One of the IaaS production web servers has a critical OS vulnerability that requires remediation. The vulnerability report indicates it is a zero-day exploit.
Which of the following is the BEST course of action to remediate the vulnerability?
A cloud security analyst performs a vulnerability scan on a web application server across all staging environments. According to the vulnerability scan, the web content featured on the server in the staging environment is located on the C:\ drive, which is the same location housing the operating system.
The analyst determines the results are false positive and submits a report, which includes artifacts supporting the claim to the CAB. Given this scenario, which of the following test plans would be the MOST appropriate to include in the report?
Drag and drop each Disaster Recovery Solution need to the corresponding SLA requirement. Options may be used once or not at all.

A CSA needs to bring a client's public cloud site online at another location in the same region after a disaster.
The RPO is eight hours, and the RTO is four hours. Which of the following is the BEST way to accomplish this goal?
A company has just completed a security audit and received initial results from the auditor. The results show that the ethical hacker was able to gain access to the company servers by exploiting non-hardened VMs and hosts as guests and administrators. Which of the following should be implemented to harden the environment?
(Select two.)