Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 CISSP Exam - Topic 4 Question 16 Discussion

A company-wide penetration test result shows customers could access and read files through a web browser. Which of the following can be used to mitigate this vulnerability?
B) Enforce the control of file director/ listings.
A) Enforce the chmod of files to 755.
C) Implement access control on the web server.
D) Implement Secure Sockets Layer (SSL) certificates throughout the web server.

ISC2 CISSP Exam - Topic 4 Question 16 Discussion

Actual exam question for ISC2's CISSP exam
Question #: 16
Topic #: 4
[All CISSP Questions]

A company-wide penetration test result shows customers could access and read files through a web browser. Which of the following can be used to mitigate this vulnerability?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Maurine
8 months ago
I disagree, file directory control is crucial too.
upvoted 0 times
...
Jeanice
9 months ago
Wait, customers could access files? That's wild!
upvoted 0 times
...
Keneth
9 months ago
SSL certificates won't fix this issue at all.
upvoted 0 times
...
Walker
9 months ago
I think enforcing chmod to 755 is a good start, but not enough.
upvoted 0 times
...
Ettie
9 months ago
Definitely need to implement access control on the web server.
upvoted 0 times
...
Ressie
9 months ago
SSL certificates are important for encryption, but I don't think they directly address file access issues like this one.
upvoted 0 times
...
Lennie
9 months ago
I feel like enforcing control of file directory listings could help, but I can't recall the exact details on how that works.
upvoted 0 times
...
Leonora
9 months ago
I think implementing access control on the web server is crucial, similar to a practice question we did about securing sensitive files.
upvoted 0 times
...
Micah
9 months ago
I remember we discussed file permissions in class, but I'm not sure if 755 is enough to prevent access.
upvoted 0 times
...
Olive
9 months ago
Hmm, this looks like a tricky accounting question. I'll need to carefully review the information provided and think through the relevant accounting principles.
upvoted 0 times
...
Lucia
9 months ago
The key here is identifying the specific term for a hotel's main entrance or waiting area. I'm pretty sure the correct answer is C - lobby.
upvoted 0 times
...
Major
9 months ago
Okay, I think I've seen this URI before in the Webex documentation. Let me double-check that.
upvoted 0 times
...
Whitney
10 months ago
No problem, I've done this kind of thing before. I'll just navigate to the item, find the BOM, and then use the copy function to create a new one. Shouldn't be too difficult.
upvoted 0 times
...

Save Cancel