findings of the latest vulnerability report for a company's web application. The web application accepts files for a Bash script to be processed if the files match a given hash. The analyst is able to submit files to the system due to a hash collision. Which of the following should the analyst suggest to mitigate the vulnerability with the fewest changes to the current script and infrastructure?
  • CS0-003 試験問題 459

    脆弱性管理チームは、毎週のスキャンで発見されたすべての脆弱性にパッチを適用することはできません。そこで、以下に示すサードパーティのスコアリングシステムを使用し、最も緊急性の高い脆弱性にパッチを適用します。

    さらに、脆弱性管理チームは、SmearとChanningの指標は他の指標よりも重要度が低いと考えているため、優先度を下げます。上記のサードパーティスコアリングシステムを考慮すると、以下の脆弱性のうちどれを最初にパッチ適用すべきでしょうか?
  • CS0-003 試験問題 460

    An organization has a critical financial application hosted online that does not allow event logging to send to the corporate SIEM. Which of the following is the best option for the security analyst to configure to improve the efficiency of security operations?