231. What is the most effective countermeasure against script injection attacks?
Stateful inspection firewall
Disallow server-side scripting in the end user's browser configuration
Filter scripting characters in all input fields
Disallow client-side scripting in the end user's browser configuration
Correct answer: (C) Filter scripting characters in all input fields
232. What is the purpose of the Software Engineering Institute Capability Maturity Model Integration (SEI CMMI)?
Objective assessment of the integrity of an organization's application programs
Objective assessment of an organization's systems engineering processes
Objective assessment of an organization's business processes
Subjective assessment of an organization's systems engineering processes
Correct answer: (B) Objective assessment of an organization's systems engineering processes
233. When an information system authenticates a user based on "what the user is," this refers to the use of:
Authorization based upon the user's job title
Role-based authentication
Two-factor authentication
Biometric authentication
Correct answer: (D) Biometric authentication
234. Where is firmware primarily stored on a computer system?
Trusted Platform Module
Read-only memory
Master boot record
File system
Correct answer: (B) Read-only memory
235. Which is the best approach for two parties who wish to establish a means for confirming the confidentiality and integrity of messages that they exchange:
Digital signatures
Encryption and digital signatures
Key exchange
Encryption
Correct answer: (B) Encryption and digital signatures
236. Which of the following is NOT a deterrent control:
Monitors showing video surveillance
Guard dogs
Surveillance notices
Mantrap
Correct answer: (D) Mantrap
237. Which of the following is NOT a risk associated with remote access:
Risk associated with sensitive information is stored on a non- company-owned computer, out of the organization's control
A non-company-owned computer with inadequate anti-malware protection can introduce an infection through remote access
Anti-virus software on the remote computer will not be able to download virus definition updates
If a split tunnel is used, the remote computer may be more vulnerable to attack
Correct answer: (C) Anti-virus software on the remote computer will not be able to download virus definition updates
238. Which of the following is NOT an authentication protocol: