350-201 exam dumps

350-201 practice question 25 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 25

Single answer

A financial institution is conducting a risk analysis to secure their customer data stored on an internal database. During the analysis, they identify that the database contains sensitive financial information, is vulnerable to SQL injection, and there is a high likelihood of attack from cybercriminals targeting financial institutions. Based on these findings, how should the institution prioritize their mitigation efforts?

  1. A

    Focus on reducing the likelihood of SQL injection attacks by implementing input validation and prepared statements.

  2. B

    Secure the database by encrypting all stored sensitive financial information.

  3. C

    Develop a disaster recovery plan to mitigate the impact of a potential breach.

  4. D

    Deploy a web application firewall (WAF) to detect and block SQL injection attempts in real-time.

Show answer and explanation

Correct answer: A

Explanation

The institution's risk analysis identified a vulnerability (SQL injection) and a related threat (cybercriminals targeting financial institutions). Mitigation efforts should prioritize reducing the likelihood of exploitation by addressing the root cause of the vulnerability. Implementing input validation and prepared statements directly mitigates the SQL injection risk, aligning with the principles of effective risk management.

  • A. Correct.

    This is the correct answer because reducing the likelihood of SQL injection directly addresses the identified vulnerability. By implementing input validation and prepared statements, the institution mitigates the primary risk vector (SQL injection), reducing the threat level.

  • B. Incorrect.

    While encryption is an important security measure, it does not address the identified vulnerability (SQL injection). Encryption primarily reduces the impact of a breach but does not prevent it.

  • C. Incorrect.

    A disaster recovery plan is critical for responding to incidents, but it does not reduce the likelihood of the SQL injection attacks identified in the risk analysis.

  • D. Incorrect.

    Deploying a WAF can help to detect and block SQL injection attempts, but it is a secondary measure. Addressing the root cause (input validation and prepared statements) is more effective and aligns with prioritizing mitigation based on the risk analysis.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam