Which describes the correct sequence in a standard change process?
Change management runs request, impact assessment, approval, testing, implementation, verification and documentation, in that order. The other sequences implement or test before approval, which is the failure the process exists to prevent.
Question 2 of 10 · Threats, Vulnerabilities, and Mitigations
Which describes the correct response to a vulnerability that cannot be patched?
When a patch is not possible, the risk is reduced another way and the remainder is owned: compensating controls, less exposure, and a recorded acceptance with a review date. Accepting without a record, relying on detection alone, or pulling the system without analysis all skip that decision.
Question 3 of 10 · Security Architecture
Which describes data masking?
Masking hides part of a value, such as all but the last four digits, for display or non-production use. Replacing with a vaulted token is tokenization, encrypting a field is field-level encryption, and removing fields is de-identification.
Question 4 of 10 · Security Operations
Which describes the purpose of a security information and event management platform?
A SIEM collects logs from many sources, correlates them and produces alerts an analyst can act on. Perimeter prevention, vulnerability scanning and endpoint configuration are other tools' jobs.
Question 5 of 10 · Security Program Management and Oversight
What does a risk register record?
A risk register lists identified risks with an owner, an assessment, the chosen treatment, dates and status. Incidents, audit findings and scan results feed it, but each has its own record.
Question 6 of 10 · General Security Concepts
Which describes key stretching?
Key stretching runs a password through a deliberately slow derivation, such as PBKDF2, bcrypt or Argon2, so each guess costs the attacker more. It does not lengthen the key, extend its validity or split one secret into several keys.
Question 7 of 10 · Threats, Vulnerabilities, and Mitigations
What is the security purpose of segmenting internet of things devices onto their own network?
Many IoT devices cannot be patched or hardened, so the practical control is to limit what a compromised one can reach. Segmentation is a security containment measure, not a performance, addressing or power measure.
Question 8 of 10 · Security Architecture
What is the purpose of a screened subnet?
A screened subnet, formerly called a DMZ, hosts services the internet must reach, such as web or mail gateways, separately from the internal network, so a compromise there does not give direct internal access.
Question 9 of 10 · Security Operations
What is the purpose of a playbook in incident response?
A playbook gives defined steps for a specific scenario, such as ransomware or a phishing report, so responders execute a tested plan under pressure. Timelines, contact lists and lessons learned are separate incident records.
Question 10 of 10 · Security Program Management and Oversight
What is the correct treatment of a risk the business chooses not to mitigate?
A risk the business chooses not to mitigate is accepted formally by the accountable owner, recorded with an expiry date so it is reviewed. Deleting it from the register hides it; insurance is transfer, a separate decision.
0 of 10
General Security Concepts
Threats, Vulnerabilities, and Mitigations
Security Architecture
Security Operations
Security Program Management and Oversight
Which domains cost you the points? Members see a breakdown by domain and a study plan built from it.