An analyst needs to scan hosts for misconfigurations and known security threats that could lead to a
security incident.
Which type of scanner will allow the analyst to check for these types of issues?
Protocol
Address
Port
Vulnerability - CORRECT ANSWERS-Vulnerability
A company is looking at different types of cloud storage options. One of the threats to cloud storage that
the company foresees is the possibility of losing forensic artifacts in the event of an incident response
investigation.
Which type of cloud storage has the highest risk of losing forensic artifacts in the event of an incident
response investigation?
File-based
Long-term
Block
Ephemeral - CORRECT ANSWERS-Ephemeral
A manager is made aware of a customer complaint about how an application developed by the company
collects personal and environmental information from the devices it is installed on.
Which document should the manager refer to in order to determine if the company has properly
disclosed information about what data it collects from this application's users?
Retention policy
Breach notification
Privacy notice
,Denial of service - CORRECT ANSWERS-Privacy notice
An organization needs to store passwords in a database securely. The data should not be available to
system administrators.
Which technique should the organization use?
Encryption
Hashing
Encoding
Masking - CORRECT ANSWERS-Hashing
A company is looking to ensure that the names of individuals in its data in the cloud are not revealed in
the event of a data breach, as the data is sensitive and classified.
Which data masking technique should the company use to prevent attackers from identifying individuals
in the event of a data breach?
Crypto-shredding
Degaussing
Anonymization
Randomization - CORRECT ANSWERS-Anonymization
An organization needs to quickly identify the document owner in a shared network folder.
Which technique should the organization use to meet this goal?
Labeling
Classification
Mapping
Categorization - CORRECT ANSWERS-Labeling
, An organization plans to introduce a new data standard and wants to ensure that system inventory data
will be efficiently discovered and processed.
Which type of data should the organization use to meet this goal?
Structured
Semi-structured
Annotated
Mapped - CORRECT ANSWERS-Structured
An organization implemented an information rights management (IRM) solution to prevent critical data
from being copied without permission and a cloud backup solution to ensure that the critical data is
protected from storage failures.
Which IRM challenge will the organization need to address?
Jurisdictional conflicts
Agent conflicts
Replication restrictions
Execution restrictions - CORRECT ANSWERS-Replication restrictions
A data center engineer is tasked with the destruction of data on solid-state drives (SSDs). The engineer
must ensure that the data is not able to be retrieved.
Which data destruction action should the engineer take to meet this goal?
Overwriting
Crypto-shredding
Wiping
Degaussing - CORRECT ANSWERS-Crypto-shredding
An organization wants to gather and interpret logs from its cloud environment.
Which system should the organization use for this task?