Which of the following provides for continuous improvement of the change control process?
Which of the following factors typically would distort a sales forecast that is based solely on shipment history?
An organization has been the subject of increasingly sophisticated phishing campaigns in recent months and has detected unauthorized access attempts against its Virtual Private Network (VPN) concentrators. Which of the following implementations would have the GREATEST impact on reducing the risk of credential compromise?
An example of a flexibility metric for an organization Is:
What is the MOST beneficial principle of threat modeling?
Which of the following techniques is BEST suited to preserve the confidentiality of a system’s data?
Which of the following statements about demonstrated capacity Is true?
An organization has decided to leverage open source software for its latest application development project. Which of the following would be the MOST effective way to ensure the open source software can be used securely while still meeting business requirements?
The production plan defines which of the following targets?
Which of the following does a federated Identity Provider (IDP) need in order to grant access to identity information?
Which of the following incorporates design techniques promoted by Crime Prevention Through Environmental Design (CPTED)?
In a lean environment, the batch-size decision for planning " A " items would be done by:
A security analyst modifies the organization’s baselines to align the controls more closely with specific security and privacy requirements. Which security concept is this an example of?
Based on the above table, calculate the mean absolute deviation (MAD).
A vendor has been awarded a contract to supply key business software. The vendor has declined all requests to have its security controls audited by customers. The organization insists the product must go live within 30 days. However, the security team is reluctant to allow the project to go live.
What is the organization ' s BEST next step?
Health information stored in paper form may be destroyed using which of the following methods?
Open Authorized (OAuth) has been chosen as technology to use across applications in the enterprise. Which of the following statements is TRUE about an OAuth token?
An organization’s computer incident responses team PRIMARY responds to which type of control?
An organizations is developing a new software package for a financial institution. What is the FIRST step when modeling threats to this new software package?
An organization is implementing Zero Trust Network Access (ZTNA) and needs a strategy to measure device trust for employee laptops. Which measurement strategy is BEST suited and why?
Disaster Recovery (DR) training plan outcomes should have which KEY quality?
After a recent threat modeling workshop, the organization has requested that the Chief Information Security Officer (CISO) implement zero trust (ZT) policies. What was the MOST likely threat identified in the workshop?
The time spent In queue by a specific manufacturing job is determined by which of the following factors related to the order?
A firm that currently produces all items to stock is implementing the concept of postponement in all new product designs. Which of the following outcomes is most likely to result?
A security consultant is working with an organization to help evaluate a proposal received from a new managed security service provider. There are questions about the confidentiality and effectiveness of the provider ' s system over a period of time. Which of the following System And Organization Controls (SOC) report types should the consultant request from the provider?
Once an organization has identified and properly classified their information and data assets, policies and procedures are created to establish requirements for the handling, protection, retention, and disposal of those assets. Which solution is the BEST method to enforce data usage policies, discover sensitive data, monitor the use of sensitive data, and ensure regulatory compliance and intellectual property protection?
An organization has determined that it needs to retain customer records for at least thirty years to discover generational trends in customer behavior. However, relevant local regulation requires that all Personally Identifiable Information (PII) is deleted after expiration of the customer ' s engagement with the organization, which is usually no longer than one year. How should the data be handled at the expiration of customer engagement at one year?
A manufacturer has a primary assembly line supported by output from several subassembly lines. Which of the following scenarios would be the best argument for a multilevel master scheduling process?
Which of the following represents the level of confidence that software is free from intentional an accidental vulnerabilities?
Which of the following is the MOST important consideration in a full-scale disaster recovery test?
Which of the following BEST describes an individual modifying something the individual is not supposed to?
What are the FIRST two steps an organization should conduct to classify its assets?
A security practitioner has been asked to investigate the presence of customer Personally Identifiable Information (PII) on a social media website. Where does the practitioner begin?
A customer of a financial Institution denies that a transaction occurred. Which of the following is used to provide evidence evidence that the customer performed the transaction?
Which of the following ensures privileges are current and appropriately reflect an individual’s authorized roles and responsibilities?
During a manual source code review, an organization discovered a dependency with an open-source library that has a history of being exploited. Which action should the organization take FIRST to assess the risk of depending on the open-source library?
An organization is aiming to be System and Organization Controls (SOC) 2 certified by an audit organization to demonstrate its security and availability maturity to its sub service organizations. Which type of audit does this engagement BEST describe?
While doing a penetration test, auditors found an old credential hash for a privileged user. To prevent a privileged user ' s hash from being cached, what is the MOST appropriate policy to mandate?
Which of the following is a disadvantage of using federated identity?
A manufacturer begins production of an item when a customer order is placed. This is an example of a(n):
Which of the following should be done FIRST when implementing an Identity And Management (IAM) solution?
What is the BEST preventive measure against employees abusing access privileges?
If all other factors remain the same, when finished goods inventory investment is increased, service levels typically will:
Following the setting of an organization’s risk appetite by senior management, a risk manager needs to prioritize all identified risks for treatment. Each risk has been scored based on its Annualized Loss Expectancy (ALE). Management has asked for an immediate risk mitigation plan focusing on top risks. Which is the MOST effective approach for the risk manager to quickly present a proposal to management?
Capacity requirements planning (CRP) is applicable primarily In companies operating In an environment where:
Global outsourcing and shared suppliers serving an industry are drivers of which category of risk?
Which of the following regarding authentication protocols is a PRIMARY consideration when designing an authentication and key management system?
A department manager executes threat modeling at the beginning of a project and throughout its lifecycle. What type of threat modeling is being performed?
An advertising agency is working on a campaign for a prospective client. Competitors are working on a similar campaign and are interested in knowing what the firm has designed. What should the advertising agency do to BEST ensure intellectual property does not leave the organization?
What is the PRIMARY benefit an organization obtains by adapting a cybersecurity framework to their cybersecurity program?
An organization wishes to utilize a managed Domain Name System (DNS) provider to reduce the risk of users accessing known malicious sites when web browsing. The organization operates DNS forwarders that forward queries for all external domains to the DNS provider. Which of the following techniques could enable the organization to identify client systems that have attempted to access known malicious domains?
The costs provided in the table below are associated with buying a quantity larger than immediately needed. What Is the total landed cost based on this table?
Cost CategoryCost
Custom fees$125
Freight$700
Warehouse rent$200
Matenal cost$500
Which of the following stock location systems would you use in a repetitive manufacturing, lean environment?
An organization’s computer incident response team PRIMARILY responds to which type of control?
To ensure the quality of its newly developed software, an organization is aiming to deploy an automated testing tool that validates the source code. What type of testing BEST supports this capability?
Which of the following techniques would a group use to prioritize problems?
The Chief Information Security Officer (CISO) defined a requirement to install a network security solution that will have the ability to inspect and block data flowing over network in real time. What network deployment scenario will be MOST suitable?
A large organization wants to implement a vulnerability management system in its internal network. A security professional has been hired to set up a vulnerability scanner on premises and to execute the scans periodically. Which of the following should be the FIRST action performed by the security professional?
A champion is assigned to lead a threat modeling exercise. Which of the following will be the FIRST thing to consider?
A security engineer is reviewing Incident Response (IR) roles and responsibilities. Several roles have static elevated privileges in case an incident occurs. Instead of static access, what is the BEST access method to manage elevated privileges?
Which of the following statements best characterizes enterprise resources planning (ERP) systems?
An organization is migrating some of its applications to the cloud. The Chief Information Security Officer (CISO) is concerned about the accuracy of the reports showing which application should be migrated and how many applications reside on each server. As a result, the CISO is looking to establish asset management requirements. Which of these elements should be considered part of asset management requirements?
A security engineer is implementing a Supervisory Control and Data Acquisition (SCADA) system.
What is the BEST action the engineer can take to ensure secure operations?
Which of the following actions hinders the transition from a push system to a pull system?
What is the MOST likely cause for a penetration tester having difficulties finding the stack to inject code?
According to best practice, at which step in the system lifecycle shall a security professional begin involvement?
Which of the following demand management approaches tends to be most subjective?
When the discrete available-to-promise (ATP) method is used, the master production receipt quantity is committed to:
Which of the following is MOST important for an international retail company to consider when handling and retaining information about its customers?
A security engineer is implementing an authentication system for a new web application. The authentication requirements include the ability for a server to authenticate the client and for the client to authenticate the server. Which of the following choices BEST supports this requirement?
Which of the following are steps involved in the identity and access provisioning lifecycle?
In pyramid forecasting, the " roll up " process begins with:
Which of the following categories of web services testing describes correctness testing of web service security functionality?
A software organization is getting ready to launch a new application. A security engineer notices the application allows unrestricted access to files on the web server. Which of the following recommendations will BEST resolve this security issue?
Which of the following are compromised in an untrusted network using public key cryptography when a digitally signed message is modified without being detected?
An organization has identified that an individual has failed to adhere to a given standard set by the organization. Based on the needs of the organization, it was decided that an exception process will be created. What is the PRIMARY benefit of establishing an exception process?
An organization decides to conduct penetration testing. Senior management is concerned about the potential loss of information through data exfiltration. The organization is currently preparing a major product launch that is time-sensitive. Which of the following methods of testing is MOST appropriate?
A low-cost provider strategy works best when which of the following conditions are met?
A security analyst has been asked to build a data retention policy for a hospital. What is the FIRST action that needs to be performed in building this policy?
A manufacturing facility uses common wireless technologies to communicate. The head of security is concerned about eavesdropping by attackers outside the perimeter fence. The distance between the facility and fence is at least 300 feet (100 m). Which of the following wireless technologies is MOST likely to be available to an attacker outside the fence?
When assessing a new vendor as a possible business partner, what would BEST demonstrate that the vendor has a proactive approach to data security compliance?
A company can easily change Its workforce, but inventory carrying costs are high. Which of the following strategies would be most appropriate during times of highly fluctuating demand?
What is the PRIMARY benefit an organization obtains by cybersecurity framework to their cybersecurity program?
A company with stable demand that uses exponential smoothing to forecast demand would typically use a:
The question below is based on the following alternative schedules for a lot of 1,200.
A company works 8-hour, single-shift days. Setups are 4 hours for Operation 20 and 4 hours for Operation 40. Each operation has multiple machines available.
Which of the following statements is correct?
During a security incident investigation, a security analyst discovered an unauthorized module was compiled into an application package as part of the application assembly phase. This incident occurred immediately prior to being digitally signed and deployed using a deployment pipeline.
Which of the following security controls would BEST prevent this type of incident in the future?
A stockout of dependent-demand item X occurred during the holiday season. To understand the root cause of the stockout, the planner should check if:
An example of a cradle-to-cradle sustainability model would be:
An independent risk assessment determined that a hospital ' s existing policies did not have a formal process in place to address system misuse, abuse, or fraudulent activity by internal users. Which of the following would BEST address this deficiency in the Corrective Action Plan?
A product manager wishes to store sensitive development data using a cloud storage vendor while maintaining exclusive control over passwords and encryption credentials. What is the BEST method for meeting these requirements?
What is the process when a security assessor compiles potential targets from the attacker’s perspective, such as data flows, and interactions with users?
An organization has hired a consultant to establish their Identity and Access Management (IAM) system. One of the consultant’s main priorities will be to understand the current state and establish visibility across the environment. How can the consultant start to establish an IAM governance process?
Which of the following systems would be the most cost-efficient for inventory management of a low value item?
Which Open Systems Interconnection (OSI) layer is concerned with Denial-Of-Service (DoS) SYN flood attacks?
A large retail organization will be creating new Application Programming Interfaces (API) as part of a customer-facing shopping solution. The solution will accept information from users both inside and outside of the organization. What is the safest software development practice the team can follow to protect the APIs against Structured Query Language Injection (SQLi) attacks?
In choosing suppliers, a company wishes to maintain maximum leverage to reduce costs. Which of the following supply chain strategies would provide this opportunity?
A webmaster has repeatedly used the same certificate sign request to renew an organization ' s website Secure Sockets Layer (SSL) certificate. What is the MOST significant increased risk for the organization?
An organization ' s security policy requires sensitive information to be protected when being transmitted to external sources via would be the BEST security solution to choose?
Before securing a email system using OpenPGP in an organization, Which of the following actions MUST be performed?
Which of the following items does the master scheduler have the authority to change in the master scheduling process?
An organization has hired a new auditor to review its critical systems infrastructure for vulnerabilities. Which of the following BEST describes the methodology the auditor will use to test whether servers are set up according to the organization ' s documented policies and standards?
What is the BEST item to consider when designing security for information systems?
Who is responsible for ensuring compliance when an organization uses a cloud provider to host its Virtual Machine (VM) instances?
Which of the following methods places a replenishment order when the quantity on hand falls below a predetermined level?
Corporate fraud has historically been difficult to detect. Which of the following methods has been the MOST helpful in unmasking embezzlement?
Which of the following controls should a financial Institution have in place in order to prevent a trader from both entering and executing a trade?
During an investigation, a forensic analyst executed a task to allow for the authentication of all documents, data, and objects collected, if required. Which of the options below BEST describes this task?
A cybersecurity analyst is responsible for identifying potential security threats and vulnerabilities in the organization ' s software systems. Which action BEST demonstrates the understanding and application of threat modeling concepts and methodologies?
Cloud computing introduces the concept of the shared responsibility model. This model can MOST accurately be described as defining shared responsibility between which of the following?
An organization is running a cloud-based application to process the information obtained at point-of-sale devices. Which guideline should be applied to the application?
An organization provides customer call center operations for major financial services organizations around the world. As part of a long-term strategy, the organization plans to add healthcare clients to the portfolio. In preparation for contract negotiations with new clients, to which cybersecurity framework(s) should the security team ensure the organization adhere?
Which of the following is PRIMARILY responsible for deciding the classification of data in an organization?
Risk pooling would work best for items with:
In which of the following phases of the product life cycle is product price most effective in influencing demand?
A security engineer has determined the need to implement preventative controls into their Wireless Local Area Network (WLAN) for added protection. Which preventative control provides the MOST security?
An organization experienced multiple compromises of endpoints, leading to breaches of systems and data. In updating its strategy to defend against these threats, which of the following BEST considers the organization’s needs?
The results of a threat campaign show a high risk of potential intrusion. Which of the following parameters of the Common Vulnerability Scoring System (CVSS) will MOST likely provide information on threat conditions for the organization to consider?
Increased use of third-party logistics (3PL) services is likely to have which of the following effects on a firm ' s balance sheet?
A large volume of outbound Transmission Control Protocol (TCP) connections from the same source Internet Protocol (IP) address was observed at a satellite office firewall. Which of the following is the MOST likely explanation?
Which of the following is typically used to control physical access to highly secure facilities?
Which of the physiological biometric scanning methods is considered the MOST invasive?
What is an important countermeasure to consider when hardening network devices and servers to reduce the effectiveness of unauthorized network scanning?
Marketing has requested a significant change in the mix for a product family. The requested change falls between the demand and the planning time fences. The most appropriate action by the master scheduler is to:
An organization is retiring an old server out of the data center. This server was used to store and process sensitive information. The server is being sent off-site to a recycling center. Which declassification method should be performed prior to it being sent off-site?
Which protocol is the BEST option to provide authentication, confidentiality, and data integrity between two applications?
A warehouse manager assigns orders to warehouse personnel grouped by where the goods are stored. This type of picking is called a(n):
A systems engineer has been tasked by management to provide a recommendation with a prioritized, focused set of actions to help the organization stop high-risk cyber attacks and ensure data security. What should the systems engineer recommend the organization use to accomplish this?
Which of the below represent the GREATEST cloud-specific policy and organizational risk?
An audit of antivirus server reports shows a number of workstations do not have current signatures installed. The organization security standard requires all systems to have current antivirus signatures. What distinct part of the audit finding did the auditor fail to include?
Which of the following planes directs the flow of data within a Software-Defined Networking (SDN) architecture?
Given the bill of material (BOM) information below and independent requirements of 10 pieces (pcs) per week of Component A and 20 pieces (pcs) per week of Component B, what is the weekly gross requirement of component F?

Which of the following is an information security management framework?
Zombieload, Meltdown, Spectre, and Fallout are all names of bugs that utilized which of the following types of attack?
When implementing a data classification program, Which is MOST important for measuring businesss impact?
Which of the following is the workflow of the identity and access provisioning lifecycle?
The most effective way to manage demand uncertainty and improve customer service is to reduce:
Which of the following strategies is most appropriate for a business unit with a low relative market share in a high-growth market?
The project manager for a new application development is building a test framework. It has been agreed that the framework will Include penetration testing; however, the project manager is keen to identify any flaws prior to the code being ready for execution. Which of the following techniques BEST supports this requirement?
An organization is attempting to address the security risk introduced by employees writing down door entry passcodes. Which of the following security measures BEST mitigates this risk?
Which of the following is the BEST solution to implement to mitigate the risk of data breach in the event of a lost or stolen mobile device?
Information regarding a major new customer is received from sales. The company ' s most appropriate initial response would be to adjust the:
An organization donates used computer equipment to a non-profit group. A system administrator used a degausser on both the magnetic and Solid State Drives (SSD) before delivery. A volunteer at the non-profit group discovered some of the drives still contained readable data and alerted the system administrator. What is the BEST solution to ensure that computer equipment does not contain data before release?
An organization’s system engineer arranged a meeting with the system owner and a few major stakeholders to finalize the feasibility analysis for a new application.
Which of the following topics will MOST likely be on the agenda?
Which of the following is a document that will be obtained at the end of an asset’s lifecycle?
Which of the following BEST represents a security benefit of Software-Defined Networking (SDN)?
Which of the following security techniques can be used to ensure the integrity of software as well as determine who developed the software?
In restoring the entire corporate email system after a major outage and data loss, an email administrator reads a few email message exchanges between the human resources manager and a candidate for an open position. Which of the following BEST describes the behavior of the email administrator, and why?
An organization currently has a network with 55,000 unique Internet Protocol (IP) addresses in their private Internet Protocol version 4 (IPv4) network range and has acquired another organization and must integrate their 25,000 endpoints with the existing, flat network topology. If subnetting is not implemented, which network class is implied for the organization ' s resulting private network segment?
Which of the following represents the BEST metric when measuring the effectiveness of a security awareness program?
The horizon for forecasts that are input to the sales and operations planning (S & OP) process should be long enough that:
What is the MOST effective way to begin a risk assessment?
Which of the following factors is the MOST important consideration for a security team when determining whether cryptographic erasure can be used for disposal of a device?
Check sheets can be used to:
A security engineer must address resource sharing between various applications without adding physical hardware to the environment. Which secure design principle is used to BEST segregate applications?
A forecasting method that responds slowly to changes in demand would be most appropriate when the historical demand pattern shows a:
In which of the following circumstances is an organization MOST likely to report the accidental release of personal data to the European Union (EU) General Data Protection Regulation (GDPR) supervisory authority and affected users?
Broadcast traffic is causing network performance degradation of sensitive equipment.
Which of the following methods is used to prevent the broadcast traffic from impacting availability?
What can help a security professional assess and mitigate vulnerabilities of an embedded device?
An agency has the requirement to establish a direct data connection with another organization for the purpose of exchanging data between the agency and organization systems. There is a requirement for a formal agreement between the agency and organization. Which source of standards can the system owners use to define the roles and responsibilities along with details for the technical and security requirements?
An infrastructure team is setting up a wireless network for employees at a new location of the organization that is located near a very busy city transport hub. Which should be the MOST important antenna consideration with regard to securing the wireless network for the infrastructure team?
Which of the following tactics can be employed effectively to reduce appraisal quality costs?
Which of the following is the MOST effective approach to reduce the threat of rogue devices being introduced to the internal network?
Which of the following is the BEST type of fire extinguisher for a data center environment?
A company selling seasonal products is preparing their sales and operations plan for the coming year. Their current labor staffing is at the maximum for their production facility and cannot meet the forecasted demand. The business plan shows they do not have the financial capability to add to the production facility. Which of the following actions would be most appropriate?
Which of the following security features is utilized to validate both user credentials and the health of the client device on a network?
A company’s Marketing and Sales departments have identified an opportunity to develop a new market for a product family and requested an increase in the production plan. Which of the following actions would be most appropriate to account for the new market opportunity?
A United States (US)-based online gaming provider, which operates in Germany, collects and uses a large amount of user behavioral data. A customer from Germany requests a copy of all their personal data.
What is the MOST appropriate course of action for the organization to take?
A lengthy power outage led to unavailability of time critical services resulting in considerable losses. It was determined that a backup electrical generator did not work as intended at the time of the incident due to lack of fuel. What should the security consultant FIRST Investigate?
A company confirms a customer order based on available capacity and inventory, even though the current production plan does not cover the entire order quantity. This situation is an example of what type of order fulfillment policy?
A company has the following production conditions:
Batch size: 1,000 items
Processing time: 4 minutes per item
Setup time: 2 hours
Utilization: 80%
Efficiency: 80%
Which of the following actions would result in the work being done in the least amount of time?
In which of the following situations would you use an X-bar chart?
A security professional is accessing an organization-issued laptop using biometrics to remotely log into a network resource. Which type of authentication method is described in this scenario?
A company ' s primary performance objective Is flexibility. Which of the following measurements is most important?
While conducting an information asset audit, it was determined that several devices were running unpatched Operating Systems (0S). Further review Indicated the OS was no longer supported by the vendor. Which of the following BEST indicates the appropriate asset lifecycle stage of the devices?
The primary outcome of frequent replenishments in a distribution requirements planning (DRP) system is that:
Which of the following outcomes Is a benefit of mixed-model scheduling?
Which of the following benefits typically will be realized when switching from a functional to a cellular layout?
Which of the following BEST describes the responsibility of an information System Security Officer?
Privacy requirements across national boundaries MOST often require protection of which data types?
Which security audit phase is MOST important to ensure correct controls are applied to classified data in a production environment?