SlideShare a Scribd company logo
1 of 2
Download to read offline
Latest Version: 47.0
Question: 1
Which of the following is the MOST relevant security check to be performed before embedding third-
parry libraries in developed code?
A. Check to see if the third party has resources to create dedicated development and staging
environments.
B. Verify the number of companies that downloaded the third-party code and the number of
contributions on the code repository.
C. Assess existing vulnerabilities affecting the third-parry code and the remediation efficiency of the
libraries' developers.
D. Read multiple penetration-testing reports for environments running software that reused the library.
Answer: C
Question: 2
The Chief Information Security Officer (CISO) has requested that a third-party vendor provide supporting
documents that show proper controls are in place to protect customer data. Which of the following
would be BEST for the third-party vendor to provide to the CISO?
A. GDPR compliance attestation
B. Cloud Security Alliance materials
C. SOC 2 Type 2 report
D. NIST RMF workbooks
Answer: C
Question: 3
A recent audit cited a risk involving numerous low-criticality vulnerabilities created by a web application
using a third-party library. The development staff state there are still customers using the application
even though it is end of life and it would be a substantial burden to update the application for
compatibility with more secure libraries. Which of the following would be the MOST prudent course of
action?
A. Accept the risk if there is a clear road map for timely decommission
B. Deny the risk due to the end-of-life status of the application.
C. Use containerization to segment the application from other applications to eliminate the risk
D. Outsource the application to a third-party developer group
Answer: C
Question: 4
Which of the following documents provides expectations at a technical level for quality, availability, and
responsibilities?
A. EOL
B. SLA
C. MOU
D. EOSL
Answer: B
Question: 5
A security analyst is receiving numerous alerts reporting that the response time of an internet-facing
application has been degraded However, the internal network performance was not degraded. Which
of the following MOST likely explains this behavior?
A. DNS poisoning
B. MAC flooding
C. DDoS attack
D. ARP poisoning
Answer: C

More Related Content

More from shirlybaker1

Take An Advantage Of Top PCAP-31-03 Exam Questions.pdf
Take An Advantage Of Top PCAP-31-03 Exam Questions.pdfTake An Advantage Of Top PCAP-31-03 Exam Questions.pdf
Take An Advantage Of Top PCAP-31-03 Exam Questions.pdfshirlybaker1
 
Substantial HP HPE6-A68 Exam Preparation Material.pdf
Substantial HP HPE6-A68 Exam Preparation Material.pdfSubstantial HP HPE6-A68 Exam Preparation Material.pdf
Substantial HP HPE6-A68 Exam Preparation Material.pdfshirlybaker1
 
AZ-204 A Top-Notch Exam Of Developing Solutions for Microsoft Azure.pdf
AZ-204 A Top-Notch Exam Of Developing Solutions for Microsoft Azure.pdfAZ-204 A Top-Notch Exam Of Developing Solutions for Microsoft Azure.pdf
AZ-204 A Top-Notch Exam Of Developing Solutions for Microsoft Azure.pdfshirlybaker1
 
PSE-STRATA Exam Questions For New PSE-STRATA Exam PDF.pdf
PSE-STRATA Exam Questions For New PSE-STRATA Exam PDF.pdfPSE-STRATA Exam Questions For New PSE-STRATA Exam PDF.pdf
PSE-STRATA Exam Questions For New PSE-STRATA Exam PDF.pdfshirlybaker1
 
Upgrade Your Preparation With Fortinet NSE7_EFW-6.4 Dumps.pdf
Upgrade Your Preparation With Fortinet NSE7_EFW-6.4 Dumps.pdfUpgrade Your Preparation With Fortinet NSE7_EFW-6.4 Dumps.pdf
Upgrade Your Preparation With Fortinet NSE7_EFW-6.4 Dumps.pdfshirlybaker1
 
Juniper JN0-250 Sample Questions With 100% Guarantee.pdf
Juniper JN0-250 Sample Questions With 100% Guarantee.pdfJuniper JN0-250 Sample Questions With 100% Guarantee.pdf
Juniper JN0-250 Sample Questions With 100% Guarantee.pdfshirlybaker1
 
Substantial Microsoft AZ-800 Exam Preparation Material.pdf
Substantial Microsoft AZ-800 Exam Preparation Material.pdfSubstantial Microsoft AZ-800 Exam Preparation Material.pdf
Substantial Microsoft AZ-800 Exam Preparation Material.pdfshirlybaker1
 
Assess CAS-004 Study Material For Comptia Exam.pdf
Assess CAS-004 Study Material For Comptia Exam.pdfAssess CAS-004 Study Material For Comptia Exam.pdf
Assess CAS-004 Study Material For Comptia Exam.pdfshirlybaker1
 
How To Complete NSE8_811 Dumps Questions Preparation.pdf
How To Complete NSE8_811 Dumps Questions Preparation.pdfHow To Complete NSE8_811 Dumps Questions Preparation.pdf
How To Complete NSE8_811 Dumps Questions Preparation.pdfshirlybaker1
 
Assess NS0-403 Study Material For NetApp Exam.pdf
Assess NS0-403 Study Material For NetApp Exam.pdfAssess NS0-403 Study Material For NetApp Exam.pdf
Assess NS0-403 Study Material For NetApp Exam.pdfshirlybaker1
 
Get PEOPLECERT ITIL-4-Foundation Sample Questions And Answers.pdf
Get PEOPLECERT ITIL-4-Foundation Sample Questions And Answers.pdfGet PEOPLECERT ITIL-4-Foundation Sample Questions And Answers.pdf
Get PEOPLECERT ITIL-4-Foundation Sample Questions And Answers.pdfshirlybaker1
 
Could it be said that you are Worried About CISA Exam Study Material.pdf
Could it be said that you are Worried About CISA Exam Study Material.pdfCould it be said that you are Worried About CISA Exam Study Material.pdf
Could it be said that you are Worried About CISA Exam Study Material.pdfshirlybaker1
 
Explore CIPP-E Ample Questions & Updated Answers.pdf
Explore CIPP-E Ample Questions & Updated Answers.pdfExplore CIPP-E Ample Questions & Updated Answers.pdf
Explore CIPP-E Ample Questions & Updated Answers.pdfshirlybaker1
 
Further develop Your CAS-004 Dumps By Using The Study Kit.pdf
Further develop Your CAS-004 Dumps By Using The Study Kit.pdfFurther develop Your CAS-004 Dumps By Using The Study Kit.pdf
Further develop Your CAS-004 Dumps By Using The Study Kit.pdfshirlybaker1
 
Pass AZ-104 Exam With Microsoft Azure Administrator Exam.pdf
Pass AZ-104 Exam With Microsoft Azure Administrator Exam.pdfPass AZ-104 Exam With Microsoft Azure Administrator Exam.pdf
Pass AZ-104 Exam With Microsoft Azure Administrator Exam.pdfshirlybaker1
 
Top Updated 350-901 Exam Questions And Answer.pdf
Top Updated 350-901 Exam Questions And Answer.pdfTop Updated 350-901 Exam Questions And Answer.pdf
Top Updated 350-901 Exam Questions And Answer.pdfshirlybaker1
 
Latest Products Of Cisco 350-401 Certification Dumps.pdf
Latest Products Of Cisco 350-401 Certification Dumps.pdfLatest Products Of Cisco 350-401 Certification Dumps.pdf
Latest Products Of Cisco 350-401 Certification Dumps.pdfshirlybaker1
 
Benefit 300-810 Exam Training Kit With Updated Demo.pdf
Benefit 300-810 Exam Training Kit With Updated Demo.pdfBenefit 300-810 Exam Training Kit With Updated Demo.pdf
Benefit 300-810 Exam Training Kit With Updated Demo.pdfshirlybaker1
 
Pass NSE5_FCT-7.0 Dumps With Updated NSE5_FCT-7.0 Exam Topics.pdf
Pass NSE5_FCT-7.0 Dumps With Updated NSE5_FCT-7.0 Exam Topics.pdfPass NSE5_FCT-7.0 Dumps With Updated NSE5_FCT-7.0 Exam Topics.pdf
Pass NSE5_FCT-7.0 Dumps With Updated NSE5_FCT-7.0 Exam Topics.pdfshirlybaker1
 
Get ADM-201 Practice Test For Salesforce Certified Administrator (SP22).pdf
Get ADM-201 Practice Test For Salesforce Certified Administrator (SP22).pdfGet ADM-201 Practice Test For Salesforce Certified Administrator (SP22).pdf
Get ADM-201 Practice Test For Salesforce Certified Administrator (SP22).pdfshirlybaker1
 

More from shirlybaker1 (20)

Take An Advantage Of Top PCAP-31-03 Exam Questions.pdf
Take An Advantage Of Top PCAP-31-03 Exam Questions.pdfTake An Advantage Of Top PCAP-31-03 Exam Questions.pdf
Take An Advantage Of Top PCAP-31-03 Exam Questions.pdf
 
Substantial HP HPE6-A68 Exam Preparation Material.pdf
Substantial HP HPE6-A68 Exam Preparation Material.pdfSubstantial HP HPE6-A68 Exam Preparation Material.pdf
Substantial HP HPE6-A68 Exam Preparation Material.pdf
 
AZ-204 A Top-Notch Exam Of Developing Solutions for Microsoft Azure.pdf
AZ-204 A Top-Notch Exam Of Developing Solutions for Microsoft Azure.pdfAZ-204 A Top-Notch Exam Of Developing Solutions for Microsoft Azure.pdf
AZ-204 A Top-Notch Exam Of Developing Solutions for Microsoft Azure.pdf
 
PSE-STRATA Exam Questions For New PSE-STRATA Exam PDF.pdf
PSE-STRATA Exam Questions For New PSE-STRATA Exam PDF.pdfPSE-STRATA Exam Questions For New PSE-STRATA Exam PDF.pdf
PSE-STRATA Exam Questions For New PSE-STRATA Exam PDF.pdf
 
Upgrade Your Preparation With Fortinet NSE7_EFW-6.4 Dumps.pdf
Upgrade Your Preparation With Fortinet NSE7_EFW-6.4 Dumps.pdfUpgrade Your Preparation With Fortinet NSE7_EFW-6.4 Dumps.pdf
Upgrade Your Preparation With Fortinet NSE7_EFW-6.4 Dumps.pdf
 
Juniper JN0-250 Sample Questions With 100% Guarantee.pdf
Juniper JN0-250 Sample Questions With 100% Guarantee.pdfJuniper JN0-250 Sample Questions With 100% Guarantee.pdf
Juniper JN0-250 Sample Questions With 100% Guarantee.pdf
 
Substantial Microsoft AZ-800 Exam Preparation Material.pdf
Substantial Microsoft AZ-800 Exam Preparation Material.pdfSubstantial Microsoft AZ-800 Exam Preparation Material.pdf
Substantial Microsoft AZ-800 Exam Preparation Material.pdf
 
Assess CAS-004 Study Material For Comptia Exam.pdf
Assess CAS-004 Study Material For Comptia Exam.pdfAssess CAS-004 Study Material For Comptia Exam.pdf
Assess CAS-004 Study Material For Comptia Exam.pdf
 
How To Complete NSE8_811 Dumps Questions Preparation.pdf
How To Complete NSE8_811 Dumps Questions Preparation.pdfHow To Complete NSE8_811 Dumps Questions Preparation.pdf
How To Complete NSE8_811 Dumps Questions Preparation.pdf
 
Assess NS0-403 Study Material For NetApp Exam.pdf
Assess NS0-403 Study Material For NetApp Exam.pdfAssess NS0-403 Study Material For NetApp Exam.pdf
Assess NS0-403 Study Material For NetApp Exam.pdf
 
Get PEOPLECERT ITIL-4-Foundation Sample Questions And Answers.pdf
Get PEOPLECERT ITIL-4-Foundation Sample Questions And Answers.pdfGet PEOPLECERT ITIL-4-Foundation Sample Questions And Answers.pdf
Get PEOPLECERT ITIL-4-Foundation Sample Questions And Answers.pdf
 
Could it be said that you are Worried About CISA Exam Study Material.pdf
Could it be said that you are Worried About CISA Exam Study Material.pdfCould it be said that you are Worried About CISA Exam Study Material.pdf
Could it be said that you are Worried About CISA Exam Study Material.pdf
 
Explore CIPP-E Ample Questions & Updated Answers.pdf
Explore CIPP-E Ample Questions & Updated Answers.pdfExplore CIPP-E Ample Questions & Updated Answers.pdf
Explore CIPP-E Ample Questions & Updated Answers.pdf
 
Further develop Your CAS-004 Dumps By Using The Study Kit.pdf
Further develop Your CAS-004 Dumps By Using The Study Kit.pdfFurther develop Your CAS-004 Dumps By Using The Study Kit.pdf
Further develop Your CAS-004 Dumps By Using The Study Kit.pdf
 
Pass AZ-104 Exam With Microsoft Azure Administrator Exam.pdf
Pass AZ-104 Exam With Microsoft Azure Administrator Exam.pdfPass AZ-104 Exam With Microsoft Azure Administrator Exam.pdf
Pass AZ-104 Exam With Microsoft Azure Administrator Exam.pdf
 
Top Updated 350-901 Exam Questions And Answer.pdf
Top Updated 350-901 Exam Questions And Answer.pdfTop Updated 350-901 Exam Questions And Answer.pdf
Top Updated 350-901 Exam Questions And Answer.pdf
 
Latest Products Of Cisco 350-401 Certification Dumps.pdf
Latest Products Of Cisco 350-401 Certification Dumps.pdfLatest Products Of Cisco 350-401 Certification Dumps.pdf
Latest Products Of Cisco 350-401 Certification Dumps.pdf
 
Benefit 300-810 Exam Training Kit With Updated Demo.pdf
Benefit 300-810 Exam Training Kit With Updated Demo.pdfBenefit 300-810 Exam Training Kit With Updated Demo.pdf
Benefit 300-810 Exam Training Kit With Updated Demo.pdf
 
Pass NSE5_FCT-7.0 Dumps With Updated NSE5_FCT-7.0 Exam Topics.pdf
Pass NSE5_FCT-7.0 Dumps With Updated NSE5_FCT-7.0 Exam Topics.pdfPass NSE5_FCT-7.0 Dumps With Updated NSE5_FCT-7.0 Exam Topics.pdf
Pass NSE5_FCT-7.0 Dumps With Updated NSE5_FCT-7.0 Exam Topics.pdf
 
Get ADM-201 Practice Test For Salesforce Certified Administrator (SP22).pdf
Get ADM-201 Practice Test For Salesforce Certified Administrator (SP22).pdfGet ADM-201 Practice Test For Salesforce Certified Administrator (SP22).pdf
Get ADM-201 Practice Test For Salesforce Certified Administrator (SP22).pdf
 

Latest CompTIA SY0-601 Exam Dumps Questions And Answer.pdf

  • 1. Latest Version: 47.0 Question: 1 Which of the following is the MOST relevant security check to be performed before embedding third- parry libraries in developed code? A. Check to see if the third party has resources to create dedicated development and staging environments. B. Verify the number of companies that downloaded the third-party code and the number of contributions on the code repository. C. Assess existing vulnerabilities affecting the third-parry code and the remediation efficiency of the libraries' developers. D. Read multiple penetration-testing reports for environments running software that reused the library. Answer: C Question: 2 The Chief Information Security Officer (CISO) has requested that a third-party vendor provide supporting documents that show proper controls are in place to protect customer data. Which of the following would be BEST for the third-party vendor to provide to the CISO? A. GDPR compliance attestation B. Cloud Security Alliance materials C. SOC 2 Type 2 report D. NIST RMF workbooks Answer: C Question: 3 A recent audit cited a risk involving numerous low-criticality vulnerabilities created by a web application using a third-party library. The development staff state there are still customers using the application even though it is end of life and it would be a substantial burden to update the application for compatibility with more secure libraries. Which of the following would be the MOST prudent course of action? A. Accept the risk if there is a clear road map for timely decommission B. Deny the risk due to the end-of-life status of the application. C. Use containerization to segment the application from other applications to eliminate the risk
  • 2. D. Outsource the application to a third-party developer group Answer: C Question: 4 Which of the following documents provides expectations at a technical level for quality, availability, and responsibilities? A. EOL B. SLA C. MOU D. EOSL Answer: B Question: 5 A security analyst is receiving numerous alerts reporting that the response time of an internet-facing application has been degraded However, the internal network performance was not degraded. Which of the following MOST likely explains this behavior? A. DNS poisoning B. MAC flooding C. DDoS attack D. ARP poisoning Answer: C