ISC2 CC • Practice Test 1 — 30 Questions
Free ISC2 CC practice test 1 — 30 questions with explanations. No signup required.
A small e-commerce company hosts its web application on a single server with a public IP address. The server runs a Linux OS with Apache, MySQL, and PHP. The company recently experienced a data breach where an attacker gained access to the customer database. The investigation reveals that the attacker exploited a vulnerability in the PHP application to execute arbitrary commands. The server logs show that the attacker used an unauthenticated HTTP POST request to a legacy script that should have been removed. Additionally, the server had default firewall rules allowing all inbound traffic on ports 80 and 443. The company wants to prevent future breaches without redesigning the entire application. Which course of action is the most effective?
Choose an answer to begin — your selection is scored in the full session.
30 questions · instant feedback and full explanations after every question.