An organization wants to ensure that its website is free of certain vulnerabilities before the final handoff to the client. What testing method should the organization use to inspect traffic and detect potential issues?
Abastion scanneris a tool or hardened system that inspects network traffic and identifies security vulnerabilities, particularly those visible from an external (internet-facing) viewpoint. It plays a key role inpost-development assessment.
OWASP Testing Guide v4.2:
'Use bastion hosts or hardened scanners to perform vulnerability assessments from an attacker's perspective.'
This option is preferable for final validation before system release, especially when looking for exposure from the public internet.
WGU Course Alignment:
Domain:System Security Engineering
Topic:Evaluate hardened systems and scanning tools during release validation
A company is concerned about the potential risks associated with unauthorized modifications to the Basic Input/Output System (BIOS) firmware on its servers. The company has decided to implement hardening techniques and endpoint security controls to mitigate the risk.
Which technique will prevent unauthorized modifications to the BIOS firmware on a server?
BIOS protectioninvolves enabling hardware security features such asfirmware password protection,secure boot, andwrite protection, which prevent unauthorized firmware modifications.
NIST SP 800-147 (BIOS Protection Guidelines):
''Proper BIOS protection mechanisms, including authenticated updates and access control, are critical to maintaining the integrity of the platform's startup environment.''
This is apreventive control. BIOS monitoring is reactive; backups protect data, not firmware integrity.
WGU Course Alignment:
Domain:System Security Engineering
Topic:Apply firmware and BIOS security controls to prevent low-level tampering
A company wants to ensure that the integrity of its systems is maintained during the startup process.
Which security technology can ensure the integrity of the system during startup by verifying that the system has not been compromised?
The correct answer is D --- Measured boot.
WGU Cybersecurity Architecture and Engineering (KFO1 / D488) explains that Measured Boot, often implemented with Trusted Platform Modules (TPMs), ensures that each component of theboot process is verified for integrity. It provides cryptographic evidence that the system's startup sequence has not been tampered with.
Two-factor authentication (A) secures user logins but does not verify boot integrity. IDS (B) monitors network or host behavior but does not protect the boot process. HSM (C) secures cryptographic operations, not the system boot.
Reference Extract from Study Guide:
'Measured Boot verifies the integrity of the boot process, providing assurance that the system has not been compromised during startup.'
--- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), System Hardening and Trusted Computing
=============================================
An on-call security engineer has been notified after business hours that a possible threat could be impacting production applications.
Which type of threat intelligence should be used by first responders?
The correct answer is A --- Tactical.
Based on WGU Cybersecurity Architecture and Engineering (KFO1 / D488) study material, tactical threat intelligence provides technical details such as indicators of compromise (IOCs), IP addresses, file hashes, domain names, and other evidence needed to detect and respond to threats immediately. This type of intelligence is used by security teams to perform real-time monitoring and incident response.
Operational intelligence (C) addresses campaigns or actor behavior but is not immediately actionable. Strategic intelligence (D) provides high-level, long-term threat trends. Commodity malware (B) refers to low-level malware types, not intelligence classifications.
Reference Extract from Study Guide:
'Tactical threat intelligence focuses on technical indicators of compromise (IOCs) and immediate actionable information that responders use to detect and contain active threats.'
--- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Threat Intelligence Concepts
=============================================
When is it better to purchase software rather than build a software solution in-house?
It is better to purchase software rather than build a software solution in-house when there is a short timeline. Building software from scratch requires significant time for development, testing, and deployment. Purchasing off-the-shelf software can significantly reduce the time needed to implement a solution. Other considerations include:
Cost-effectiveness: Pre-built software can be more cost-effective than developing a custom solution, especially when factoring in the costs of development, maintenance, and support.
Immediate availability: Purchased software is usually ready to deploy immediately, whereas custom development can take months or even years.
Proven reliability: Commercial software often has a track record of reliability and user support, reducing the risk of bugs and issues that may arise with custom development.
Therefore, when time is of the essence, purchasing software is the preferable option.
Reference
Ian Sommerville, 'Software Engineering,' Pearson.
Steve McConnell, 'Rapid Development: Taming Wild Software Schedules,' Microsoft Press.
William Evans
26 days agoNathan Roberts
1 month agoCharles Lopez
2 months agoMatthew Parker
2 months agoElizabeth Ramirez
3 months agoKaren Edwards
3 months agoAnthony Peterson
4 months agoRonald Green
4 months agoGary Clark
4 months agoThomas Murphy
4 months agoAngela Torres
4 months agoMargaret Turner
4 months agoMelissa Cook
4 months agoSarina
5 months agoLouvenia
5 months agoCherrie
5 months agoLashaun
6 months agoJulio
6 months agoPamella
6 months agoNguyet
7 months agoSelene
7 months agoRenea
7 months agoTerrilyn
7 months agoEun
8 months agoScot
8 months agoLenna
8 months agoLauna
8 months agoHoa
9 months agoTawny
9 months agoJeanice
9 months agoFrancisca
9 months agoBarrett
9 months agoAlaine
10 months ago