Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 62 pages
Exam (elaborations)

D484 EXAM UPDATED QUESTIONS AND CORRECT ANSWERS.

Document preview thumbnail
Preview 4 out of 62 pages

D484 EXAM UPDATED QUESTIONS AND CORRECT ANSWERS.

Content preview

D484 EXAM UPDATED QUESTIONS AND
CORRECT ANSWERS.




A security professional is researching the latest vulnerabilities that have been released. Where
is a good resource they can go to in order to look at these?
A.CVSS
B.CVE
C.NVD

D.ISSAF - ANS C.NVD


To learn more about the vulnerabilities, you can often click on CVE names, which have
hyperlinks to the record in the National Vulnerability Database (NVD). Once there, you can read
more details.


A new penetration tester is creating a strategy for their first upcoming process and wants to
follow the standard process. What step takes place after planning?
A.Scanning
B.Recon
C.Gaining access

D.Analysis - ANS B.Recon


A marketing coordinator meets with many high-profile companies to discuss penetration
testing engagements. Which of the following is NOT something they might want to show to
ensure confidence and trust in their team?
A.Credentials


1 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED

,B.Pre-Discovered information
C.Background check

D.Clearances - ANS B.Pre-Discovered information


Penetration testing companies should never do work before entering into an agreement
including scope. This could possibly lead to prosecution.


PTES - ANS The Penetration Testing Execution Standard (PTES) has seven main sections that
provide a comprehensive overview of the proper structure of a complete PenTest. Some of the
sections include details on topics such as pre-engagement interactions, threat modeling,
vulnerability analysis, exploitation, and reporting.


ISSAF - ANS The ISSAF contains a list of 14 documents that relate to PenTesting, such as
guidelines on business continuity and disaster recovery along with legal and regulatory
compliance.


A penetration tester has been contracted to do a test for a hospital and is looking at
computerized electronic patient records. What are these referred to as?
A.HIPAA
B.e-PHI
C.CCPA

D.GDPR - ANS B.e-PHI


Computerized electronic patient records are referred to as electronic protected health
information (e-PHI). With HIPAA, the e-PHI of any patient must be protected from exposure, or
the organization can face a hefty fine.


The Health Insurance Portability and Accountability Act (HIPAA) is a law that mandates rigorous
requirements for anyone that deals with patient information.


A penetration tester is conducting a PCI DSS compliance report for a large company that does
ten million transactions a year. What level should they comply with?


2 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED

,A.1
B.2
C.3

D.4 - ANS A.1


Level 1 is a large merchant with over six million transactions a year and must have an external
auditor perform the assessment by an approved Qualified Security Assessor (QSA).
Level 2 is a merchant with one to six million transactions a year. Both levels 1 and 2 must
complete a Report on Compliance (RoC).
Level 3 is a merchant with 20,000 to one million transactions a year. Levels 2 through 4 can
either have an external auditor or submit a self-test that proves they are taking active steps to
secure the infrastructure.
Level 4 is a small merchant with under 20,000 transactions a year.


A project manager is preparing documentation that covers recurring costs and any unforeseen
additional charges that may occur during a project without the need for an additional contract.
Which of the following should they prepare?
A.SOW
B.MSA
C.SLA

D.NVD - ANS B.MSA


The Master Service Agreement (MSA) is a contract that establishes guidelines for any business
documents executed between two parties. It can be used to cover recurring costs and any
unforeseen additional charges.


SOW - ANS The Statement of Work (SOW) is a document that defines the expectations for a
specific business arrangement. It typically includes a list of deliverables, responsibilities of both
parties, and others.


A penetration test is being conducted on a financial institution. Which of the following is geared
to ensure the security and confidentiality of client information?


3 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED

, A.GLBA
B.DPPA
C.HIPAA

D.ISSAF - ANS A.GLBA


The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to ensure the security and
confidentiality of client information and take steps to keep customer information secure.


DPPA - ANS The Driver's Privacy Protection Act (DPPA) governs the privacy and disclosure of
personal information gathered by state Departments of Motor Vehicles.


A security firm is looking at expanding operations outside the United States. Which of the
following tools might require careful consideration for legal compliance due to its decryption
capabilities?
A.InterMapper
B.Nmap
C.OpenVAS

D.Wireshark - ANS D.Wireshark


Wireshark is a powerful open-source protocol analysis tool that can decrypt numerous
protocols, such as IPsec, Kerberos, and SSL/TLS. While not restricted by U.S. export regulations,
its use in countries with strict encryption import laws should be approached with caution due
to its decryption capabilities.


A project manager is reviewing the scope of a penetration test. Which of the following is least
likely to be included?
A.Location
B.Target exclusions
C.Framework

D.Tools - ANS C.Framework



4 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED

Document information

Uploaded on
October 13, 2025
Number of pages
62
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$12.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
sirjoel
3.6
(18)
Sold
133
Followers
13
Items
12780
Last sold
2 months ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions