amol9w wrote: » 1) like to be sure that they are downloading the patches from the legitimate site. ---> Digital Certificate is right not the signature which is used on docs, hence C is right since it includes DC
dave0212 wrote: » some are epic curve balls
amol9w wrote: » hi guys,plz help on below question, i have exam in next week want quick reply. As a vendor, you need to provide periodic patches or updates to a product. Your customers would like to be sure that they are downloading the patches from the legitimate site. Further, they would like to ensure that the integrity of the download has not been compromised. An effective way to do this is through the use of:
The risk analysis team has come up with a set of findings and identified certain threats. The information security team puts up a contingency plan in place so that the company can continue to function if that threat takes place. This would be termed as:
Dante182 wrote: » Regarding the risk question: Risk mitigation and risk reduction are not actually interchangable terms. To mitigate risk, you would have to put a control in place to address that risk with the intention to prevent the threat from occuring. In the question it states that a "contingency plan in place....",meaning that a compensating control (not a mitigating control) has been put in place to reduce the impact of the risk should a threat be realised..
amol9w wrote: » hi guys,plz help on below question, i have exam in next week want quick reply. As a vendor, you need to provide periodic patches or updates to a product. Your customers would like to be sure that they are downloading the patches from the legitimate site. Further, they would like to ensure that the integrity of the download has not been compromised. An effective way to do this is through the use of: A. Symmetric cryptography B. Digital signatures. C. Asymmetric cryptography D. PGP Answer: B I selected C, since digital signature i think is not used on website , rather CA is used . Why B is right ??
amol9w wrote: » Risk reduction is part of risk mitigation. Risk cannot be eleminated but can be brought to acceptable level using controls which was done here using compensating control as other options are not possible . How can you prevent Disaster ? hence compensate
colemic wrote: » Mitigating risk means putting a control in place to prevent the threat from occurring. (Such as patching a SQL server.) Reducing risk, is removing the SQL server from the environment altogether. Mitigations do not reduce risk.
Archon wrote: » 1. B 2. Surely risk reduction and risk mitigation are pretty much the same thing.