The results of an external penetration test for a software development company show a small number of applications account for the largest number of findings. While analyzing the content and purpose of the applications, the following matrix is created: The findings are then categorized according to the following chart:
Which of the following would BEST reduce the amount of immediate risk incurred by the organization from a compliance and legal standpoint? (Choose two.)
A) Place a WAF in line with Application 2
B) Move Application 3 to a secure VLAN and require employees to use a jump server for access
C) Apply the missing OS and software patches to the server hosting Application 4
D) Use network segmentation and ACLs to control access to Application 5
E) Implement an IDS/IPS on the same network segment as Application 3
F) Install a FIM on the server hosting Application 4
G) Enforce Group Policy password complexity rules on the server hosting Application 1
Correct Answer:
Verified
Q384: A security analyst receives an email from
Q385: A security administrator receives reports that several
Q386: A Chief Information Security Officer (CISO) has
Q387: A SaaS provider decides to offer data
Q388: The Chief Financial Officer (CFO) of an
Q390: A new employee is plugged into the
Q391: An organization is moving internal core data-processing
Q392: An attacker has been compromising banking institution
Q393: Designing a system in which only information
Q394: A company wants to implement a cloud-based
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents