00:00

QUESTION 21

- (Exam Topic 15)
Which reporting type requires a service organization to describe its system and define its control objectives and controls that are relevant to users internal control over financial reporting?

Correct Answer: B

QUESTION 22

- (Exam Topic 15)
While dealing with the consequences of a security incident, which of the following security controls are MOST appropriate?

Correct Answer: C

QUESTION 23

- (Exam Topic 7)
Which of the following is a PRIMARY advantage of using a third-party identity service?

Correct Answer: D

QUESTION 24

- (Exam Topic 15)
Dumpster diving is a technique used in which stage of penetration testing methodology?

Correct Answer: B

QUESTION 25

- (Exam Topic 15)
What is the overall goal of software security testing?

Correct Answer: B