1. Which of the following is the BEST definition of Cross-Site Request Forgery (CSRF)?

2. A security architect plans to reference a Mandatory Access Control (MAC) model for implementation. This indicates that which of the following properties are being prioritized?

3. What is the MOST common component of a vulnerability management framework?

4. An application team is running tests to ensure that user entry fields will not accept invalid input of any length.
What type of negative testing is this an example of?

5. Directive controls are a form of change management policy and procedures. Which of the following subsections are recommended as part of the change management process?

