Mark, a security manager, categorizes an information system and determines that the loss of integrity of a specific information type would impact business significantly. Based on this, he recommends the implementation of several solutions. Which of the following, when combined, would mitigate this risk?This type of question contains radio buttons and checkboxes for selection of options. Use Tab for navigation and Enter or space to select the option.optionAASLR optionBSDDoptionCValidationoptionDSandboxing
Question
Mark, a security manager, categorizes an information system and determines that the loss of integrity of a specific information type would impact business significantly. Based on this, he recommends the implementation of several solutions. Which of the following, when combined, would mitigate this risk?This type of question contains radio buttons and checkboxes for selection of options. Use Tab for navigation and Enter or space to select the option.optionAASLR optionBSDDoptionCValidationoptionDSandboxing
Solution
To mitigate the risk of significant business impact due to loss of integrity of a specific information type, Mark could combine several solutions. In this case, the combination of Address Space Layout Randomization (ASLR), Validation, and Sandboxing would be effective.
ASLR is a computer security technique which involves randomly positioning the address space locations of key data areas, typically including the base of the executable and position of libraries, heap, and stack, in a process's address space.
Validation is the process of evaluating a system or component during or at the end of the development process to determine whether it satisfies the specified requirements.
Sandboxing is a security mechanism for separating running programs to prevent software vulnerabilities from spreading. It is often used to execute untested or untrusted programs or code.
So, the options to select would be option A (ASLR), option C (Validation), and option D (Sandboxing).
Similar Questions
John works as a security manager at XYZ Inc. He has created a policy to allow employees to use their personally owned devices. He is getting reports of the company's data appearing on unapproved forums and an increase in the theft of personal electronic devices. Which of the following security controls would he implement to reduce the risk of exposure?This type of question contains radio buttons and checkboxes for selection of options. Use Tab for navigation and Enter or space to select the option.optionANone of theseoptionBParity checkingoptionCImplementation of S/MIMEoptionDDisk encryption on the local drive
Joseph, a security administrator, wants to monitor and make alterations on specific file changes to determine the possibility of system compromise. Which of the following will he use to check for integrity in the given scenario?This type of question contains radio buttons and checkboxes for selection of options. Use Tab for navigation and Enter or space to select the option.optionATripwireoptionBwifiphisheroptionCaircrack-ngoptionDEttercap
Which security technology could you use to protect against enumeration on services?This type of question contains radio buttons and checkboxes for selection of options. Use Tab for navigation and Enter or space to select the option.optionAEDRoptionBAnti‐malwareoptionCIDSoptionDHost‐based firewall
c) Prepare a list of 4 recommended solutions/controls that would reduce the risk of security breach to Octal Info Solutions. 1.Conduct Regular Employee Training Malicious hackers gain access to your database by using phishing emails sent to the employees. Phishing emails are very difficult to detect because they seem like a legitimate one. Having regular cybersecurity training can prevent or reduce threats. 2. Encrypt Your Data and Create Backups The organization must make sure to encrypt all sensitive data and save encrypted data can make attacker difficult to access. It can ensure that even when unauthorized parties gain access to the system data, they can't read it. When cybersecurity breaches can result in data loss. And if you don’t have any secure or reliable data backup, it can cause your organization to lose a lot of revenue. 3.Create A Secure Cybersecurity Policy Create cybersecurity in the organization such as restricted data or information can be accessed and available only authorized people. So, it can reduce the insider threats in the organization. 4.Using strong password If the employees use strong or not sharing password, it can reduce the threats. If one computer is under attacked, the other will be secure. The password should be implemented such as at least 8 characters, alphanumeric characters, no personal information, unique and never used before. d) Prepare an implementation plan (for each solution) in a procedurally organized manner to ensure minimum risk of security breach in line with organizational guidelines.
Jacob, a security administrator, wants to protect an organization against an SQL injection attack. Which of the following controls will he implement?Each correct answer represents a complete solution. Choose all that apply.This type of question contains radio buttons and checkboxes for selection of options. Use Tab for navigation and Enter or space to select the option.Aoption AIntrusion detection systemBoption BWeb application firewallCoption CParameterized queriesDoption DInput validation
Upgrade your grade with Knowee
Get personalized homework help. Review tough concepts in more detail, or go deeper into your topic by exploring other relevant questions.