
Which of the following is not a typical measure or practice implemented in a passive security strategy? (Wentz QOTD)
A. Vulnerability scanning
B. Penetration testing
C. Incident response
D. Threat hunting

Which of the following is not a typical measure or practice implemented in a passive security strategy? (Wentz QOTD)
A. Vulnerability scanning
B. Penetration testing
C. Incident response
D. Threat hunting

Which of the following is least likely to suffer from injection attacks? (Wentz QOTD)
A. A logger that supports Java Naming and Directory Interface (JNDI)
B. A database server that accepts parameterized SQL queries
C. A directory service that accepts LDAP queries
D. A web server that accepts HTTP requests

Information security is crucial to organizations in both the private and public sectors. When organizations acquire resources, which of the following is not a major organizational concern about a foreign interest that may directly or indirectly affect the supplier? (Wentz QOTD)
A. The ownership of the supplier
B. The control over the election of the supplier’s board of directors
C. The security posture of the supplier
D. The influence toward the governing body of the supplier

RSA encryption requires a longer key length to provide the same level of security as symmetric encryption. Which of the following is incorrect or least related to this fact? (Wentz QOTD)
A. RSA encryption requires more CPU cycles
B. RSA depends on prime numbers and boolean operations to encrypt data
C. RSA encryption typically encrypts plaintext of which the size is smaller than 512 bytes
D. The number of prime numbers to shape the keyspace is far less than natural numbers

You are implementing single-factor authentication. Which of the following is the least effective authentication solution? (Wentz QOTD)
A. Password
B. One-time password token
C. Fingerprint
D. Retina

When responding to an incident after the triage phase, which of the following should be conducted first? (Wentz QOTD)
A. Identify the root cause and work out a solution
B. Implement a workaround to restore the service level
C. Conduct retrospective to improve continously
D. Prioritize the incident based on importance and urgency

Your organization has a tight budget and cannot afford to hire more employees so that you have to cover the work of software development and operations. Which of the following security principles is the best to mitigate the dilemma? (Wentz QOTD)
A. M of N control
B. Separation of duties
C. Zero-knowledge proof
D. Separation of privilege

Your organization consumed cloud services provisioned by a well-known cloud service provider. Which of the following security principles best applies to the decision? (Wentz QOTD)
A. Zero Trust
B. Trust but verify
C. Separation of duties
D. Never trust, always verify

Which of the following roles determines the purposes and means of the processing of personal data? (Wentz QOTD)
A. Data owner
B. Data principal
C. Data controller
D. Data steward

Which of the following is the best artifact that directs information security programs? (Wentz QOTD)
A. Program management plan
B. Portfolio charter
C. Program policy
D. Business case