An organization has discovered that users are visiting unauthorized websites using anonymous proxies.
Which of the following is the BEST way to prevent future occurrences?
A. Remove the anonymity from the proxy
B. Analyze Internet Protocol (IP) traffic for proxy requests
C. Disable the proxy server on the firewall
D. Block the Internet Protocol (IP) address of known anonymous proxies
Correct Answer: C


In order to assure authenticity, which of the following are required?
A. Confidentiality and authentication
B. Confidentiality and integrity
C. Authentication and non-repudiation
D. Integrity and non-repudiation
Correct Answer: D


With what frequency should monitoring of a control occur when implementing Information Security Continuous
Monitoring (ISCM) solutions?
A. Continuously without exception for all security controls
B. Before and after each change of the control
C. At a rate concurrent with the volatility of the security control
D. Only during system implementation and decommissioning
Correct Answer: B


In the Software Development Life Cycle (SDLC), maintaining accurate hardware and software inventories is a critical
part of
A. systems integration.
B. risk management.
C. quality assurance.
D. change management.
Correct Answer: D


Which of the following types of technologies would be the MOST cost-effective method to provide a reactive control for
protecting personnel in public areas?
A. Install mantraps at the building entrances
B. Enclose the personnel entry area with polycarbonate plastic
C. Supply a duress alarm for personnel exposed to the public
D. Hire a guard to protect the public area
Correct Answer: D


Which of the following is the MOST efficient mechanism to account for all staff during a speedy nonemergency
evacuation from a large security facility?
A. Large mantrap where groups of individuals leaving are identified using facial recognition technology
B. Radio Frequency Identification (RFID) sensors worn by each employee scanned by sensors at each exitdoor
C. Emergency exits with push bars with coordinates at each exit checking off the individual against a predefined list
D. Card-activated turnstile where individuals are validated upon exit
Correct Answer: B


Which of the following is the MOST important output from a mobile application threat modeling exercise according to
Open Web Application Security Project (OWASP)?
A. Application interface entry and endpoints
B. The likelihood and impact of a vulnerability
C. Countermeasures and mitigations for vulnerabilities
D. A data flow diagram for the application and attack surface analysis
Correct Answer: D


Additional padding may be added to toe Encapsulating Security Protocol (ESP) b trailer to provide which of the
A. Access control
B. Partial traffic flow confidentiality
C. Protection against replay attack
D. Data origin authentication
Correct Answer: C


Information security metrics provide the GREATEST value tp management when based upon the security manager\\’s
knowledge of which of the following?
A. Likelihood of a security breach
B. Value of information assets
C. Cost of implementing effective controls
D. Benefits related to quantitative analysts
Correct Answer: B


Which programming methodology allows a programmer to use pre-determined blocks of code end consequently
reducing development time and programming costs?
A. Application security
B. Object oriented
C. Blocked algorithm
D. Assembly language
Correct Answer: B

Which of the following is the BEST way to verify the integrity of a software patch?
A. Cryptographic checksums
B. Version numbering
C. Automatic updates
D. Vendor assurance
Correct Answer: A


The World Trade Organization\\’s (WTO) agreement on Trade-Related Aspects of Intellectual Property Rights (TRIPS)
requires authors of computer software to be given the
A. right to refuse or permit commercial rentals.
B. right to disguise the software\\’s geographic origin.
C. ability to tailor security parameters based on location.
D. ability to confirm license authenticity of their works.
Correct Answer: A


When transmitting information over public networks, the decision to encrypt it should be based on
A. the estimated monetary value of the information.
B. whether there are transient nodes relaying the transmission.
C. the level of confidentiality of the information.
D. the volume of the information.
Correct Answer: C

