We often refer to 0-day vulnerabilities when we talk about IT security vulnerabilities. What would constitute 0-day vulnerabilities?
The latest changes and updates from the administration for this exam.
Latest Update: Jun 13 2026
All questions are working fine.
We often refer to 0-day vulnerabilities when we talk about IT security vulnerabilities. What would constitute 0-day vulnerabilities?
What are some of the dangers if we chose to NOT use proper and regular patching of our systems?
We have 100 users all needing to communicate with each other. If we are using asymmetric encryption how many keys would we need?
Which is NOT one of the (ISC)² ethics canons?
Why would we choose a centralized access control system over a decentralized one?
As part of our updated security posture, we have started blocking TCP/UDP port 22 as a default. What are we blocking?
Which type of Intrusion Detection Systems (IDS) and Intrusion Prevention System (IPS) are completely vulnerable to 0-day attacks?
You hear a colleague talk about polyinstantiation. What does that mean?
When we talk about WORM media, what are we referring to?
We are using some of the best practice rules on our password's requirements. Which of these would NOT be part of that?