350-201 Question 57
Select 3A financial organization wants to evaluate the security posture of its recently deployed cloud-based web application. As a cybersecurity professional, which of the following steps would you include in the evaluation process?
- A
Identify and prioritize the critical assets and data handled by the application.
- B
Conduct regular organizational training sessions on cybersecurity awareness.
- C
Perform vulnerability scans and penetration testing on the application and its components.
- D
Review and analyze the application’s compliance with industry security standards like PCI DSS or GDPR.
- E
Implement a new firewall solution before starting the evaluation process.
Show answer and explanation
Correct answers: A, C, D
Explanation
Evaluating the security posture of an asset involves identifying critical assets, assessing vulnerabilities, and ensuring compliance with relevant security standards. These steps provide a comprehensive understanding of the asset's security state, enabling informed decisions on mitigating risks.
- A. Correct.
Correct: Identifying and prioritizing critical assets and data is a fundamental step in security posture evaluation. It ensures that security efforts focus on the most important areas.
- B. Incorrect.
Incorrect: While cybersecurity awareness training is important, it is not directly related to the technical evaluation of the security posture of an asset.
- C. Correct.
Correct: Performing vulnerability scans and penetration testing is crucial for identifying weaknesses and potential entry points in the application.
- D. Correct.
Correct: Reviewing compliance with security standards helps ensure the application adheres to required security practices and regulations.
- E. Incorrect.
Incorrect: Implementing a new firewall solution is a preventive measure, not a step in the process of evaluating the current security posture.