D340 Cyber Defense and Countermeasures - Set 5 - Part 2

Test your knowledge of technical writing concepts with these practice questions. Each question includes detailed explanations to help you understand the correct answers.

Question 21: What is risk appetite?

Question 22: Who should formally accept a residual risk?

Question 23: What is a security control assessment?

Question 24: Why is independent assessment valuable?

Question 25: What is the purpose of a security architecture review?

Question 26: What is secure software development lifecycle (SDLC) integration?

Question 27: What is static application security testing (SAST)?

Question 28: What is dynamic application security testing (DAST)?

Question 29: Why are SAST and DAST complementary?

Question 30: What is software composition analysis (SCA)?

Question 31: Why is dependency management a critical security activity?

Question 32: What is a secrets management system used for?

Question 33: Why are secrets in source control repositories a serious risk?

Question 34: What is container security primarily concerned with?

Question 35: Why should container images be scanned before deployment?

Question 36: Why should containers avoid running as root?

Question 37: What is infrastructure drift detection?

Question 38: What is the security benefit of immutable infrastructure?

Question 39: What is a security champion in a development organization?

Question 40: Why is security culture important to a defense program?


Complete the Captcha to view next question set.


Quick View

Don't Want to Study?

Save Time on Studies, Spend More with Family & Friends! Pay-After-you-Pass!

Get Exam Support