CS0-002 Exam Question 66

An organization has the following risk mitigation policies
* Risks without compensating controls will be mitigated first it the nsk value is greater than $50,000
* Other nsk mitigation will be pnontized based on risk value.
The following risks have been identified:

Which of the following is the ordei of priority for risk mitigation from highest to lowest?
  • CS0-002 Exam Question 67

    An organization has the following vulnerability remediation policies:
    * For production environment servers:
    * Vulnerabilities with a CVSS score of 9.0 or greater must be remediated within 48 hours.
    * Vulnerabilities with a CVSS score of 5.0 to 8.9 must be remediated within 96 hours.
    * Vulnerabilities in lower environments may be left unremediated for up to two weeks.
    * All vulnerability remediations must be validated in a testing environment before they are applied in the production environment.
    The organization has two environments: production and testing. The accountingProd server is the only server that contains highly sensitive information.
    A recent vulnerability scan provided the following report:

    Which of the following identifies the server that should be patched first? (Choose Two)
  • CS0-002 Exam Question 68

    A help desk technician inadvertently sent the credentials of the company's CRM n clear text to an employee's personal email account. The technician then reset the employee's account using the appropriate process and the employee's corporate email, and notified the security team of the incident According to the incident response procedure, which of the following should the security team do NEXT?
  • CS0-002 Exam Question 69

    An incident response plan requires systems that contain critical data to be triaged first in the event of a compromise. Which of the following types of data would most likely be classified as critical?
  • CS0-002 Exam Question 70

    A company's legal and accounting teams have decided it would be more cost-effective to offload the risks of data storage to a third party. The IT management team has decided to implement a cloud model and has asked the security team for recommendations. Which of the following will allow all data to be kept on the third-party network?