All practice questions
2232 questions
A SOC analyst is reviewing web server access logs within a SIEM platform after an automated alert was generated. The analyst identifies the following log entries:
192.168.10.45 - - [27/Jul/2026:10:15:32 +0000] "GET /item.php?id=12%27%20UNION%20SELECT%20username,%20password_hash%20FROM%20users-- HTTP/1.1" 200 4812
192.168.10.45 - - [27/Jul/2026:10:15:40 +0000] "GET /item.php?id=12%27%20OR%201=1-- HTTP/1.1" 200 9520
Based on the log analysis, which security event has occurred?
A security analyst conducts a host and network audit of a newly deployed industrial sensor gateway host. The audit reveals two vulnerability findings: the host's administrative web interface uses unencrypted HTTP with factory default credentials, and the host resides on a flat corporate network segment directly accessible to internal workstations. Which of the following recommendations should the analyst make to remediate these vulnerabilities? (Select TWO.)
Select all that apply
A DevSecOps engineer is hardening a shared Linux host operating system running multiple containerized microservices for a financial application. Although process namespaces successfully prevent containers from viewing processes outside their environment, a security audit reveals that a compromised container could still invoke unauthorized kernel functions directly against the shared host kernel. Which of the following technical security controls should the engineer implement to restrict the specific system calls available to the containerized applications?
An enterprise security architect is designing network isolation controls for a corporate software development environment. The architecture must prevent lateral movement between developer workstations on the same local subnet while restricting direct administrative connections from developer machines to automated build servers. Which of the following network design strategies should the architect implement to achieve these requirements? (Select TWO.)
Select all that apply
An e-commerce enterprise needs to process customer payment cards while ensuring that actual Primary Account Numbers (PANs) are never stored in internal application databases. The security architecture replaces sensitive card numbers with non-sensitive surrogate values while storing the real card numbers in a secure external vault. Which of the following data protection mechanisms is being described?
An IT administrator needs to deploy multiple isolated application services on a single physical host while minimizing memory overhead and eliminating the need to install a separate guest operating system for each service. Which of the following technologies best fulfills this requirement?
An enterprise security architecture team at a telecommunications firm is updating their threat landscape documentation. Match each threat actor category on the left with its primary operational attributes, resources, and attack vector characteristics on the right.
Click a left item, then click its matching right item
Items
Matches
A logistics enterprise recently migrated its driver dispatch platform to a public cloud API gateway. During a post-deployment security assessment, an analyst discovers that while TLS 1.3 protects network transit, the API gateway relies exclusively on source IP address allowlisting to authorize client requests sent from drivers' mobile devices across cellular carrier networks. Which of the following architectural weaknesses represents the MOST critical security control failure in this implementation?
Match each storage security control mechanism to its corresponding enterprise architectural objective.
Click a left item, then click its matching right item
Items
Matches
An enterprise security architect is designing an Identity and Access Management (IAM) architecture to support modern cloud applications, API access, network administration, and automated user lifecycle management. Match each IAM protocol or specification on the left to its corresponding architectural use case on the right.
Click a left item, then click its matching right item
Items
Matches
A smart utility company deploys thousands of IoT smart meters to transmit real-time electrical grid telemetry back to a central collection server. During a technical security evaluation of the device firmware binary, security analysts discover that all smart meters utilize a single, identical AES key compiled directly into the executable code to encrypt outgoing telemetry payloads. Which cryptographic weakness is present in this deployment, and what is the main security risk associated with it?
An enterprise security analyst is designing an isolation architecture for a multi-tenant physical host. The system will process sensitive financial transactions alongside untrusted third-party code. The security policy mandates that a vulnerability exploited in one workload must not allow memory access or host execution privileges over co-located workload instances on the same server. Which of the following isolation strategies best fulfills this requirement?
During a routine security audit, a security engineer discovers that an internal data-processing application uses static, long-lived API keys embedded directly within source code to query a backend customer database. Additionally, the service account assigned to this application currently holds full database administrator privileges. To mitigate credential exposure risks and align with identity operational best practices, which of the following actions should the engineer take? (Select TWO.)
Select all that apply
An enterprise organization is designing a high-availability infrastructure for its edge network services across two geographically separate data centers. The design requires automatic traffic redirection to the healthy data center if a primary site suffers an outage, while minimizing client browser resolution caching during a failover event. Which of the following mechanisms should the security architect deploy to meet these resilience objectives? (Select TWO.)
Select all that apply
An enterprise security team is configuring an automated Security Orchestration, Automation, and Response (SOAR) playbook to respond to high-confidence phishing alerts containing malicious URL links. The team wants to execute rapid containment and context enrichment while preventing self-inflicted operational outages. Which of the following automated actions should be incorporated into this playbook? (Select TWO.)
Select all that apply
A security analyst has been tasked with evaluating an enterprise web application server to identify missing software patches, unsecure configurations, and known system weaknesses. The organization requires that the assessment identify specific vulnerability details without attempting system exploitation or causing service disruption to production users. Which of the following security assessment methods should the analyst execute to fulfill these requirements?
A regional power grid operator discovers an undetected intrusion within its operational technology (OT) network. Forensic analysis reveals that the attackers leveraged a zero-day vulnerability in specialized industrial controller software to establish long-term persistence. Over an eight-month period, the attackers conducted extensive reconnaissance and network mapping without deploying ransomware or attempting financial extortion. Which of the following threat actor types and attribute profiles best aligns with this attack scenario?
An industrial manufacturing facility needs to secure its operational technology (OT) network housing Programmable Logic Controllers (PLCs) from the corporate IT network. Unauthorized network scanning originating from corporate workstations recently reached the shop floor. The security architect must permit authorized engineering personnel to conduct remote maintenance on PLCs while preventing direct network routing between IT endpoints and OT devices. Which of the following network architecture designs best meets these security requirements?
A security architect is designing a cloud backup and object storage architecture to safeguard critical corporate records against unauthorized data exfiltration and ransomware tampering. The design must guarantee data confidentiality at rest while preventing stored backup snapshots from being modified or deleted even if administrative credentials are compromised. Which TWO of the following technical controls should the architect incorporate into the storage design to satisfy these requirements? (Select TWO).
Select all that apply
A maritime shipping enterprise is formalizing its cloud security architecture strategy across diverse operational environments. Match each security operational requirement on the left with the corresponding cloud model or security architecture component on the right.
Click a left item, then click its matching right item
Items
Matches