Pre-Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Certified in Planning and Inventory Management (CPIM 8.0) Question and Answers

Certified in Planning and Inventory Management (CPIM 8.0)

Last Update May 31, 2026
Total Questions : 606

We are offering FREE CPIM-8.0 APICS exam questions. All you do is to just go and sign up. Give your details, prepare CPIM-8.0 free exam questions and then go for complete pool of Certified in Planning and Inventory Management (CPIM 8.0) test questions that will help you more.

CPIM-8.0 pdf

CPIM-8.0 PDF

$36.75  $104.99
CPIM-8.0 Engine

CPIM-8.0 Testing Engine

$43.75  $124.99
CPIM-8.0 PDF + Engine

CPIM-8.0 PDF + Testing Engine

$57.75  $164.99
Questions 1

The question below is based on the following information:

Work Center 1 has an available capacity of 1,200 hours per month. Which of the following amounts represents the cumulative difference between the required capacity and the available capacity of Months 1 through 3?

Options:

A.  

50

B.  

150

C.  

1.250

D.  

3.750

Discussion 0
Questions 2

A large organization wants to implement a vulnerability management system in its internal network. A security professional has been hired to set up a vulnerability scanner on premises and to execute the scans periodically. Which of the following should be the FIRST action performed by the security professional?

Options:

A.  

Configure internal firewalls to accept and pass all scanner traffic and responses

B.  

Execute a vulnerability scan to determine the current organization security posture

C.  

Select two different vulnerability scanners to get comprehensive reporting

D.  

Obtain support from the computing systems ' stakeholders

Discussion 0
Questions 3

The demand for an item has increasing forecast error, whereas all other factors remain constant. Which of the following remains constant while maintaining the same customer service level?

Options:

A.  

Reorder point(ROP)

B.  

Safety stock

C.  

Inventory investment

D.  

Safety factor

Discussion 0
Questions 4

In which cloud computing model is Identify And Access Management (IAM) the responsibility of a service provider?

Options:

A.  

Software As A Service (SaaS).

B.  

Platform As A Service (PaaS).

C.  

Desktop As A Service (DaaS).

D.  

Infrastructure As A Service (IaaS).

Discussion 0
Questions 5

An organization is implementing improvements to secure the Software Development Life Cycle (SDLC). When should defensive three modeling occur?

Options:

A.  

Standards review

B.  

Static Application Security Testing (SAST)

C.  

Design and requirements gathering

D.  

Dynamic Application Security Testing (DAST)

Discussion 0
Questions 6

An organization has been the subject of increasingly sophisticated phishing campaigns in recent months and has detected unauthorized access attempts against its Virtual Private Network (VPN) concentrators. Which of the following implementations would have the GREATEST impact on reducing the risk of credential compromise?

Options:

A.  

Increasing the network password complexity requirements

B.  

Implementing tougher encryption on the VPN

C.  

Implementing Multi-Factor Authentication (MFA)

D.  

Implementing advanced endpoint protection on user endpoints

Discussion 0
Questions 7

Which of the following data is needed to determine gross requirements when conducting distribution requirements planning (DRP)?

Options:

A.  

Order value

B.  

Location points

C.  

Shipping schedules

D.  

Interplant demand

Discussion 0
Questions 8

Which of the following methods places a replenishment order when the quantity on hand falls below a predetermined level?

Options:

A.  

Min-max system

B.  

Fixed order quantity

C.  

Periodic review

D.  

Available-to-promlse (ATP)

Discussion 0
Questions 9

An infrastructure team is setting up a wireless network for employees at a new location of the organization that is located near a very busy city transport hub. Which should be the MOST important antenna consideration with regard to securing the wireless network for the infrastructure team?

Options:

A.  

Network ' s Service Set Identifier (SSID) visibility and vulnerabilities are not cast out too far.

B.  

Parabolic antenna is used for signal convergence.

C.  

Network efficiently allows maximum channel separation.

D.  

Implement Wired Equivalent Privacy (WEP) encryption.

Discussion 0
Questions 10

In which of the following situations would you use an X-bar chart?

Options:

A.  

Track the number of defects that are found in each unit.

B.  

Measure the difference between the largest and the smallest in a sample.

C.  

Determine the average value of a group of units.

D.  

Estimate a subgroup variation.

Discussion 0
Questions 11

An appropriate performance measure for sales and operations planning (S & OP) would be the variance between:

Options:

A.  

The forecasted and actual demand

B.  

The actual and planned raw material level

C.  

The demand plan and the production plan

D.  

The production plan and the master production schedule (MPS)

Discussion 0
Questions 12

An organization implemented a threat modeling program focusing on key assets. However, after a short time it became clear that the organization was having difficulty executing the threat modeling program.

Which approach will MOST likely have been easier to execute?

Options:

A.  

System-centric approach

B.  

Attacker-centric approach

C.  

Asset-centric approach

D.  

Developer-centric approach

Discussion 0
Questions 13

Which of the following Internet Protocol Security (IPSec) components provides the MOST confidentiality for the information that is being transmitted?

Options:

A.  

Authentication Header (AH)

B.  

Generic Routing Encapsulation (GRE)

C.  

Encapsulation Security Payload

D.  

Internet Key Exchange (IKE)

Discussion 0
Questions 14

The question below is based on the following standard and actual data of a production order

Which of the following statements about variances is true?

Options:

A.  

The material price vanance for Component A is favorable by S10

B.  

The labor pnce variance is unfavorable by S20

C.  

The material usage variance for Component B is favorable by $36

D.  

The labor efficiency variance is favorable by S20

Discussion 0
Questions 15

An organization wants to implement Zero Trust (ZT). The Information Technology (IT) department is already using Multi-Factor Authentication (MFA) and Identity and Access Management (IAM). Which of the following would be the BEST solution for the organization to implement in order to have a ZT network?

Options:

A.  

Next-generation firewall

B.  

Host-Based Intrusion Detection System (HIDS)

C.  

Micro-segmentation

D.  

Network Intrusion Detection System (NIDS)

Discussion 0
Questions 16

In the context of mobile device security, which of the following BEST describes why a walled garden should be implemented?

Options:

A.  

To track user actions and activity

B.  

To prevent the installation of untrusted software

C.  

To restrict a user ' s ability to change device settings

D.  

To limit web access to only approved sites

Discussion 0
Questions 17

The Business Continuity Plan (BCP) has multiple components. The information security plan portion must prioritize its efforts. Which 3 aspects of information security MUST be prioritized?

Options:

A.  

Confidentiality, integrity, availability

B.  

Physical security, access control, asset protection

C.  

Intent, capability, opportunity

D.  

Threat level, network security, information disposal

Discussion 0
Questions 18

An agency has the requirement to establish a direct data connection with another organization for the purpose of exchanging data between the agency and organization systems. There is a requirement for a formal agreement between the agency and organization. Which source of standards can the system owners use to define the roles and responsibilities along with details for the technical and security requirements?

Options:

A.  

International Organization For Standardization (ISO)

B.  

European Committee for Electrotechnical Standardization

C.  

Caribbean Community Regional Organization for Standards and Quality

D.  

Institute of Electrical and Electronics Engineers (IEEE)

Discussion 0
Questions 19

An organization is opening a new data center and is looking for a facilities security officer to provide best practices for the site and facility design. The two major requirements for this organization are not to attract undue attention and avoid proximity to potentially hazardous sites.

What site selection considerations do these requirements BEST fall under when deciding on the location for a facility?

Options:

A.  

Visibility and natural disasters

B.  

Visibility and locale

C.  

Visibility and hazardous sites

D.  

Visibility and transportation

Discussion 0
Questions 20

Which of the following categories of web services testing describes correctness testing of web service security functionality?

Options:

A.  

Focuses on ensuring that security operations performed by a web service meets its stated requirements

B.  

Generally includes threat modeling, requirements risk analysis, and security modeling

C.  

Ensures that individual protocol implementations adhere to the relevant published standards

D.  

Focuses on the smallest unit of the web service application, apart from the rest of the application

Discussion 0
Questions 21

An organization is planning to streamline its Identity and Access Management (IAM) processes and platform. The executive team mandated a compact platform to efficiently manage identities for internal and third-party services access. What is the BEST platform choice?

Options:

A.  

Cloud Single Sign-On (SSO)

B.  

On-premise IAM

C.  

Cloud IAM

D.  

Identity as a Service (IDaaS)

Discussion 0
Questions 22

Which security concept states that a subject (user, application, or asset) be given only the access needed to complete a task?

Options:

A.  

Discretionary Access Control (DAC)

B.  

Principle of least privilege

C.  

Need to know

D.  

Role-Based Access Control (RBAC)

Discussion 0
Questions 23

An example of a flexibility metric for an organization Is:

Options:

A.  

average batch size.

B.  

scrap rate.

C.  

percentageof orders delivered late.

D.  

cycle time.

Discussion 0
Questions 24

One of the benefits of Integrating a poka-yoke into the production process is that it can be used to:

Options:

A.  

facilitate mixed-model scheduling.

B.  

prevent defects.

C.  

Improve machine utilization.

D.  

enable one-piece flow.

Discussion 0
Questions 25

Which of the following MUST be in place for security to be effective in an organization?

Options:

A.  

Security objectives are documented and in line with the organization’s mission and goals.

B.  

Security policies are in line with international standards.

C.  

Technology strategy decisions have the involvement and approval of the security organization.

D.  

Risk assessments on business plans include security issues as part of the analysis.

Discussion 0
Questions 26

What is the MAIN benefit of network segmentation?

Options:

A.  

Limiting data transfer

B.  

Limiting cyberattack damage

C.  

Limiting privilege access

D.  

Limiting network addresses

Discussion 0
Questions 27

Which Open Systems Interconnection (OSI) layer is concerned with Denial-Of-Service (DoS) SYN flood attacks?

Options:

A.  

Data

B.  

Physical

C.  

Network

D.  

Transport

Discussion 0
Questions 28

What is the MOST effective way to begin a risk assessment?

Options:

A.  

Reviewing the policy, objectives, mandate, and commitment to manage risk

B.  

Learning the organization ' s ability to accept and/or manage risks

C.  

Identifying the resources available to manage risks within the organization

D.  

Identifying the nature of the risks faced by the organization

Discussion 0
Questions 29

What can help a security professional assess and mitigate vulnerabilities of an embedded device?

Options:

A.  

Conduct black-box testing.

B.  

Conduct red-box testing.

C.  

Conduct yellow-box testing.

D.  

Conduct green-box testing.

Discussion 0
Questions 30

Which of the following is a methodology for threat modeling in application?

Options:

A.  

Disaster, Reproducibility, Exploitability, Affected Users, And Discoverability (DREAD)

B.  

Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege (STRIDE)

C.  

Pretend, Allow, Crash, Modify, Ascertain, Name

D.  

Confidentiality, Authentication, Integrity, Nonrepudiation, Availability

Discussion 0
Questions 31

An organization has received the results of their network security risk assessment. What is the BEST course of action for the organization to take in response to the analyzed report findings?

Options:

A.  

Hire a security consulting firm with specialized expertise to fix all the issues on the report and ensure the organization’s system are secure.

B.  

Work with the organization’s legal team to ensure their cyber liability insurance policy will fully cover the costs of any breach related to the network risk assessment findings.

C.  

Create an organizational risk response team and assign them the task of remediating all the issues or identifying and implementing compensating controls.

D.  

Accept the risk of the issues within the organization’s risk tolerance and identify responses for the remainder of the issues.

Discussion 0
Questions 32

A recent email-based malware breakout caused a significant volume of traffic and password spam account lockouts for an organization. Which BEST identifies compromised devices?

Options:

A.  

Security Information And Event Management (SIEM)

B.  

Network Intrusion Detection System (NIDS)

C.  

Vulnerability scan

D.  

Penetration test

Discussion 0
Questions 33

An attacker wants to decrypt a message and has no knowledge of what may have been in the original message. The attacker chooses to use an attack that will exhaust the keyspace in order to decrypt the message. What type of cryptanalytic attack is the attacker using?

Options:

A.  

Ciphertext only

B.  

Chosen ciphertext

C.  

Brute force

D.  

Known plaintext

Discussion 0
Questions 34

A company is having trouble with raw material deliveries and has decided to develop a supplier certification program. The certification process most appropriately would start with which of the following suppliers?

Options:

A.  

Suppliers of " A“ classified items

B.  

Suppliers recently ISO 9000 certified

C.  

Suppliers with the worst performance records

D.  

Suppliers with vendor-managed inventory (VMI)

Discussion 0
Questions 35

When starting an external benchmarking study, a firm must first:

Options:

A.  

determine the metrics which will be measured and compared.

B.  

identify the target firms with which to benchmark against.

C.  

understand its own processes and document performance.

D.  

determine its areas of weakness versus the competition ' s.

Discussion 0
Questions 36

Which technology is BEST suited to establish a secure communications link between an individual’s home office and the organization’s Local Area Network (LAN)?

Options:

A.  

Switched Port Analyzer (SPAN)

B.  

Representational State Transfer (REST)

C.  

Remote Desktop Protocol (RDP)

D.  

Virtual Private Network (VPN)

Discussion 0
Questions 37

An organization’s external auditors have issued a management letter identifying significant deficiencies related to the effectiveness of the previous year’s global access certification. The organization wants to move from a department-based access control system to a Role-Based Access Control (RBAC) system. In addition to quickly and securely provisioning users by granting membership into predefined and approved roles, which of these presents the BEST reason to do so?

Options:

A.  

The organization can implement both mandatory and dynamic access controls, except where they would be in conflict.

B.  

The organization can clone roles, saving time and granting broad access to persons within the same department.

C.  

The organization can give a person holding multiple roles the appropriate levels of access to specific data for each role.

D.  

The organization can implement both static and dynamic access controls, adjusting them to fit any individual’s access needs.

Discussion 0
Questions 38

Which of the following statements is true about total productive maintenance (TPM)?

Options:

A.  

It uses statistical tools.

B.  

It is part of the business strategy.

C.  

It influences the product design process.

D.  

It minimizes unscheduled breakdowns.

Discussion 0
Questions 39

The Data Loss Prevention (DLP) team in a major financial institution discovered network traffic that involved movement of sensitive material to a Cloud Service Provider (CSP). What action should be taken FIRST in this situation?

Options:

A.  

Contact the CSP to validate data access controls in the cloud.

B.  

Contact the network security team to block the traffic.

C.  

Contact the Identity And Access Management (IAM) team to remove the user from the network.

D.  

Contact the data owner to confirm the transfer was authorized.

Discussion 0
Questions 40

Which of the following capabilities BEST distinguishes a Next-Generation Firewall (NGFW) from a traditional firewall?

Options:

A.  

Ensures incoming and outgoing packets are inspected before they are allowed to pass through

B.  

Offers features such as integrated intrusion prevention or application awareness and control

C.  

Provides security when users traverse public networks such as the Internet

D.  

Provides stateless and stateful inspection of incoming and outgoing network traffic

Discussion 0
Questions 41

Which of the following is PRIMARILY responsible for deciding the classification of data in an organization?

Options:

A.  

Data owner/steward

B.  

Authorizing Official (AO)

C.  

Chief Information Security Officer (CISO)

D.  

Data custodian

Discussion 0
Questions 42

Which of the following provides that redundancy and failover capabilities are built into a system to maximize its uptime?

Options:

A.  

Offsite backup

B.  

High availability

C.  

Diverse routing

D.  

System mirroring

Discussion 0
Questions 43

Which of the following BEST describes web service security conformance testing as it relates to web services security testing?

Options:

A.  

Generally includes threat modeling, requirements risk analysis, and security modeling

B.  

Focused on ensuring that the security functionally performed by a web service meets its stated requirements

C.  

Ensure individual protocol implementations adhere to the relevant published standards

D.  

Focused on the smallest unit of the web service application, apart from the rest of the application

Discussion 0
Questions 44

What MUST be completed before developing physical security controls?

Options:

A.  

Develop a comprehensive security policy

B.  

Provide the annual security awareness training

C.  

Contract for licensed and bonded security force

D.  

Perform a physical security audit

Discussion 0
Questions 45

A security engineer is implementing an authentication system for a new web application. The authentication requirements include the ability for a server to authenticate the client and for the client to authenticate the server. Which of the following choices BEST supports this requirement?

Options:

A.  

Secure Shell (SSH)

B.  

Trusted Platform Module (TPM)

C.  

Virtual Private Network (VPN)

D.  

Transport Layer Security (TLS)

Discussion 0
Questions 46

Which of the following measurements indicates there may be bias In the forecast model?

Options:

A.  

Mean absolute deviation (MAD)

B.  

Standard deviation

C.  

Tracking signal

D.  

Variance

Discussion 0
Questions 47

A hot Disaster Recovery (DR) data center is the victim of a data breach. The hackers are able to access and copy 10GB of clear text confidential information. Which of the following could have decreased the amount of exposure from this data breach?

Options:

A.  

Encryption in transit

B.  

Layer 7 filtering

C.  

Encryption at rest

D.  

Password hashing

Discussion 0
Questions 48

Which of the below represents the GREATEST cloud-specific policy and organizational risk?

Options:

A.  

Supply chain failure

B.  

Loss of business reputation due to co-tenant activities

C.  

Loss of governance between the client and cloud provider

D.  

Cloud service termination or failure

Discussion 0
Questions 49

Disaster Recovery (DR) training plan outcomes should have which KEY quality?

Options:

A.  

Comprehensible

B.  

Identifiable

C.  

Measurable

D.  

Editable

Discussion 0
Questions 50

Organization A provides scalable Information Technology (IT) infrastructure while Organization B provides security services to customers via Software as a Service (SaaS) model. Which document is used to express a set of intended actions between the organizations with respect to meeting the customers’ needs?

Options:

A.  

Business partnership agreement

B.  

Interconnection Security Agreement (ISA)

C.  

Framework partnership agreement

D.  

Memorandum of Understanding (MOU)

Discussion 0
Questions 51

A team is tasked with developing new email encryption software. To ensure security, what will be the PRIMARY focus during the initial phase of development?

Options:

A.  

Ensuring compliance with international data protection and privacy laws for email communication

B.  

Implementing strong encryption algorithms to ensure the confidentiality of the emails

C.  

Developing a robust user authentication system to prevent unauthorized access to the software

D.  

Defining clear software requirements for security and identifying potential threats and risks to the software

Discussion 0
Questions 52

Which of the following MUST be checked during the validation of software verification capabilities?

Options:

A.  

Security

B.  

Completeness

C.  

Vulnerabilities

D.  

Logic

Discussion 0
Questions 53

A failure mode and effects analysis (FMEA) could be used for which of the following activities?

Options:

A.  

Forecasting the estimated warranty costs for the annual budget cycle

B.  

Calculating the lost productivity from unplanned equipment downtime

C.  

Determining the critical-to-quality (CTQ) characteristics for a new product design

D.  

Assessing the supply chain risk for a single-sourced raw material

Discussion 0
Questions 54

A third-party vendor is procured to conduct a non-financial audit. Which report evaluates the effectiveness of the controls?

Options:

A.  

Statement of Auditing Standards (SAS) 70

B.  

System ad Organization Controls (SOC) 1

C.  

System ad Organization Controls (SOC) 2

D.  

System ad Organization Controls (SOC) 3

Discussion 0
Questions 55

A work center has 3 machines that are all run at the same time with a single worker. The work center has an efficiency of 75% and a utilization of 100%. What is the work center ' s capacity in standard hours for an 8-hour shift?

Options:

A.  

6 hours

B.  

8 hours

C.  

18 hours

D.  

24 hours

Discussion 0
Questions 56

A security team leader needs to communicate the value of the security program. As the security team leader determines the return on security investments, what is the MOST important aspect to incorporate?

Options:

A.  

Annualized loss reduction measured over time

B.  

Assessment of magnitude based on risk analyses

C.  

Added economic value

D.  

Total cost of ownership

Discussion 0
Questions 57

An organization has identified that an individual has failed to adhere to a given standard set by the organization. Based on the needs of the organization, it was decided that an exception process will be created. What is the PRIMARY benefit of establishing an exception process?

Options:

A.  

Prevent future material audit findings.

B.  

Provide administrators with more autonomy.

C.  

Enable management of organizational risk.

D.  

Ensure better Business Continuity (BC).

Discussion 0
Questions 58

A furniture manufacturer using material requirements planning (MRP) and lean manufacturing has changed the bills of material (BOMs) for all chests by making drawers into phantom assemblies. Which of the following outcomes would likely result from this change?

Options:

A.  

An increased number of receipts and issues for subassemblies

B.  

An increased number of production order feedback transactions

C.  

A reduced number of production orders planned by MRP

D.  

An inability to process orders for replacement drawers

Discussion 0
Questions 59

The security department was notified about vulnerabilities regarding users ' identity verification in a web application. Which of the following vulnerabilities is the security professional MOST likely to test?

Options:

A.  

Exposure of sensitive information

B.  

Use of hard-coded passwords

C.  

Trust boundary violation

D.  

Improper authentication

Discussion 0
Questions 60

An increase in work-in-process (WIP) inventory levels results in:

Options:

A.  

Shorter setup time

B.  

Smaller batch sizes

C.  

Longer throughput time

D.  

More accurate due dates

Discussion 0
Questions 61

Which of the following statements correctly describes the relationship between the strategic plan and the business plan?

Options:

A.  

These are two names for the same plan.

B.  

The strategic plan constrains the business plan.

C.  

The two plans are developed independently.

D.  

The two plans are the output of a single process.

Discussion 0
Questions 62

In order for an organization to mature their data governance processes to ensure compliance, they have created a data classification matrix.

What are the next BEST activities to build on this completed work?

Options:

A.  

Ensure the data owners agree with the classification of their data and then socialize the matrix with employees handling data.

B.  

Ensure the internal legal team approves the data classification matrix then perform a Business Impact Analysis (BIA) to understand the impact of applying the classifications.

C.  

Complete a Privacy Impact Assessment (PIA) and use the results to identify improvements to the data classification matrix.

D.  

Document the handling procedures for each classification of data in the matrix and schedule data handling educational sessions with employees.

Discussion 0
Questions 63

Which of the following conditions is most likely to result in planned production that is greater than the total demand over the sales and operations planning (S & OP) horizon for a product family that is

made to stock?

Options:

A.  

An increase in the customer service level is planned for the product family.

B.  

New models are being added to the product family.

C.  

Planned ending inventory for the product family is less than the beginning inventory.

D.  

There is a long-term upward trend in demand for the product family.

Discussion 0
Questions 64

A healthcare organization is preparing an exercise test plan of its Disaster Recovery Plan (DRP) for the Electronic Medical Record (EMR) application. The Business Continuity (BC) analyst is reviewing the requirements of the DRP. The EMR must provide basic charting services within 4 hours, must not lose more than 15 minutes of data, and must be fully functional within 12 hours. At the completion of the exercise, the analyst is preparing a lessons learned report and notes that the EMR was available after 3 hours and 25 minutes of data was lost. Which PRIMARY requirement needs to be addressed because of the exercise?

Options:

A.  

Maximum Tolerable Downtime (MTD)

B.  

Recovery Point Objective (RPO)

C.  

Recovery Time Objective (RTO)

D.  

Mean Time to Recovery (MTTR)

Discussion 0
Questions 65

Which of the following incorporates design techniques promoted by Crime Prevention Through Environmental Design (CPTED)?

Options:

A.  

Capacity of residents to act individually should be increased.

B.  

Landscape design features should be used to create the impression of a fortress.

C.  

Multiple entrances and exits should be used to keep traffic flowing smoothly through the facility.

D.  

Communal areas with amenities should be created to encourage activity and use.

Discussion 0
Questions 66

Capacity requirements planning (CRP) is applicable primarily In companies operating In an environment where:

Options:

A.  

backlog is very low.

B.  

the status of work orders is disregarded.

C.  

lean principles are used.

D.  

material requirements planning (MRP) is used.

Discussion 0
Questions 67

A Generic Routing Encapsulation (GRE) tunnel moves data across a third-party Internet Protocol (IP) network. What is the risk of using GRE tunnels?

Options:

A.  

They are proprietary and incompatible between vendors.

B.  

They can be complex to configure.

C.  

They do not provide any authentication or encryption protection.

D.  

They are unreliable due to high protocol overhead.

Discussion 0
Questions 68

The time spent In queue by a specific manufacturing job is determined by which of the following factors related to the order?

Options:

A.  

Lot size

B.  

Priority

C.  

Setup time

D.  

Run time

Discussion 0
Questions 69

A multinational organization acquires a subsidiary. The acquisition results in the need to integrate a large population of new users into the organization ' s corporate cloud. What is the MAIN benefit of the organization ' s Federated Identity Management (FIM) system to address the need?

Options:

A.  

Efficient access provisioning

B.  

Increased robustness of authentication

C.  

Greater flexibility of access control

D.  

Reduced complexity of maintenance and changes

Discussion 0
Questions 70

What is a malicious activity that overwhelms a Wireless Access Point (WAP)?

Options:

A.  

Identification spoofing

B.  

Signal jamming

C.  

Pin attack

D.  

War driving

Discussion 0
Questions 71

A new organization building is being designed and the security manager has been asked for input on needed security requirements. Which of the following controls are MOST applicable to this scenario?

Options:

A.  

Deterrent controls, such as signs announcing video cameras and alarms, are installed.

B.  

Preventative controls, such as Intrusion Detection Systems (IDS) and security guards, are used.

C.  

Preventative controls, such as Intrusion Detection Systems (IDS) and mechanical locks, are used.

D.  

Deterrent controls, such as signs announcing video cameras and alarms, are installed.

Discussion 0
Questions 72

The primary consideration In maintenance, repair, and operating (MRO) supply systems typically is:

Options:

A.  

order quantity.

B.  

stockout costs.

C.  

carrying costs.

D.  

shelf life.

Discussion 0
Questions 73

An organization has decided to give decommissioned computers to a school in a developing country. The company data handling policy prohibits the storage of confidential and sensitive data. What would be the BEST technique to use to avoid data remanence, and to minimize the operational burden for the inheriting school?

Options:

A.  

Overwriting the hard disk drive of the computers

B.  

Encrypting the hard disk drive of the computers

C.  

Removing and physically destroying the hard disk drive of the computers

D.  

Degaussing the hard disk drive of the computers

Discussion 0
Questions 74

Access Control Lists (ACL), protection bits, and file passwords are typical examples of which of the following access control methods?

Options:

A.  

Discretionary.

B.  

Attribute-based.

C.  

Mandatory.

D.  

Role-based.

Discussion 0
Questions 75

An organization ' s security policy requires sensitive information to be protected when being transmitted to external sources via would be the BEST security solution to choose?

Options:

A.  

Use spam filters and anti-virus software to send emails externally.

B.  

Configure digital signatures to send emails externally.

C.  

Configure the system to utilize to send encrypted emails externally.

D.  

Use e-mail security gateway to send emails externally.

Discussion 0
Questions 76

Which of the following BEST defines whether an organization can consider an alternate location during a contingency?

Options:

A.  

Verify the availability of an office location for the given size of the team

B.  

Verify that there is a contractual obligation for location-providing services

C.  

Verify the availability of cheap resources in the new location

D.  

Verify that a memorandum of understanding (MOU) is in place for office equipment

Discussion 0
Questions 77

A newly hired Chief Information Security Officer (CISO) is now responsible to build a third-party assurance for their organization. When assessing a third-party, which of the following questions needs to be answered?

Options:

A.  

How many employees the third-party employs?

B.  

Which level of support does the third-party provide related to security?

C.  

What is the monetary value of the third-party contract?

D.  

To which standards does the third-party need to be assessed?

Discussion 0
Questions 78

What is the MOST beneficial principle of threat modeling?

Options:

A.  

To focus on specific adversaries, assets, or techniques

B.  

To improve the security and privacy of a system through early and frequent analysis

C.  

To create meaningful outcomes when they are of value to external agencies

D.  

To create a single threat model representation as multiple models may be inconsistent

Discussion 0
Questions 79

Improvements in an Input/output control (I/O control) system will most likely lead to:

Options:

A.  

flattened bills of material (BOMs).

B.  

a change in operation sequencing.

C.  

reduction in queue size and queue time.

D.  

fewer engineering change notifications.

Discussion 0
Questions 80

An information security professional has been tasked with remediating vulnerabilities identified during a recent penetration test. Which of the following sections of the penetration results report would be MOST preferable to remediate hosts one at a time?

Options:

A.  

Findings by host, with associated vulnerabilities

B.  

Findings by vulnerabilities, with associated hosts

C.  

Appendix of definitions

D.  

Executive summary

Discussion 0
Questions 81

After a recent cybersecurity incident, a manufacturing organization is interested in further hardening its Identity and Access Management (IAM) solution. Knowing that the organization limits the use of personal devices in the facility, which could BEST be implemented to enhance the manufacturing organization ' s IAM solution?

Options:

A.  

Enhanced background checks

B.  

Mobile Multi-Factor Authentication (MFA) application

C.  

Biometric system

D.  

Personal Identification Number (PIN) code

Discussion 0
Questions 82

During an onsite audit, an assessor inspected an organization’s asset decommission practice. Which of the following would MOST likely be a finding from a security point of view?

Options:

A.  

Solid State Drives (SSD) were degaussed along with hard drives.

B.  

The Non-Disclosure Agreement (NDA) between the organization and its data disposal service was more than 3 years old.

C.  

Hard drives from older assets replaced defective hard drives from current assets of similar classification levels.

D.  

Data classifications were not clearly identified.

Discussion 0
Questions 83

Which of the following regarding authentication protocols is a PRIMARY consideration when designing an authentication and key management system?

Options:

A.  

Refresh

B.  

Visibility

C.  

Authorization

D.  

Integrity

Discussion 0
Questions 84

Which of the following MUST exist for an activity to be considered an audit?

Options:

A.  

An auditor that is in no way employed, connected or associated to the organization being audited

B.  

Stored Personally Identifiable Information (PII) that an organization has a legal obligation to protect

C.  

A predefined standard and systematic approach to test the application of that standard

D.  

A certified member of a professional body qualified in the area of inspection

Discussion 0
Questions 85

To ensure the quality of its newly developed software, an organization is aiming to deploy an automated testing tool that validates the source code. What type of testing BEST supports this capability?

Options:

A.  

Network vulnerability scanning

B.  

Dynamic Application Security Testing (DAST)

C.  

Static Application Security Testing (SAST)

D.  

Fuzz parsing

Discussion 0
Questions 86

The planned channels of Inventory disbursement from one or more sources to field warehouses are known as:

Options:

A.  

a supply chain community.

B.  

interplant demand.

C.  

a bill of distribution.

D.  

logistics data interchange (LDI).

Discussion 0
Questions 87

An organization is aiming to be System and Organization Controls (SOC) 2 certified by an audit organization to demonstrate its security and availability maturity to its sub service organizations. Which type of audit does this engagement BEST describe?

Options:

A.  

Forensic audit

B.  

Third-party audit

C.  

Location audit

D.  

Internal audit

Discussion 0
Questions 88

An information security auditor is creating an audit program to assess endpoint security controls for portable storage media movement. Which type of control will MOST likely be part of the program?

Options:

A.  

Detective control

B.  

Device control

C.  

Recovery control

D.  

Network control

Discussion 0
Questions 89

Which of the following factors Is considered a carrying cost?

Options:

A.  

Setup

B.  

Transportation

C.  

Obsolescence

D.  

Scrap rate

Discussion 0
Questions 90

In a large organization, the average time for a new user to receive access is seven days. Which of the following is the BEST enabler to shorten this time?

Options:

A.  

Implement a self-service password management capability

B.  

Increase system administration personnel

C.  

Implement an automated provisioning tool

D.  

Increase authorization workflow steps

Discussion 0
Questions 91

The development team wants new commercial software to Integrate into the current systems. What steps can the security office take to ensure the software has no vulnerabilities?

Options:

A.  

Request a copy of the most recent System and Organization Controls (SOC) report and/or most recent security audit reports and any vulnerability scans of the software code from the vendor.

B.  

Purchase the software, deploy it in a test environment, and perform Dynamic Application Security Testing (DAST) on the software.

C.  

Request a software demo with permission to have a third-party penetration test completed on it.

D.  

Ask the development team to reevaluate the current program and have a toolset developed securely within the organization.

Discussion 0
Questions 92

A company decided not to pursue a business opportunity In a foreign market due to political Instability and currency fluctuations. Which risk control strategy did this business utilize?

Options:

A.  

Mitigation

B.  

Prevention

C.  

Recovery

D.  

Wait and see

Discussion 0
Questions 93

Risk pooling would work best for items with:

Options:

A.  

low demand uncertainty and short lead times.

B.  

low demand uncertainty and long lead times.

C.  

high demand uncertainty and short lead times.

D.  

high demand uncertainty and long lead times.

Discussion 0
Questions 94

An information security professional is enhancing the organization ' s existing information security awareness program through educational posters. Which of the following is the MOST effective location for poster placement?

Options:

A.  

In a secure room inside the office

B.  

Beside the copy machine

C.  

Outside the office

D.  

In the human resources area

Discussion 0
Questions 95

A security engineer must address resource sharing between various applications without adding physical hardware to the environment. Which secure design principle is used to BEST segregate applications?

Options:

A.  

Network firewalls

B.  

Logical isolation

C.  

Application firewalls

D.  

Physical isolation

Discussion 0
Questions 96

As the organization requires user friendly access to a new web-based application, a software developer decides to implement Single Sign-On (SSO). The developer uses the de-facto standard for web-based applications and the implementation includes the use of a JavaScript Object Notation (JSON) web token. With this information, which is the BEST way for the software developer to establish SSO capability?

Options:

A.  

The developer Inputs the user ' s account, the user ' s password, and a token.

B.  

The developer uses the user ' s credentials stored within the web-based application.

C.  

The developer uses Transport Layer Security (TLS) certificates and Open ID Connect (OIDC).

D.  

The developer uses Open ID Connect (OIDC) and Open Authorization (OAuth).

Discussion 0
Questions 97

Objective security metrics tend to be easier to gather, easier to interpret, and easier to include in reports to management.

What is the BEST objective metric for the effectiveness of a security awareness training?

Options:

A.  

The management’s attitude toward the training

B.  

The number of times users comply with the training

C.  

A change of helpdesk calls after the training

D.  

The off-hand comments about the training

Discussion 0
Questions 98

An organization has a requirement that all documents must be auditable and that the original is never modified once created. When designing the system, what security model MUST be implemented in order to meet this requirement?

Options:

A.  

Biba Integrity

B.  

Brewer-Nash

C.  

Bell-LaPadula

D.  

Clark-Wilson

Discussion 0
Questions 99

Which of the following is a threat modeling methodology used for accessing threats against applications and Operating Systems (OS)?

Options:

A.  

Basically Available, Soft-State, Eventual-Consistency (BASE)

B.  

Spoofing, Tampering, Repudiation, Information Disclosure, Denial Of Service, And Elevation Of Privilege (STRIDE)

C.  

Control Objectives For Information And Related Technology (COBIT)

D.  

Security, Trust, Assurance And Risk (STAR)

Discussion 0
Questions 100

When designing a production cell, which of the following items would be the most important consideration?

Options:

A.  

Theunit per hour requirement for the production cell to meet the sales forecast

B.  

Theflow of materials into the cell and sequencing of operations to minimize total cycle time

C.  

Theoutput rate for the first operation and move time after the last workstation

D.  

Thetakt time requirement for each operator to meet the monthly production goals of the plant

Discussion 0
Questions 101

A bill of resources typically contains information about a product’s:

Options:

A.  

Complete list of components

B.  

Production schedule

C.  

Inventory balances

D.  

Key work centers

Discussion 0
Questions 102

A customer of a financial Institution denies that a transaction occurred. Which of the following is used to provide evidence evidence that the customer performed the transaction?

Options:

A.  

Authorization controls

B.  

Two-Factor Authentication (2FA)

C.  

Non-repudiation controls

D.  

Access audit

Discussion 0
Questions 103

Which of the following prioritization rules will have the greatest impact In reducing the number of orders In queue?

Options:

A.  

Critical ratio

B.  

Shortest processing time

C.  

Fewest operations remaining

D.  

First come, first served

Discussion 0
Questions 104

In a rapidly changing business environment, a primary advantage of an effective customer relationship management (CRM) program is:

Options:

A.  

reduced forecast variability.

B.  

fewer customer order changes.

C.  

fewer customer defections.

D.  

earlier Identification of shifts Incustomer preferences.

Discussion 0
Questions 105

Which of the following is an access control method that organizations can use to prevent unauthorized access?

Options:

A.  

Bring Your Own Device (BYOD)

B.  

Man-in-the-Middle (MITM)

C.  

Token-based authentication

D.  

Digital verification

Discussion 0
Questions 106

Which of the following techniques is BEST suited to preserve the confidentiality of a system’s data?

Options:

A.  

Audit log review

B.  

Database encryption

C.  

Immutable backups

D.  

Database record locking

Discussion 0
Questions 107

An organization uses an external Identity Provider (IdP) to secure internal, external, or third-party applications. Which of the following is the GREATEST risk to the organization?

Options:

A.  

Unavailability of access logs

B.  

Integrity of authentication mechanism

C.  

Compromise of service

D.  

Deletion of federated tokens

Discussion 0
Questions 108

An information system containing Protected Health Information (PHI) will be accessed by doctors, nurses, and others working in a hospital. The same application will be used by staff in the pharmacy department only for dispensing prescribed medication. Additionally, patients can log in to view medical history. The system owner needs to propose an access control model that considers environment, situation, compliance, and security policies while dynamically granting the required level of access. Which access control model is the MOST suitable?

Options:

A.  

Role-Based Access Control (RBAC)

B.  

Attribute-Based Access Control (ABAC)

C.  

Task-based access control

D.  

Risk-adaptive access control

Discussion 0
Questions 109

An organization recently created a new accounting department, and that department is critical in the event of a disaster for the operations to continue. Which steps should the organization take to create a Business Continuity Plan (BCP)?

Options:

A.  

Test, maintain, implement, deliver, and execute

B.  

Plan, implement, execute, deliver, and document

C.  

Understand, plan, deliver, implement, and execute

D.  

Understand, plan, deliver, test, and maintain

Discussion 0
Questions 110

Typically, rough-cut capacity planning (RCCP) in a job shop environment would review which of the following work centers to determine the ability to execute the plan?

Options:

A.  

Critical work centers only

B.  

Gateway work centers only

C.  

Final assembly work centers only

D.  

All work centers

Discussion 0
Questions 111

A Structured Query Language (SQL) database is hosted on a hardened, secure server. All unused ports are locked down, but external connections from untrusted networks are still required to be allowed through. What is the BEST way to ensure transactions to/from this server remain secure?

Options:

A.  

Secure SQL service port with a Transport Layer Security (TLS) certificate.

B.  

Use Multi-Factor Authentication (MFA) for all logins to the server.

C.  

Secure SQL service port with a Secure Sockets Layer (SSL) certificate.

D.  

Scan all connections to the server for malicious packets.

Discussion 0
Questions 112

A security engineer is responsible for verifying software reliability prior to commercial deployment. Which of the following factor would BEST be verified to ensure that the software stays reliable?

Options:

A.  

Monitoring

B.  

Web Application Firewall (WAF)

C.  

Content Delivery Network (CDN)

D.  

Logging

Discussion 0
Questions 113

Check sheets can be used to:

Options:

A.  

determine the frequency of a defect and the time period between occurrences.

B.  

provide a quick method to identify if possible defects exist.

C.  

allow improvement teams to see if action items are being completed on time.

D.  

provide an indication of correlation between defects.

Discussion 0
Questions 114

Fishbone diagrams would help a service organization determine:

Options:

A.  

the proper level of service for a customer segment.

B.  

the source of a quality-of-service issue.

C.  

differences in the performance of employees.

D.  

the decomposition of customer return rates with seasonality.

Discussion 0
Questions 115

A statistical safety stock calculation would be appropriate for:

Options:

A.  

components used in multiple end items.

B.  

new products at time of introduction.

C.  

end items with stable demand.

D.  

supply-constrained raw materials.

Discussion 0
Questions 116

An advantage of applying ABC classification to a firm ' s replenishment items is that:

Options:

A.  

it distinguishes independent demand from dependent demand.

B.  

it allows planners to focus on critical products.

C.  

it provides better order quantities than the economic order quantity (EOQ).

D.  

it allows the firm to utilize time-phased order point (TPOP).

Discussion 0
Questions 117

Management should support investments in new process technologies that:

Options:

A.  

require minimal changes in existing systems, procedures, and skills.

B.  

have been recommended by technical experts and equipment suppliers.

C.  

provide significant cost-reduction opportunities for the company ' s current products.

D.  

provide long-term competitive advantage with acceptable financial risk.

Discussion 0
Questions 118

An organization is looking to integrate security concepts into the code development process early in development to detect issues before the software is launched. Which advantage does the organization gain from using Static Application Security Testing (SAST) techniques versus dynamic application security testing techniques?

Options:

A.  

Allows tailored techniques

B.  

Executes code to detect issues

C.  

Allows for earlier vulnerability detection

D.  

Simulates attacker patterns

Discussion 0
Questions 119

A financial services organization wants to deploy a wireless network. Which of the following is the WEAKEST option for ensuring a secure network?

Options:

A.  

Separating internal wireless users from guests

B.  

Media Access control (MAC) address filtering

C.  

Multi-Factor Authentication (MFA)

D.  

Deploy mutual authentication between the client and the network

Discussion 0
Questions 120

A security professional is accessing an organization-issued laptop using biometrics to remotely log into a network resource. Which type of authentication method is described in this scenario?

Options:

A.  

Something one does

B.  

Something one is

C.  

Something one has

D.  

Something one knows

Discussion 0
Questions 121

Which of the following BEST describes how an Application Programming Interface (API) gateway fits into an application architecture?

Options:

A.  

An API gateway is a specialized reverse proxy that can make different APIs appear as if they are a single API.

B.  

An API gateway inspects traffic and blocks many common attacks against Hypertext Transfer Protocol (HTTP) web services.

C.  

An API gateway ensures that a Denial-Of-Service (DoS) attack cannot occur within the application.

D.  

An API gateway monitors traffic within internal networks and ensures suspicious patterns are detected on any API.

Discussion 0
Questions 122

An effective approach to projecting requirements for materials with long lead times Includes which of the following options?

Options:

A.  

Initiate a multilevel master schedule.

B.  

Use phantom bills of materials (BOMs).

C.  

Increase the level of safety stock.

D.  

Decrease the planning horizon.

Discussion 0
Questions 123

An organization is considering options to outsource their Information Technology (IT) operations. Although they do not sell anything on the Internet, they have a strong requirement in uptime of their application. After the offerings received by the Cloud Service Provider (CSP), the IT manager decided it was mandatory to develop processes to continue operations without access to community or public cloud-based applications. Which of the following arguments MOST likely led the IT manager to make this decision?

Options:

A.  

Circumstances may force a cloud provider to discontinue operations.

B.  

The need to develop alternative hosting strategies for applications deployed to the cloud.

C.  

Most cloud services offerings are unique to each provider and may not be easily portable.

D.  

Integrity and confidentiality are not ensured properly on the most cloud service offerings.

Discussion 0
Questions 124

Increased use of third-party logistics (3PL) services is likely to have which of the following effects on a firm ' s balance sheet?

Options:

A.  

Decreased fixed assets

B.  

Decreased retained earnings

C.  

Increased accounts receivable

D.  

Increased intangible assets

Discussion 0
Questions 125

Which of the following tactics can be employed effectively to reduce appraisal quality costs?

Options:

A.  

Investing in prevention

B.  

Conducting quality audits

C.  

Loosening product specifications

D.  

Implementing house of quality (HOQ)

Discussion 0
Questions 126

An Information Technology (IT) professional is seeking a control objective framework that is widely accepted around the world and focuses specifically on information security controls. Which of the following frameworks BEST meets this need?

Options:

A.  

International Organization For Standardization (ISO) 27001

B.  

International Organization For standardization (ISO) 27002

C.  

International Technology Infrastructure Library (ITIL)

D.  

Capability Maturity Model (CMM)

Discussion 0
Questions 127

Which of the following statements is an advantage of a fourth-party logistics (4PL) provider?

Options:

A.  

It coordinates between the client and multiple logistics suppliers.

B.  

It focuses primarily on last-mile delivery.

C.  

It allows the client to concentrate on operating its own warehouse.

D.  

It provides a logistics specialist who manages some of the logistics operation.

Discussion 0
Questions 128

Which of the following BEST characterizes the operational benefit of using immutable workloads when working on a cloud-based project?

Options:

A.  

The cloud service provider is responsible for all security within the workload

B.  

Allows a user to enable remote logins to running workloads

C.  

Security testing is managed after image creation

D.  

No longer have to bring system down to patch

Discussion 0
Questions 129

Which of the following data elements is required for a manufacturing routing?

Options:

A.  

Queue time

B.  

Work center

C.  

Order quantity

D.  

Efficiency factor

Discussion 0
Questions 130

An information system security manager is tasked with properly applying risk management principle to their cloud information system as outlined by the National Institute of Standards and Technology (NIST).

Which of the following is the INITIAL step?

Options:

A.  

Categorize

B.  

Select

C.  

Assess

D.  

Prepare

Discussion 0
Questions 131

An organization is considering options to outsource their Information Technology (IT) operations. Although they do not sell anything on the Internet, they have a strong requirement in uptime of their application. After evaluating the offerings received by the Cloud Service Provider (CSP), the IT manager decided it was mandatory to develop processes to continue operations without access to community or public cloud-based applications. Which of the following arguments MOST likely led the IT manager to make this decision?

Options:

A.  

Circumstances may force a cloud provider to discontinue operations

B.  

Most cloud service offerings are unique to each provider and may not be easily portable

C.  

Integrity and confidentiality are not ensured properly on most cloud service offerings

D.  

The need to develop alternative hosting strategies for applications deployed to the cloud

Discussion 0
Questions 132

An advertising agency is working on a campaign for a prospective client. Competitors are working on a similar campaign and are interested in knowing what the firm has designed. What should the advertising agency do to BEST ensure intellectual property does not leave the organization?

Options:

A.  

Protect the information by installing a Data Loss Prevention (DLP) system

B.  

Block all organizational email communication with the competitor

C.  

Install an Intrusion Prevention System (IPS)

D.  

Encrypt the data on the servers and distribute private-key information to authorized users

Discussion 0
Questions 133

Which of the following is the workflow of the identity and access provisioning lifecycle?

Options:

A.  

Creation, Assessment, Deletion

B.  

Assessment, Creation, Deletion

C.  

Provision, Review, Revocation

D.  

Review, Provision, Revocation

Discussion 0
Questions 134

An organization has deployed an Identity And Access Management (IAM) tool and is expanding their information governance program. Which of the following would BEST be included in the governance for IAM?

Options:

A.  

Employ password masking, obfuscation, and tokenization and automate account updates based on human resources reporting.

B.  

Implementing Multi-Factor Authentication (MFA) and account lookout controls.

C.  

Create and enforce a strong password policy and implementing security awareness training for all users.

D.  

Control physical access to the IAM system and implementing Data Loss Prevention (DPL) for credentials.

Discussion 0
Questions 135

Which of the following threats MUST be included while conducting threat modeling for a Cloud Service Provider (CSP)?

Options:

A.  

Risks of data breaches that can result from inadequate encryption of tenant data in transit and at rest

B.  

Potential legal actions from third parties due to tenants’ activities on the CSP’s platform

C.  

Vulnerabilities in shared resources that can be exploited by attackers to affect multiple tenants

D.  

Threats originating from the CSP’s tenants that can impact the infrastructure and other tenants

Discussion 0
Questions 136

In a Discretionary Access Control (DAC) model, how is access to resources managed?

Options:

A.  

By the subject’s ability to perform the function

B.  

By the discretion of a system administrator

C.  

By the subject’s rank and/or title within the security organization

D.  

By the identity of subjects and/or groups to which they belong

Discussion 0
Questions 137

An organization currently has a network with 55,000 unique Internet Protocol (IP) addresses in their private Internet Protocol version 4 (IPv4) network range and has acquired another organization and must integrate their 25,000 endpoints with the existing, flat network topology. If subnetting is not implemented, which network class is implied for the organization’s resulting private network segment?

Options:

A.  

A

B.  

B

C.  

C

D.  

E

Discussion 0
Questions 138

A security engineer has determined the need to implement preventative controls into their Wireless Local Area Network (WLAN) for added protection. Which preventative control provides the MOST security?

Options:

A.  

Enabling software to enforce authorized network profiles

B.  

Having an automated alerting capability when a problem is detected

C.  

Third-party software to monitor configuration changes on the network

D.  

Using a monitoring tool to capture all network activity

Discussion 0
Questions 139

Which of the following factors typically would distort a sales forecast that is based solely on shipment history?

Options:

A.  

Material shortages

B.  

Labor rate changes

C.  

Currency exchange rates

D.  

Customer demands

Discussion 0
Questions 140

When an organization is recruiting for roles within the organization, at which stage of the employee life cycle are termination procedures incorporated?

Options:

A.  

Security training

B.  

Orientation

C.  

User provisioning

D.  

Background check

Discussion 0
Questions 141

Which approach will BEST mitigate risks associated with root user access while maintaining system functionality?

Options:

A.  

Creating a system where administrative tasks are performed under monitored sessions using the root account, with audits conducted regularly

B.  

Implementing a policy where users log in as root for complex tasks but use personal accounts for everyday activities, with strict logging of root access

C.  

Configuring individual user accounts with necessary privileges for specific tasks and employing “sudo” for occasional administrative needs

D.  

Allowing key authorized personnel to access the root account for critical system changes, while other staff use limited accounts with “sudo” for routine tasks

Discussion 0
Questions 142

Which of the following are compromised in an untrusted network using public key cryptography when a digitally signed message is modified without being detected?

Options:

A.  

Integrity and authentication

B.  

Integrity and non-repuditation

C.  

Integrity and availability

D.  

Confidentiality and availability

Discussion 0
Questions 143

Company A has acquired Company B. Company A has decided to start a project to convert Company B ' s enterprise resource planning (ERP) software to the same ERP software that Company A uses. What is a likely reason for this decision?

Options:

A.  

The ERP system has business processes which both companies can adopt

B.  

Company A wants to save on software licensing costs

C.  

Each ERP package has unique and distinctive business processes

D.  

Company A wishes to close Company B ' s data center

Discussion 0
Questions 144

The production plan defines which of the following targets?

Options:

A.  

Sales forecast

B.  

Quantities of each product to be produced

C.  

Level of output to be produced

D.  

Business plans for the company

Discussion 0
Questions 145

What resources does a respondent have when contesting disciplinary action taken by the ISC2 Board of Directors?

Options:

A.  

The respondent may file an appeal with the Ethics Committee

B.  

None; the decision made by the Board of Directors are final

C.  

The respondent may file an appeal with the Board of Director

D.  

The respondent has 30 days to provide additional evidence for consideration

Discussion 0
Questions 146

Which of the following BEST represents a security benefit of Software-Defined Networking (SDN)?

Options:

A.  

Improved threat detection

B.  

Flexible firewall configuration

C.  

Network availability

D.  

Improved threat prevention

Discussion 0
Questions 147

Which of the following controls should a financial Institution have in place in order to prevent a trader from both entering and executing a trade?

Options:

A.  

Cameras in the trading room

B.  

Two-Factor Authentication (2FA)

C.  

Separation of Duties (SoD)

D.  

Least privilege

Discussion 0
Questions 148

An organization experienced multiple compromises of endpoints, leading to breaches of systems and data. In updating its strategy to defend against these threats, which of the following BEST considers the organization’s needs?

Options:

A.  

Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege (STRIDE)

B.  

Zero Trust (ZT) threat modeling

C.  

Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE)

D.  

Process for Attack Simulation and Threat Analysis (PASTA)

Discussion 0
Questions 149

A security practitioner notices that workforce members retain access to information systems after transferring to new roles within the organization, which could lead to unauthorized changes to the information systems.

This is a direct violation of which common security model?

Options:

A.  

Clark-Wilson

B.  

Bell-LaPadula

C.  

Graham-Denning

D.  

Take-Grant

Discussion 0
Questions 150

An organization co-locates three divisions and merges them into one network infrastructure. Prior to the merge, the network manager issued devices to employees for remote login. What security concept should be observed to provide security when a device joins the network or when a client makes an Application Programming Interface (API) call?

Options:

A.  

Access Control List (ACL)

B.  

Non-repudiation

C.  

Multi-Factor Authentication (MFA)

D.  

Zero Trust (ZT)

Discussion 0
Questions 151

Which of the following actions hinders the transition from a push system to a pull system?

Options:

A.  

Using standardized containers

B.  

Using work orders as a backup

C.  

Introducing kanban cards as authorization for material movement

D.  

Maintaining a constant number of kanban cards during minor changes in the level of production

Discussion 0
Questions 152

Which of the following production activity control (PAC) techniques focuses on optimizing output?

Options:

A.  

Gantt chart

B.  

Priority sequencing rules

C.  

Theory of constraints (TOC) scheduling

D.  

Critical path management (CPM)

Discussion 0
Questions 153

What is the following is the MAIN reason why hot-spot usually adopt open security mode in wireless networks?

Options:

A.  

Ease of use

B.  

Limitation of Infrastructure

C.  

Adapter compatibility concerns

D.  

Cost concerns

Discussion 0
Questions 154

The define, measure, analyze, improve, control (DMAIC) process is an effective method to understand and improve business processes because it begins with a:

Options:

A.  

Problem that is data driven.

B.  

Decision about a course of action.

C.  

Graphical depiction of the problem.

D.  

Discussion among impacted team members.

Discussion 0
Questions 155

An organization is concerned that if an employee’s mobile device is lost or stolen and does not reconnect to the carrier network, the data on the device may still be at risk. Consequently, the organization has implemented a control on all mobile devices to require an eight-character passcode for unlock and login. What should happen after multiple incorrect passcode attempts?

Options:

A.  

The device should be restarted.

B.  

The device should be wiped.

C.  

The device should be turned off.

D.  

The device passcode should be reset.

Discussion 0
Questions 156

Following the go-live of a new financial software, an organization allowed the Information Technology (IT) officer to maintain all rights and access permissions to help the organization staff should they have challenges in their day-to-day work. What is the BEST way to categorize the situation?

Options:

A.  

Excessive privileges

B.  

Need to know access

C.  

Training access

D.  

Least access principle

Discussion 0
Questions 157

A vendor has been awarded a contract to supply key business software. The vendor has declined all requests to have its security controls audited by customers. The organization insists the product must go live within 30 days. However, the security team is reluctant to allow the project to go live. What is the organization ' s BEST next step?

Options:

A.  

Shift the negative impact of the risk to a cyber insurance provider, i.e., risk transference.

B.  

Document a risk acceptance, in accordance with internal risk management procedures, that will allow the product to go-live.

C.  

Gain assurance on the vendor ' s security controls by examining independent audit reports and any relevant certifications the vendor can provide.

D.  

Evaluate available open source threat intelligence pertaining to the vendor and their product.

Discussion 0
Questions 158

An organization provides customer call center operations for major financial services organizations around the world. As part of a long-term strategy, the organization plans to add healthcare clients to the portfolio. In preparation for contract negotiations with new clients, to which cybersecurity framework(s) should the security team ensure the organization adhere?

Options:

A.  

Control Objectives For Information And Related Technology (COBIT) and Health Insurance Portability And Accountability Act (HIPAA) frameworks

B.  

National Institute Of Standards And Technology (NIST) and International Organization For Standardization (ISO) frameworks

C.  

Frameworks specific to the industries and locations clients do business in

D.  

Frameworks that fit the organization’s risk appetite, as cybersecurity does not vary industry to industry

Discussion 0
Questions 159

An organization’s computer incident response team PRIMARILY responds to which type of control?

Options:

A.  

Detective

B.  

Administrative

C.  

Preventative

D.  

Corrective

Discussion 0
Questions 160

Which of the following may authorize an organization to monitor an employee’s company computer and phone usage?

Options:

A.  

Signed Non-Disclosure Agreement (NDA)

B.  

Signed Acceptable Use Policy (AUP)

C.  

ISC2 Code of Ethics

D.  

Suspicious that a crime is being committed

Discussion 0
Questions 161

What FIRST step should a newly appointed Data Protection Officer (DPO) take to develop an organization ' s regulatory compliance policy?

Options:

A.  

Draft an organizational policy on retention for approval.

B.  

Ensure that periodic data governance compliance meetings occur.

C.  

Understand applicable laws, regulations, and policies with regard to the data.

D.  

Determine the classification of each data type.

Discussion 0
Questions 162

Which of the following design considerations would offer the BEST protection against unauthorized access to the facility?

Options:

A.  

Allowing only one person to enter at a time

B.  

Auditing access logs annually

C.  

Limiting access to regular business hours only

D.  

Establishing entry points from public areas only

Discussion 0
Questions 163

Which assessing whether real-world threats to the security of an application have been mitigated, what is MOST effective source to confirm that sufficient security controls are in place for both end users and customers?

Options:

A.  

Software security team

B.  

Product management

C.  

Third-party reviews

D.  

Senior management

Discussion 0
Questions 164

Which of the following BEST effective when protecting against insider threats?

Options:

A.  

Implement Two-Factor Authentication (2FA).

B.  

Segment data repositories by business rules.

C.  

Develop recovery and restoration procedures.

D.  

Address security in third-party agreements.

Discussion 0
Questions 165

Labor3 people

Work hours10 hours per day

Days4 days per week

Meetings with work area employees1/2 hour per day

Work area efficiency85%

Given the information above, what is the weekly theoretical capacity of this work area in hours?

Options:

A.  

97

B.  

102

C.  

114

D.  

120

Discussion 0
Questions 166

A product manager wishes to store sensitive development data using a cloud storage vendor while maintaining exclusive control over passwords and encryption credentials. What is the BEST method for meeting these requirements?

Options:

A.  

Local self-encryption with passwords managed by a local password manager

B.  

Client-side encryption keys and passwords generated dynamically during cloud access sessions

C.  

Zero-knowledge encryption keys provided by the cloud storage vendor

D.  

Passwords generated by a local password manager during cloud access sessions and encrypted in transit

Discussion 0
Questions 167

A software development vendor wants to test the Application Programming Interface (API). The testers use and manipulate data to identify the various states of the application behavior. What is the kind of testing that is being used?

Options:

A.  

Quality Assurance (QA) testing

B.  

Integration technique

C.  

User Acceptance Testing

D.  

Fuzzing technique

Discussion 0
Questions 168

In Company XYZ, transaction-costing capability has been Integrated into the shop floor reporting system. A batch of 20 units was started in production. At the fourth operation, 20 units are reported as complete. At the fifth operation, 25 units are reported as complete. When all operations are complete, 20 units are checked into the stockroom. If the error at the fifth operation is undetected, which of the following conditions will be true?

Options:

A.  

Stockroom inventory balance will be incorrect.

B.  

Operator efficiency for the fifth operation will be overstated.

C.  

Units in process will be understated.

D.  

Work-in-process (WIP) cost will be understated.

Discussion 0
Questions 169

Which of the following concepts MOST accurately refers to an organization ' s ability to fully understand the health of the data in its system at every stage of the lifecycle?

Options:

A.  

Data observability

B.  

Data portability

C.  

Data discovery

D.  

Data analytics

Discussion 0
Questions 170

When a third-party needs to receive privileged information, which of the following would be the BEST to

transport the data?

Options:

A.  

Layer 2 Tunneling Protocol

B.  

Encrypted at rest

C.  

Virtual Private Network (VPN)

D.  

Encrypted in transit

Discussion 0
Questions 171

Which authentication method is used by an email server to verify that a sender’s Internet Protocol (IP) address is authorized to send messages by the sending domain?

Options:

A.  

DomainKeys Identified Mail (DKIM)

B.  

Sender policy framework

C.  

Pointer record

D.  

Secure/Multipurpose Internet Mail Extensions (S/MIME)

Discussion 0
Questions 172

A warehouse manager assigns orders to warehouse personnel grouped by where the goods are stored. This type of picking is called a(n):

Options:

A.  

Zone system

B.  

Area system

C.  

Multi-order system

D.  

Pull system

Discussion 0
Questions 173

The primary outcome of frequent replenishments in a distribution requirements planning (DRP) system is that:

Options:

A.  

lead times to customers decrease.

B.  

transportation costs decrease.

C.  

the level of required safety stock is reduced.

D.  

more efficient load consolidation occurs.

Discussion 0
Questions 174

An external audit is conducted on an organization ' s cloud Information Technology (IT) infrastructure. This organization has been using cloud IT services for several years, but its use is not regulated in any way by the organization and security audits have never been conducted in the past. Which task will be the MOST challenging to conduct an effective security audit?

Options:

A.  

Resource forecast

B.  

Asset inventory

C.  

Access to logs

D.  

Software license agreements

Discussion 0
Questions 175

Which if the following is the FIRST control step in provisioning user rights and privileges?

Options:

A.  

Identification

B.  

Authorization

C.  

Authentication

D.  

Confidentiality

Discussion 0
Questions 176

Endpoint security needs to be established after an organization procured 1,000 industrial Internet Of Things (IoT) sensors. Which of the following challenges are the security engineers MOST likely to face?

Options:

A.  

Identity And Access Management (IAM)

B.  

Power and physical security

C.  

Configuration Management (CM) and deployment

D.  

Installation and connection

Discussion 0
Questions 177

Which of the following is the GREATEST threat for a Border Gateway Protocol (BGP) deployment on the internet?

Options:

A.  

Ability to use weak hashing algorithms for peer authentication

B.  

Ability to perform unauthenticated peering across autonomous systems

C.  

Failure to validate legitimacy of received route advertisements

D.  

Failure to encrypt route announcement across autonomous systems

Discussion 0
Questions 178

A systems engineer has been tasked by management to provide a recommendation with a prioritized, focused set of actions to help the organization stop high-risk cyber attacks and ensure data security. What should the systems engineer recommend the organization use to accomplish this?

Options:

A.  

Center for Internet Security critical security controls

B.  

Control Objectives for Information and Related Technology (COBIT)

C.  

Inventory baseline controls

D.  

Security content automation protocol controls

Discussion 0
Questions 179

What is the BEST protection method to ensure that an unauthorized entry attempt would fail when securing highly sensitive areas?

Options:

A.  

Employee badge with a picture and video surveillance

B.  

Keyed locks and Closed-Circuit Television (CCTV) at entrances

C.  

Combination lock and a gate that prevents piggybacking

D.  

Proximity badge requiring a Personal Identification Number (PIN) entry at entrances

Discussion 0
Questions 180

A security consultant is recommending the implementation of a security-focused Configuration Management (CM) process in an organization. What would be the BEST benefit the security consultant would include in the recommendation?

Options:

A.  

Security-focused CM integrates the general concepts of CM with existing security requirements of the organization.

B.  

Security-focused CM integrates the general concepts of CM with regulatory requirements placed on an organization.

C.  

Security-focused CM surpasses existing security requirements of the organization.

D.  

Security-focused CM integrates the general concepts of CM with best practices derived from industry frameworks.

Discussion 0