00:00

QUESTION 106

- (Exam Topic 15)
The Chief Executive Officer (CEO) wants to implement an internal audit of the company's information security posture. The CEO wants to avoid any bias in the audit process; therefore, has assigned the Sales Director to conduct the audit. After significant interaction over a period of weeks the audit concludes that the company's policies and procedures are sufficient, robust and well established. The CEO then moves on to engage an external penetration testing company in order to showcase the organization's robust information security stance. This exercise reveals significant failings in several critical security controls and shows that the incident response processes remain undocumented. What is the MOST likely reason for this disparity in the results of the audit and the external penetration test?

Correct Answer: C

QUESTION 107

- (Exam Topic 15)
What is the FIRST step in developing a patch management plan?

Correct Answer: B

QUESTION 108

- (Exam Topic 14)
Which of the following is a characteristic of convert security testing?

Correct Answer: B

QUESTION 109

- (Exam Topic 15)
What is considered a compensating control for not having electrical surge protectors installed?

Correct Answer: D

QUESTION 110

- (Exam Topic 13)
Digital certificates used in Transport Layer Security (TLS) support which of the following?

Correct Answer: D