List of questions
Related questions
Question 69 - CAS-004 discussion
A Chief information Security Officer (CISO) is developing corrective-action plans based on the following from a vulnerability scan of internal hosts:
Which of the following MOST appropriate corrective action to document for this finding?
A.
The product owner should perform a business impact assessment regarding the ability to implement a WAF.
B.
The application developer should use a static code analysis tool to ensure any application code is not vulnerable to buffer overflows.
C.
The system administrator should evaluate dependencies and perform upgrade as necessary.
D.
The security operations center should develop a custom IDS rule to prevent attacks buffer overflows against this server.
Your answer:
0 comments
Sorted by
Leave a comment first