EXAM QUESTIONS WITH CORRECT
VERIFIED SOLUTIONS||A+
GRADED!!!<<UPDATED 2025-
2026>>
1. Which type of management focuses on arranging all the elements needed
to deploy new software, including QA testing and staging, before the
software enters active maintenance?
Availability management (AM)
Release management (RM)
Incident management (IM)
Problem management (PM) - ANSWER ✓ Release management (RM)
2. A security analyst is tasked with collecting evidence related to a data
breach involving monetary theft.
Which action should the security analyst take when accessing the breached
system?
Create an unencrypted backup of all data
Create an encrypted backup of all data
Detail and replicate all activities taken
Document and record all activities taken - ANSWER ✓ Document and record all
activities taken
3. During an investigation, government agents asked a security professional to
collect the records stored in a database and present them to the court.
Which process should the security professional use to identify and obtain
that information?
,Electronic communication
Error correcting code (ECC) memory
Cyclic redundancy check (CRC)
Electronic discovery - ANSWER ✓ Electronic discovery
4. The service at a cloud provider has been interrupted.
Which group should this cloud provider contact with information about the
expected window for which the services will be down as per a contractual
agreement?
Customers
Regulators
Executives
Employees - ANSWER ✓ Customers
5. An online store has declared a disaster situation because of a large storm in
the area of its primary cloud data center location. The emergency plan has
allowed the store to remain online and accept payments, but it has fallen
out of compliance with its Payment Card Industry Data Security Standard
(PCI DSS) practices.
Which party should the store keep apprised of ongoing developments and
the potential solutions being considered?
Customers
Developers
Consumers
Regulators - ANSWER ✓ Regulators
6. Which type of communication channel should be established between
parties in a supply chain to be used in a disaster situation?
Back
Landline
Satellite
Secondary - ANSWER ✓ Secondary
, 7. An organization's engineers recently attended a training session designed
to raise awareness of the dangers of using insecure direct object identifiers
to view another user's account information.
Which Open Web Application Security Project (OWASP) Top 10 vulnerability
category did their training cover?
Vulnerable and outdated components
Identification and authentication failures
Broken access control
Security logging failures - ANSWER ✓ Broken access control
8. An organization's engineers recently attended a training session that raised
their awareness of the dangers of using weak algorithms or protocols for
data security.
Which Open Web Application Security Project (OWASP) Top 10 vulnerability
category did their training cover?
Insecure design
Hashing
Sandboxing
Cryptographic failures - ANSWER ✓ Cryptographic failures
9. A company plans to deploy a new application. Before the deployment, the
company hires an IT security consultant to perform a zero-knowledge test
to access the application as an external hacker would.
Which testing technique applies to the work the consultant is performing?
Black box
White box
Abuse case
Static application - ANSWER ✓ Black box
10.Which concept refers to multiple teams and roles within an organization
that perform testing on code from end to end to ensure that the code
meets all standards and requirements?
Quality assurance