All practice questions
378 questions
A security operations center (SOC) analyst is performing forensic triage on endpoints following an enterprise network intrusion. Analyze the host and network telemetry artifacts, and match each malware classification on the left with its corresponding technical indicator of compromise (IoC) artifact on the right.
Click a left item, then click its matching right item
Items
Matches
Match each third-party risk management agreement or contractual clause to its primary operational purpose.
Click a left item, then click its matching right item
Items
Matches
Match each social engineering attack vector on the left with its corresponding attack scenario description on the right.
Click a left item, then click its matching right item
Items
Matches
An organization is categorizing its security controls based on CompTIA Security+ implementation categories (Technical, Managerial, Operational, Physical) and functional types (Preventive, Deterrent, Detective, Corrective, Compensating, Directive). Match each implemented security control on the left with its correct dual-classification on the right.
Click a left item, then click its matching right item
Items
Matches
Match each core Zero Trust Architecture (ZTA) control plane component with its primary operational responsibility in accordance with NIST SP 800-207 standards.
Click a left item, then click its matching right item
Items
Matches
Match each vulnerability assessment and security testing method on the left with its appropriate operational description on the right.
Click a left item, then click its matching right item
Items
Matches
A security analyst is reviewing incident reports to classify different types of malicious software based on their core behavior and primary indicators of compromise. Match each malware type on the left with its corresponding technical indicator or defining behavior on the right.
Click a left item, then click its matching right item
Items
Matches
Match each threat actor type to its primary defining attribute or motivation in cybersecurity. Which pairings accurately reflect each threat actor profile?
Click a left item, then click its matching right item
Items
Matches
Match each enterprise security management scenario to the cloud service model that reflects its allocation of customer responsibilities under the Shared Responsibility Model.
Click a left item, then click its matching right item
Items
Matches
Match each enterprise host, network, or architecture vulnerability scenario to its primary mitigation strategy.
Click a left item, then click its matching right item
Items
Matches
A security analyst is selecting appropriate security assessment methodologies for an enterprise infrastructure audit. Match each vulnerability assessment and security testing method on the left to its corresponding operational characteristic on the right.
Click a left item, then click its matching right item
Items
Matches
Match each cloud service model to the primary component managed by the enterprise customer under the cloud shared responsibility model.
Click a left item, then click its matching right item
Items
Matches
A security analyst is reviewing endpoint telemetry and forensic artifacts across several compromised systems. Match each malware classification on the left with its corresponding technical indicator of compromise (IoC) or behavior on the right.
Click a left item, then click its matching right item
Items
Matches
During a comprehensive security audit following a series of distinct security events across a global enterprise, threat intelligence analysts are categorizing observed activities by threat actor type, attributes, and primary attack vectors. Match each threat actor profile on the left with the enterprise scenario on the right that best exemplifies its characteristic capabilities, motivation, and attack vector.
Click a left item, then click its matching right item
Items
Matches
Match each social engineering attack vector to the enterprise incident scenario that best exemplifies its delivery method and tactics.
Click a left item, then click its matching right item
Items
Matches
An aerospace engineering enterprise recently completed a third-party technical audit of its internal infrastructure. Match each security weakness scenario on the left with the corresponding cryptographic or control vulnerability on the right.
Click a left item, then click its matching right item
Items
Matches
A corporate security operations center is investigating four distinct security incidents involving social engineering vectors across physical, web, domain, and email boundaries. Match each incident description on the left with its corresponding social engineering attack classification on the right.
Click a left item, then click its matching right item
Items
Matches
A security analyst is establishing baseline service level objectives for system availability and recovery. Match each resiliency metric on the left with its corresponding definition on the right.
Click a left item, then click its matching right item
Items
Matches
Match each enterprise security assessment requirement with the vulnerability scanning method or configuration best suited to satisfy it.
Click a left item, then click its matching right item
Items
Matches
Match each hardware security mechanism on the left to its corresponding primary functional capability on the right.
Click a left item, then click its matching right item
Items
Matches